Agent skill

Githits Onboarding

by githits-com in githits-com/githits-cli

A skill your agent uses when the user asks to install, connect, configure, sign in to, sign up for, or start using GitHits.

Apache-2.0Auto-check passedAgent Workflows

Install Githits Onboarding

skills CLI
$ npx skills add githits-com/githits-cli --skill githits-onboarding -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install githits-com/githits-cli githits-onboarding --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/githits-com/githits-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/githits-onboarding .claude/skills/githits-onboarding && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
githits-onboarding
GitHub stars
114
Token cost
~3.5k tokens
SKILL.md length
1,885 words
Files
2 (incl. references)
Skills in repo
7
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the user asks to install, connect, configure, sign in to, sign up for, or start using GitHits.

  • The user asks to install
  • SKILL.md covers Current Boundary, Command Style, Execution Mode and Onboarding Flow, plus 2 more sections
  • Calls npx; reaches mcp.githits.com
  • Start using GitHits

What it does

Githits Onboarding is an agent skill from githits-com/githits-cli. Use when the user asks to install, connect, configure, sign in to, sign up for, or start using GitHits. Covers agent detection, MCP and guidance installation, authentication, verification, and setup recovery.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/troubleshooting.md`). Compatibility notes: Requires shell access, internet access, and npx. Use a local githits binary only for explicit local/dev/pinned testing.

It sits in Agent Workflows, covering Authentication and MCP servers. It works with Model Context Protocol. The repository describes itself as: CLI & MCP for GitHits - The Code Context Layer for AI Coding Agents. The licence is Apache-2.0.

When your agent uses it

  • The user asks to install
  • Start using GitHits

Example prompts

  • “/githits-onboarding”

Requirements

  • Node.js
  • Compatibility (from SKILL.md): Requires shell access, internet access, and npx. Use a local githits binary only for explicit local/dev/pinned testing.

What it can do on your machine

Read from SKILL.md and the folder at commit 7449018. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • mcp.githits.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires shell access, internet access, and npx. Use a local githits binary only for explicit local/dev/pinned testing.

    From compatibility in the SKILL.md frontmatter.

Context cost

Githits Onboarding loads about 3.5k tokens when it runs, and up to ~4.3k if it reads all its reference files. Until then it costs about 57 tokens; SKILL.md has 1,885 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from githits-com/githits-cli at commit 7449018, republished under its Apache-2.0 licence (© githits-com). 1,885 words, ~3,485 tokens.

Download SKILL.mdSave it as .claude/skills/githits-onboarding/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
githits-onboarding
description
Use when the user asks to install, connect, configure, sign in to, sign up for, or start using GitHits. Covers agent detection, MCP and guidance installation, authentication, verification, and setup recovery.
compatibility
Requires shell access, internet access, and npx. Use a local githits binary only for explicit local/dev/pinned testing.

Use this skill when the user wants to start using GitHits from their agent. This is a new-user onboarding skill: assume the user wants to create or connect a GitHits account and configure GitHits unless they explicitly say otherwise.

Current Boundary

  • GitHits account sign-in/signup currently uses browser OAuth. You can start and monitor the flow, but the user may need to approve GitHits in a browser tab.
  • Do not promise browserless account creation or that everything happens inside chat.
  • Never ask the user to paste passwords, OAuth codes, cookies, access tokens, refresh tokens, or API keys into chat.

Command Style

  • Use npx -y githits@latest ... for every normal onboarding command. This guarantees the latest published GitHits CLI behavior for new users.
  • Do not use a globally installed githits binary for onboarding unless the user explicitly asks to test a local, dev, or pinned CLI build.
  • If the user explicitly asks for local/dev/pinned testing, preserve the command and environment they provide.
  • For explicit development testing, GITHITS_ENV=dev selects CLI/local MCP service defaults and a separate login namespace; use the same environment for login and verification. Unset or prod uses production. URL overrides remain independent; use GITHITS_CODE_NAV_URL instead of the removed PKGSEER_URL. This selector does not reconfigure hosted MCP connections or plugin endpoints.
  • Prefer --json for staged init commands because agents need stable fields.
  • Do not start npx -y githits@latest as a background task. If npx fails because of network, DNS, or package-fetch errors, stop and report that GitHits CLI is unavailable.

Execution Mode

  • Run onboarding commands inline in the current agent session.
  • For Codex and other agents with background/subagent capabilities, do not use subagents, background agents, background terminals, or long-running background tasks for onboarding.
  • Do not delegate githits, npx, npm, codex, claude, detection, login, or setup commands to subagents or background agents.
  • Do not start npx -y githits@latest init --detect-agents --json as a background task. Run it directly, wait for the result, and only continue after it returns.
  • Do not run pkill, ps, process inspection, or package-source inspection as part of normal onboarding. If a command appears stuck, stop and report that official detection did not return.
  • These are short setup probes and must stay visible and sequential so the user can approve side effects and failures are easy to diagnose.
  • If official detection fails or appears stuck, do not inspect package internals, manually probe tools to infer install IDs, or ask the user to type inferred IDs. Report that official GitHits detection failed and offer to retry, switch setup scope, or stop.

Onboarding Flow

  1. Choose setup scope with a structured choice.

Use the agent's structured choice UI when available. Do not ask the user to type a freeform response for setup scope.

Ask: Where should GitHits be configured?

Options:

  • My user account (Recommended) — configures detected tools globally/user-level on this machine. Best for onboarding because GitHits will be available wherever the user works with those agents.
  • This project only — writes project-local MCP files into the current repo. Good for repo-specific or team setup. These files may be committed.
  1. Detect supported coding tools and GitHits MCP configuration state for the selected scope:

Project-level detection:

bash
npx -y githits@latest init --project --detect-agents --json

User-level detection:

bash
npx -y githits@latest init --detect-agents --json

Run detection inline, not in a background terminal. Wait for JSON before continuing.

Use the JSON fields to summarize detected tools. agents[].status describes MCP state and can be needs_setup, already_configured, unsupported_project_config, or not_detected. agents[].guidanceStatus describes supporting guidance. installableIds remains MCP-only; use actionableIds for tools needing either MCP setup or requested guidance repair.

If actionableIds is absent because the installed CLI predates guidance-aware detection, use installableIds for MCP setup and do not infer guidance-only repair from missing fields.

For project-level setup, do not offer tools with unsupported_project_config. Explain only if needed: those detected tools do not have verified project-level MCP support.

Before showing the review, classify the detection result:

  • If every agent is not_detected, explain that no supported coding tool was found and stop before review, installation, or authentication. Tell the user to install or open a supported tool, then rerun detection.
  • In project scope, if no agent is needs_setup or already_configured and at least one is unsupported_project_config, explain that project-level setup is unavailable, offer user-level detection, and stop the project flow before review or authentication.
  • If supported agents are mixed with unsupported_project_config, explain the unsupported tools but continue only with supported agents.
  • If no effective actionable IDs remain but at least one supported agent is already_configured, continue to the review, skip installation after acknowledgment, and then check authentication.

Follow the CLI JSON instructions remediation for these states rather than replacing it with generic authentication guidance.

  1. When setup can proceed, show the install review before asking for tool approval or starting browser authentication, including the already-configured supported-tool case.

Tell the user:

  • GitHits queries and public package, repository, and documentation targets are sent to GitHits services for processing.
  • Installing GitHits does not itself upload the local workspace.
  • After installation, open a new coding-agent session so it loads MCP configuration and any supporting instructions. The terminal and machine do not need to be restarted.

Ask the user to acknowledge this review before continuing. If the user does not acknowledge it, stop onboarding without installing or starting authentication.

  1. Recommend the simplest actionable setup choice with structured options.

If actionableIds is non-empty, use structured choices when available. Do not ask the user to type comma-separated tool IDs unless the current agent interface has no structured choice mechanism. Explain whether each ID needs MCP setup, guidance repair, or both.

Ask: Which tools should I configure?

Options:

  • Configure all actionable tools (Recommended) — the recommended default option; after approval execute suggestedCommand exactly so scope and guidance intent are preserved.
  • One selective setup option per actionable tool, using the tool display name and ID.

Do not present "configure none" as a normal onboarding choice; if the user does not want any tool configured, pause and clarify whether they want to stop onboarding.

Ask before writing configuration. A good prompt is: I recommend configuring all detected tools so GitHits works wherever you use an agent. Proceed with all, or choose specific tools?

Only install user-approved IDs. Do not run init -y or init --yes unless the user explicitly asks to configure every detected tool.

For selective setup, build the matching scoped --install-agents command and preserve --no-guidance when guidanceRequested is false. Follow the CLI-emitted verification instruction instead of constructing a separate detect command.

If no effective actionable IDs remain and at least one supported tool is already configured, skip installation and continue to authentication only after the user acknowledges the install review.

  1. Install GitHits MCP and supporting guidance for approved tools using the selected scope.

Guidance is installed by default. It adds the githits-mcp skill and a short instruction pointer for tools with verified guidance paths. Add --no-guidance only when the user explicitly asks for plain MCP without supporting instructions.

Show full SKILL.md (749 more words)Show less

Local CLI MCP startup automatically refreshes eligible older githits-mcp installations. It preserves modified, unrecognized, and newer managed content. Users can disable refresh with skills.auto_update = false in GitHits config or GITHITS_DISABLE_SKILL_UPDATE=1. Rerun guided setup to update an existing managed GitHits-first instruction block; startup refresh updates the MCP skill, not that block. Remote-only integrations do not run this local refresh.

Project-level install:

bash
npx -y githits@latest init --project --install-agents <comma-separated-approved-ids> --json

User-level install:

bash
npx -y githits@latest init --install-agents <comma-separated-approved-ids> --json

Treat success and already_configured outcomes as usable. Report any failed outcome with the tool name and message. For project-level setup, remind the user that project-local MCP files may be committed.

Cursor is configured with the remote MCP at https://mcp.githits.com, not a local stdio command. An existing Cursor entry that runs npx ... githits ... mcp start is legacy and should become needs_setup; installing it migrates the entry to the remote URL.

  1. Start GitHits sign-in/signup during onboarding.

Do not ask whether the user wants to log in. Login creates or connects the GitHits account, so it is part of onboarding. Ask before launching browser OAuth, then run login unless auth status already shows an active session.

This CLI authentication step applies to local GitHits CLI/stdio integrations. Cursor remote MCP authentication is managed separately by Cursor. If Cursor is the only approved tool, skip local CLI login and continue to the Cursor verification below. For a mixed install, use this CLI login step for the non-Cursor tools, but do not treat it as evidence that Cursor is authenticated.

Check auth state:

bash
npx -y githits@latest auth status

Treat Authenticated. and Authenticated via environment variable. as already signed in and skip launching login. Treat Not authenticated. and Token expired. as requiring login.

Explain: I can start GitHits sign-in now. It may open a browser tab where you approve or create your GitHits account. I will not ask you to paste secrets into chat.

Then run:

bash
npx -y githits@latest login

Normal login opens the browser when possible and also prints a fallback sign-in URL. If command output is hidden from the user, relay the URL verbatim.

If the browser cannot open automatically, or the session appears to be SSH/container/headless, use:

bash
npx -y githits@latest login --no-browser

With --no-browser, surface the printed sign-in URL clearly so the user can open it in a browser. If command output is hidden from the user, relay the URL verbatim. Do not ask them to paste passwords, tokens, cookies, or OAuth codes back into chat.

  1. Verify setup after login and installation.

Follow the CLI-emitted verification instruction for the selected setup scope, preserving --project and --no-guidance when applicable. Confirm selected tools are already_configured for that scope. For local CLI/stdio integrations, confirm local authentication is active using the auth-status command above. Skip local CLI authentication checks for Cursor-only setup; use the Cursor verification below. For mixed setups, verify each authentication path separately.

If MCP configuration or supporting guidance changed, tell the user to open a new coding-agent session in the project or user environment so the tool reloads its MCP configuration and any supporting instructions. The terminal and machine do not need to be restarted.

For Cursor, already_configured verifies only that the remote URL is present. It does not verify Cursor-managed OAuth or tool discovery. Do not report Cursor as ready based on githits auth status or init detection alone.

If cursor-agent is available, verify Cursor directly:

bash
cursor-agent mcp list
cursor-agent mcp list-tools GitHits

If Cursor reports that authentication is required, run cursor-agent mcp login GitHits, let the user complete browser OAuth, then rerun both verification commands. Do not ask the user to paste OAuth data into chat.

Whether or not cursor-agent is available, tell the user to open a new Cursor Agent chat after installation. In the Cursor MCP tools UI, confirm that GitHits is enabled, complete its OAuth prompt if shown, and confirm that GitHits tools are listed. If the CLI checks cannot run, require the user's confirmation from that new chat before reporting Cursor ready.

Completion Response

Report:

  • Which tools were configured or already configured.
  • Whether local GitHits CLI auth and Cursor-managed OAuth are active, require browser approval, or could not be verified, keeping those states separate.
  • Whether the user needs to restart/open a new agent session.
  • Any failed tool setup with the exact tool name and error message.

Safety Rules

  • Do not collect or display secrets.
  • Do not write secrets into MCP config.
  • Do not ask the user to run commands manually unless you lack shell access.
  • Do not retry broad setup with init --yes after a failure; use the staged JSON flow and approved IDs.
  • If auth storage fails, read references/troubleshooting.md before suggesting recovery.

Read references/troubleshooting.md for recovery paths when setup, login, storage, or verification fails.

© githits-com, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/githits-onboarding of githits-com/githits-cli.

  • SKILL.md
  • references/troubleshooting.md

Open the folder on GitHubat commit 7449018

Compare with similar skills

Githits Onboarding next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Githits Onboarding compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Githits Onboarding this skillgithits-com/githits-cli114—~3.5kAutomated safety check: PassApache-2.0
MCP Server Builder with mcp-usemcp-use/mcp-use11k—~923Automated safety check: PassApache-2.0
Cao MCP Appsawslabs/cli-agent-orchestrator1.4k—~1.9kAutomated safety check: PassApache-2.0
Cross Origin Iframe Probejumodada/Drissionpage-MCP-Server487—~1.2kAutomated safety check: PassCustom licence
Fastmcp Serverdavila7/claude-code-templates32k—~1.9kAutomated safety check: PassMIT
Copilot SDKaiskillstore/marketplace4305 repos~3.8kAutomated safety check: PassNone

Similar skills

  • Builds, modifies, debugs, migrates and verifies TypeScript MCP servers and MCP Apps with the mcp-use framework, treating the installed package's types as the source of truth.

    11k GitHub stars~923 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Cao MCP Apps

    awslabs/cli-agent-orchestrator

    Official

    Enable, operate, and extend CAO's MCP Apps surface — the host-rendered fleet dashboard visible inside MCP App hosts (Claude Desktop, ChatGPT, VS Code Copilot, Goose, Postman).

    1.4k GitHub stars~1.9k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Cross Origin Iframe Probe

    jumodada/Drissionpage-MCP-Server

    A skill your agent uses when a drissionpage-mcp task targets an iframe such as a payment widget, challenge, SSO flow, or embedded checkout.

    487 GitHub stars~1.2k tokensUpdated 24 days ago
    Agent WorkflowsAuto-check passed
  • Fastmcp Server

    davila7/claude-code-templates

    Complete guide for building MCP servers with FastMCP 3.0 - tools, resources, authentication, providers, middleware, and deployment.

    32k GitHub stars~1.9k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Copilot SDK

    aiskillstore/marketplace

    Build applications that programmatically interact with GitHub Copilot.

    430 GitHub starsUsed in 5 repos~3.8k tokens
    Agent WorkflowsAuto-check passed
  • Copilot SDK

    intellectronica/agent-skills

    This skill helps with GitHub Copilot SDK work across Node.js/TypeScript, Python, Go, .NET, and Java.

    295 GitHub stars~3.2k tokensUpdated 5 mo ago
    Agent WorkflowsAuto-check passed

More from githits-com/githits-cli

  • Githits Code

    githits-com/githits-cli

    A skill your agent uses whenever invoking the GitHits CLI for public OSS source, documentation, or example evidence, including code search/grep, file navigation, source verification, docs lookup, or…

    114 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • Githits Package

    githits-com/githits-cli

    A skill your agent uses whenever invoking the GitHits CLI for public package or dependency evidence, including metadata, versions, licenses, vulnerabilities, dependency graphs, changelogs, release…

    114 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Braintrust Agent Evals

    githits-com/githits-cli

    Inspect, query, compare, or explicitly export GitHits agent-eval history in Braintrust using the repository's verified workflow.

    114 GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • Githits Plugin Maintenance

    githits-com/githits-cli

    Internal repository-maintenance skill for GitHits cross-host plugin and Agent Skill surfaces.

    114 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Githits Release

    githits-com/githits-cli

    A skill your agent uses when maintaining the GitHits changelog or preparing, reviewing, or executing a GitHits release.

    114 GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed
  • Githits MCP

    githits-com/githits-cli

    Route public OSS code, documentation, examples, and package questions to GitHits tools.

    114 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed

Questions about Githits Onboarding

What does Githits Onboarding do?

A skill your agent uses when the user asks to install, connect, configure, sign in to, sign up for, or start using GitHits. Githits Onboarding is an agent skill from githits-com/githits-cli. Use when the user asks to install, connect, configure, sign in to, sign up for, or start using GitHits.

When should I use Githits Onboarding?

Githits Onboarding fits situations like: the user asks to install; start using GitHits.

How do I install Githits Onboarding in Claude Code?

Run `npx skills add githits-com/githits-cli --skill githits-onboarding -a claude-code`. Or copy the skill folder (skills/githits-onboarding in githits-com/githits-cli) into .claude/skills/githits-onboarding in your project. Claude Code loads it when a task matches its description.

How do I install Githits Onboarding in Codex?

Run `npx skills add githits-com/githits-cli --skill githits-onboarding -a codex`. Or copy the skill folder (skills/githits-onboarding in githits-com/githits-cli) into .agents/skills/githits-onboarding in your project. Codex loads it when a task matches its description.

Can I use Githits Onboarding in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add githits-com/githits-cli --skill githits-onboarding -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/githits-onboarding, .gemini/skills/githits-onboarding, .github/skills/githits-onboarding and .opencode/skills/githits-onboarding in your project.

What does Githits Onboarding need to run?

Going by SKILL.md and its folder, Githits Onboarding needs the command-line tools its instructions call (npx). Our summary lists: Node.js. Compatibility (from SKILL.md): Requires shell access, internet access, and npx. Use a local githits binary only for explicit local/dev/pinned testing..

Does Githits Onboarding access the network?

SKILL.md names 1 domain. In commands or code: mcp.githits.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Githits Onboarding safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Githits Onboarding use?

Githits Onboarding is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Githits Onboarding use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 797 tokens, read only when the agent opens those files.

What are the alternatives to Githits Onboarding?

Skills that share tags, products or a category with Githits Onboarding: MCP Server Builder with mcp-use (mcp-use/mcp-use, 11k stars), Cao MCP Apps (awslabs/cli-agent-orchestrator, 1.4k stars), Cross Origin Iframe Probe (jumodada/Drissionpage-MCP-Server, 487 stars) and Fastmcp Server (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Githits Onboarding?

githits-com (a GitHub organization) maintains it in githits-com/githits-cli, which has 114 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 7, 2026.

Source: githits-com/githits-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.