Official agent skill

Messages

by github in github/gh-aw

Add new safe-output message types and wire validation/rendering.

OfficialMITAuto-check passed

Install Messages

skills CLI
$ npx skills add github/gh-aw --skill messages -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/gh-aw messages --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/messages .claude/skills/messages && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
messages
GitHub stars
5.4k
Token cost
~1.7k tokens
SKILL.md length
500 words
Files
1
Skills in repo
52
Repo updated
First seen
Licence
MIT

At a glance

Add new safe-output message types and wire validation/rendering.

  • Works in 9 steps: Update JSON Schema → Update Go Struct → Wire the field in the parser → …
  • SKILL.md covers Overview, Step 1: Update JSON Schema, Step 2: Update Go Struct and Step 3: Wire the field in the…, plus 9 more sections
  • Calls make

What it does

Messages is an agent skill from github/gh-aw, published by the product's own GitHub organization. Add new safe-output message types and wire validation/rendering.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with JavaScript. The repository describes itself as: GitHub Agentic Workflows. The licence is MIT.

Example prompts

  • “/messages”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Update JSON Schema
  2. Update Go Struct
  3. Wire the field in the parser
  4. Create the JavaScript message module
  5. Add tests
  6. Update the core JS type metadata and exports
  7. Wire it into the real build path
  8. Use the message in consumer scripts
  9. Update documentation

What it can do on your machine

Read from SKILL.md and the folder at commit a4ca9f2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Messages loads about 1.7k tokens when it runs. Until then it costs about 18 tokens; SKILL.md has 500 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~18
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/gh-aw at commit a4ca9f2, republished under its MIT licence (© github). 500 words, ~1,677 tokens.

Download SKILL.mdSave it as .claude/skills/messages/SKILL.md (or your agent's skills folder).
name
messages
description
Add new safe-output message types and wire validation/rendering.

Adding New Message Types Guide

Use this guide to add a new safe-output message type so it works in the current gh-aw pipeline: frontmatter → schema → Go compiler → JavaScript modules → action/workflow build output.

Overview

The messages system lets workflow authors customize safe-output messages. The current architecture does not rely on the old pkg/workflow/js.go embedding registry for runtime shipping.

Current flow:

  1. Frontmatter (YAML)
  2. JSON Schema
  3. Go Compiler
  4. JavaScript module under pkg/workflow/js/ or actions/setup/js/
  5. Action/workflow bundle generation via make actions-build or the relevant workflow build path

Step 1: Update JSON Schema

Add the new message field to pkg/parser/schemas/main_workflow_schema.json in the messages object:

json
{
	"messages": {
		"properties": {
		  "my-new-message": {
		    "type": "string",
		    "description": "Description of when this message is used. Available placeholders: {placeholder1}, {placeholder2}.",
		    "examples": [
		      "Example message with {placeholder1}"
		    ]
		  }
		}
	}
}

Key points:

  • Use kebab-case for the YAML field name (for example my-new-message)
  • Document placeholders in the description
  • Provide helpful examples
  • Rebuild the schema-backed binary or run the relevant compile checks after changes

Step 2: Update Go Struct

Add the field to SafeOutputMessagesConfig in pkg/workflow/safe_outputs_config_types.go:

go
type SafeOutputMessagesConfig struct {
	// ... existing fields ...
	MyNewMessage string `yaml:"my-new-message,omitempty" json:"myNewMessage,omitempty"`
}

Key points:

  • Use CamelCase for Go field names
  • Use kebab-case for YAML tags
  • Use camelCase for JSON tags
  • Add omitempty to both tags

Step 3: Wire the field in the parser

Add the field to parseMessagesConfig in pkg/workflow/safe_outputs_messages_config.go. Each field is mapped explicitly; simple string fields use extractStringFromMap:

go
config.MyNewMessage = extractStringFromMap(messagesMap, "my-new-message", nil)

Step 4: Create the JavaScript message module

Create the new module in the current shared JS location, typically pkg/workflow/js/:

javascript
// @ts-check
/// <reference types="@actions/github-script" />

const { getMessages, renderTemplate, toSnakeCase } = require("./messages_core.cjs");

/**
 * @typedef {Object} MyNewMessageContext
 * @property {string} placeholder1 - Description of placeholder1
 * @property {string} placeholder2 - Description of placeholder2
 */

function getMyNewMessage(ctx) {
	const messages = getMessages();
	const templateContext = toSnakeCase(ctx);
	const defaultMessage = "Default message with {placeholder1} and {placeholder2}";

	return messages?.myNewMessage
		? renderTemplate(messages.myNewMessage, templateContext)
		: renderTemplate(defaultMessage, templateContext);
}

module.exports = {
	getMyNewMessage,
};

Key points:

  • File naming: messages_<category>.cjs
  • Reuse ./messages_core.cjs for shared helpers
  • Use JSDoc for types and default behavior
  • Keep the default message sensible and deterministic

Step 5: Add tests

Create a matching test file, for example pkg/workflow/js/messages_my_new.test.cjs:

javascript
import { describe, it, expect, beforeEach, vi } from "vitest";

const mockCore = { warning: vi.fn() };
global.core = mockCore;

describe("getMyNewMessage", () => {
	beforeEach(() => {
		vi.clearAllMocks();
		delete process.env.GH_AW_SAFE_OUTPUT_MESSAGES;
	});

	it("returns the default message when no custom template is configured", async () => {
		const { getMyNewMessage } = await import("./messages_my_new.cjs");
		const result = getMyNewMessage({ placeholder1: "value1", placeholder2: "value2" });
		expect(result).toBe("Default message with value1 and value2");
	});

	it("uses the custom template when configured", async () => {
		process.env.GH_AW_SAFE_OUTPUT_MESSAGES = JSON.stringify({ myNewMessage: "Custom: {placeholder1}" });
		const { getMyNewMessage } = await import("./messages_my_new.cjs");
		const result = getMyNewMessage({ placeholder1: "test", placeholder2: "ignored" });
		expect(result).toContain("Custom: test");
	});
});

Run the relevant tests with make test-js or the targeted Vitest file.

Step 6: Update the core JS type metadata and exports

Update the SafeOutputMessages typedef and the return object in pkg/workflow/js/messages_core.cjs, and re-export the message helper from pkg/workflow/js/messages.cjs.

Show full SKILL.md (210 more words)Show less

Step 7: Wire it into the real build path

Do not add any new //go:embed entries to pkg/workflow/js.go for a normal message module. The current system packages JavaScript through the action-generation/build path.

Instead:

  • keep the JS module in pkg/workflow/js/ or the relevant action folder,
  • update the action dependency map or action source if needed,
  • rebuild the action bundle with make actions-build.

Step 8: Use the message in consumer scripts

javascript
const { getMyNewMessage } = require("./messages_my_new.cjs");

const message = getMyNewMessage({
	placeholder1: actualValue1,
	placeholder2: actualValue2,
});

Step 9: Update documentation

Document the new message in the repo’s relevant safe-output docs, and keep the examples aligned with the current action-based JavaScript build flow.

Verification Checklist

Before committing a message change:

  • Frontmatter and schema updated
  • Go config/struct updated if needed
  • JS module created under the correct source tree
  • Tests added and passing
  • messages_core.cjs and messages.cjs updated if relevant
  • Generated action/build output refreshed when required
  • No stale embedding instructions are introduced for the current action-based JS build flow

References

  • actions/README.md - current action-generation/build workflow
  • pkg/workflow/js/messages_core.cjs - shared safe-output message helpers
  • pkg/workflow/js/messages.cjs - message exports
  • pkg/parser/schemas/main_workflow_schema.json - schema source of truth

Update the Message Module Architecture table:

markdown
| Module | Purpose | Exported Functions |
|--------|---------|-------------------|
| `messages_my_new.cjs` | My new message description | `getMyNewMessage` |

Notes

For current gh-aw work, keep message modules aligned with the action-generation flow instead of the historical Go-embed pattern. If you need an example, review the existing safe-output modules under pkg/workflow/js/ and the generated action files under actions/.

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/messages of github/gh-aw.

Open the folder on GitHubat commit a4ca9f2

Compare with similar skills

Messages next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Messages compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Messages this skillgithub/gh-aw5.4k—~1.7kAutomated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Tailwindcss Developmentanonaddy/anonaddy4.9k10 repos~865Automated safety check: PassMIT
Figma use_figma Plugin API Ruleswarpdotdev/warp65k4 repos~4.4kAutomated safety check: PassAGPL-3.0
Install Anti-Slop Oxlint Rulesdmmulroy/anti-slop5.3k1 repos~2.2kAutomated safety check: PassMIT
GSAP Core Animationgreensock/gsap-skills16k4 repos~3.7kAutomated safety check: PassMIT

Similar skills

  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Tailwindcss Development

    anonaddy/anonaddy

    Always invoke when the user's message includes 'tailwind' in any form.

    4.9k GitHub starsUsed in 10 repos~865 tokens
    Frontend & DesignAuto-check passed
  • Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.

    65k GitHub starsUsed in 4 repos~4.4k tokens
    Frontend & DesignAuto-check passed
  • Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.

    5.3k GitHub starsUsed in 1 repo~2.2k tokens
    DevelopmentAuto-check passed
  • GSAP Core Animation

    greensock/gsap-skills

    Covers the GSAP core API for tweens, easing, staggers, defaults and matchMedia, and when to choose GSAP over CSS animations or other JavaScript animation libraries.

    16k GitHub starsUsed in 4 repos~3.7k tokens
    Frontend & DesignAuto-check passed
  • Chrome CDP Browser Control

    zenstory-ai/oh-story-claudecode

    Drives a Chrome window over the DevTools Protocol with the agent-browser CLI, so the agent can reuse your logged-in sessions, read pages and pull tokens.

    7.4k GitHub starsUsed in 3 repos~1.2k tokens
    Productivity & AutomationAuto-check passed

More from github/gh-aw

All 52 skills in this repo
  • Official

    Drives a real browser from the command line with playwright-cli to open pages, interact, mock requests, save state and work with Playwright tests.

    5.4k GitHub starsUsed in 24 repos~2.8k tokens
    Auto-check passed
  • Official

    Designs and verifies a deterministic grader that measures whether a GitHub Agentic Workflow run reached its real-world or repository outcome.

    5.4k GitHub stars~6.8k tokensUpdated today
    Auto-check passed
  • Official

    Scaffolds, edits, reloads and debugs a canvas extension that the GitHub Copilot CLI can open in its side panel.

    5.4k GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Official

    Drives an open pull request to merge-ready from inside a GitHub Copilot cloud agent, resolving review threads and local checks concurrently, without merging or retriggering CI.

    5.4k GitHub stars~3.8k tokensUpdated today
    Auto-check: warnings
  • Official

    Bumps gh-aw's pinned gh-aw-firewall version, rebuilds generated artifacts, and flags upstream spec or schema changes that need follow-up work.

    5.4k GitHub stars~899 tokensUpdated today
    Auto-check passed
  • Official

    Guide to the console struct tag system in gh-aw: headers, titles, number and cost formats, omitempty, and how structs, slices and maps render in the terminal.

    5.4k GitHub stars~736 tokensUpdated today
    Auto-check passed

Works with

Questions about Messages

What does Messages do?

Add new safe-output message types and wire validation/rendering. Messages is an agent skill from github/gh-aw, published by the product's own GitHub organization. Add new safe-output message types and wire validation/rendering.

How do I install Messages in Claude Code?

Run `npx skills add github/gh-aw --skill messages -a claude-code`. Or copy the skill folder (.github/skills/messages in github/gh-aw) into .claude/skills/messages in your project. Claude Code loads it when a task matches its description.

How do I install Messages in Codex?

Run `npx skills add github/gh-aw --skill messages -a codex`. Or copy the skill folder (.github/skills/messages in github/gh-aw) into .agents/skills/messages in your project. Codex loads it when a task matches its description.

Can I use Messages in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw --skill messages -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/messages, .gemini/skills/messages, .github/skills/messages and .opencode/skills/messages in your project.

What does Messages need to run?

Going by SKILL.md and its folder, Messages needs the command-line tools its instructions call (make).

Does Messages access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Messages safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Messages use?

Messages is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Messages use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Messages?

Skills that share tags, products or a category with Messages: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Tailwindcss Development (anonaddy/anonaddy, 4.9k stars), Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars) and Install Anti-Slop Oxlint Rules (dmmulroy/anti-slop, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Messages?

github (a GitHub organization, an official publisher) maintains it in github/gh-aw, which has 5,359 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 8, 2026.

Source: github/gh-aw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.