Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Add new safe-output message types and wire validation/rendering.
$ npx skills add github/gh-aw --skill messages -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install github/gh-aw messages --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/messages .claude/skills/messages && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "messages" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/messages into .claude/skills/messages/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "messages", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/github/gh-aw/tree/main/.github/skills/messagesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add github/gh-aw --skill messages -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install github/gh-aw messages --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/messages .agents/skills/messages && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "messages" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/messages into .agents/skills/messages/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "messages", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw --skill messages -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install github/gh-aw messages --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/messages .cursor/skills/messages && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "messages" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/messages into .cursor/skills/messages/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "messages", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/github/gh-aw.git --path .github/skills/messages--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add github/gh-aw --skill messages -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install github/gh-aw messages --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/messages .gemini/skills/messages && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "messages" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/messages into .gemini/skills/messages/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "messages", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install github/gh-aw messagesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add github/gh-aw --skill messages -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/messages .github/skills/messages && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "messages" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/messages into .github/skills/messages/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "messages", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw --skill messages -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install github/gh-aw messages --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/messages .opencode/skills/messages && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "messages" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/messages into .opencode/skills/messages/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "messages", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
messagesAdd new safe-output message types and wire validation/rendering.
Messages is an agent skill from github/gh-aw, published by the product's own GitHub organization. Add new safe-output message types and wire validation/rendering.
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It works with JavaScript. The repository describes itself as: GitHub Agentic Workflows. The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit a4ca9f2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
makeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Messages loads about 1.7k tokens when it runs. Until then it costs about 18 tokens; SKILL.md has 500 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from github/gh-aw at commit a4ca9f2, republished under its MIT licence (© github). 500 words, ~1,677 tokens.
.claude/skills/messages/SKILL.md (or your agent's skills folder).Use this guide to add a new safe-output message type so it works in the current gh-aw pipeline: frontmatter → schema → Go compiler → JavaScript modules → action/workflow build output.
The messages system lets workflow authors customize safe-output messages. The current architecture does not rely on the old pkg/workflow/js.go embedding registry for runtime shipping.
Current flow:
pkg/workflow/js/ or actions/setup/js/make actions-build or the relevant workflow build pathAdd the new message field to pkg/parser/schemas/main_workflow_schema.json in the messages object:
{
"messages": {
"properties": {
"my-new-message": {
"type": "string",
"description": "Description of when this message is used. Available placeholders: {placeholder1}, {placeholder2}.",
"examples": [
"Example message with {placeholder1}"
]
}
}
}
}Key points:
kebab-case for the YAML field name (for example my-new-message)Add the field to SafeOutputMessagesConfig in pkg/workflow/safe_outputs_config_types.go:
type SafeOutputMessagesConfig struct {
// ... existing fields ...
MyNewMessage string `yaml:"my-new-message,omitempty" json:"myNewMessage,omitempty"`
}Key points:
CamelCase for Go field nameskebab-case for YAML tagscamelCase for JSON tagsomitempty to both tagsAdd the field to parseMessagesConfig in pkg/workflow/safe_outputs_messages_config.go. Each field is mapped explicitly; simple string fields use extractStringFromMap:
config.MyNewMessage = extractStringFromMap(messagesMap, "my-new-message", nil)Create the new module in the current shared JS location, typically pkg/workflow/js/:
// @ts-check
/// <reference types="@actions/github-script" />
const { getMessages, renderTemplate, toSnakeCase } = require("./messages_core.cjs");
/**
* @typedef {Object} MyNewMessageContext
* @property {string} placeholder1 - Description of placeholder1
* @property {string} placeholder2 - Description of placeholder2
*/
function getMyNewMessage(ctx) {
const messages = getMessages();
const templateContext = toSnakeCase(ctx);
const defaultMessage = "Default message with {placeholder1} and {placeholder2}";
return messages?.myNewMessage
? renderTemplate(messages.myNewMessage, templateContext)
: renderTemplate(defaultMessage, templateContext);
}
module.exports = {
getMyNewMessage,
};Key points:
messages_<category>.cjs./messages_core.cjs for shared helpersCreate a matching test file, for example pkg/workflow/js/messages_my_new.test.cjs:
import { describe, it, expect, beforeEach, vi } from "vitest";
const mockCore = { warning: vi.fn() };
global.core = mockCore;
describe("getMyNewMessage", () => {
beforeEach(() => {
vi.clearAllMocks();
delete process.env.GH_AW_SAFE_OUTPUT_MESSAGES;
});
it("returns the default message when no custom template is configured", async () => {
const { getMyNewMessage } = await import("./messages_my_new.cjs");
const result = getMyNewMessage({ placeholder1: "value1", placeholder2: "value2" });
expect(result).toBe("Default message with value1 and value2");
});
it("uses the custom template when configured", async () => {
process.env.GH_AW_SAFE_OUTPUT_MESSAGES = JSON.stringify({ myNewMessage: "Custom: {placeholder1}" });
const { getMyNewMessage } = await import("./messages_my_new.cjs");
const result = getMyNewMessage({ placeholder1: "test", placeholder2: "ignored" });
expect(result).toContain("Custom: test");
});
});Run the relevant tests with make test-js or the targeted Vitest file.
Update the SafeOutputMessages typedef and the return object in pkg/workflow/js/messages_core.cjs, and re-export the message helper from pkg/workflow/js/messages.cjs.
Do not add any new //go:embed entries to pkg/workflow/js.go for a normal message module. The current system packages JavaScript through the action-generation/build path.
Instead:
pkg/workflow/js/ or the relevant action folder,make actions-build.const { getMyNewMessage } = require("./messages_my_new.cjs");
const message = getMyNewMessage({
placeholder1: actualValue1,
placeholder2: actualValue2,
});Document the new message in the repo’s relevant safe-output docs, and keep the examples aligned with the current action-based JavaScript build flow.
Before committing a message change:
messages_core.cjs and messages.cjs updated if relevantactions/README.md - current action-generation/build workflowpkg/workflow/js/messages_core.cjs - shared safe-output message helperspkg/workflow/js/messages.cjs - message exportspkg/parser/schemas/main_workflow_schema.json - schema source of truthUpdate the Message Module Architecture table:
| Module | Purpose | Exported Functions |
|--------|---------|-------------------|
| `messages_my_new.cjs` | My new message description | `getMyNewMessage` |For current gh-aw work, keep message modules aligned with the action-generation flow instead of the historical Go-embed pattern. If you need an example, review the existing safe-output modules under pkg/workflow/js/ and the generated action files under actions/.
© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/messages of github/gh-aw.
Open the folder on GitHubat commit a4ca9f2
Messages next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Messages this skillgithub/gh-aw | 5.4k | — | ~1.7k | Automated safety check: Pass | MIT | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Tailwindcss Developmentanonaddy/anonaddy | 4.9k | 10 repos | ~865 | Automated safety check: Pass | MIT | |
| Figma use_figma Plugin API Ruleswarpdotdev/warp | 65k | 4 repos | ~4.4k | Automated safety check: Pass | AGPL-3.0 | |
| Install Anti-Slop Oxlint Rulesdmmulroy/anti-slop | 5.3k | 1 repos | ~2.2k | Automated safety check: Pass | MIT | |
| GSAP Core Animationgreensock/gsap-skills | 16k | 4 repos | ~3.7k | Automated safety check: Pass | MIT |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
anonaddy/anonaddy
Always invoke when the user's message includes 'tailwind' in any form.
warpdotdev/warp
Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.
dmmulroy/anti-slop
Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.
greensock/gsap-skills
Covers the GSAP core API for tweens, easing, staggers, defaults and matchMedia, and when to choose GSAP over CSS animations or other JavaScript animation libraries.
zenstory-ai/oh-story-claudecode
Drives a Chrome window over the DevTools Protocol with the agent-browser CLI, so the agent can reuse your logged-in sessions, read pages and pull tokens.
github/gh-aw
Drives a real browser from the command line with playwright-cli to open pages, interact, mock requests, save state and work with Playwright tests.
github/gh-aw
Designs and verifies a deterministic grader that measures whether a GitHub Agentic Workflow run reached its real-world or repository outcome.
github/gh-aw
Scaffolds, edits, reloads and debugs a canvas extension that the GitHub Copilot CLI can open in its side panel.
github/gh-aw
Drives an open pull request to merge-ready from inside a GitHub Copilot cloud agent, resolving review threads and local checks concurrently, without merging or retriggering CI.
github/gh-aw
Bumps gh-aw's pinned gh-aw-firewall version, rebuilds generated artifacts, and flags upstream spec or schema changes that need follow-up work.
github/gh-aw
Guide to the console struct tag system in gh-aw: headers, titles, number and cost formats, omitempty, and how structs, slices and maps render in the terminal.
Works with
Add new safe-output message types and wire validation/rendering. Messages is an agent skill from github/gh-aw, published by the product's own GitHub organization. Add new safe-output message types and wire validation/rendering.
Run `npx skills add github/gh-aw --skill messages -a claude-code`. Or copy the skill folder (.github/skills/messages in github/gh-aw) into .claude/skills/messages in your project. Claude Code loads it when a task matches its description.
Run `npx skills add github/gh-aw --skill messages -a codex`. Or copy the skill folder (.github/skills/messages in github/gh-aw) into .agents/skills/messages in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw --skill messages -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/messages, .gemini/skills/messages, .github/skills/messages and .opencode/skills/messages in your project.
Going by SKILL.md and its folder, Messages needs the command-line tools its instructions call (make).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Messages is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Messages: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Tailwindcss Development (anonaddy/anonaddy, 4.9k stars), Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars) and Install Anti-Slop Oxlint Rules (dmmulroy/anti-slop, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
github (a GitHub organization, an official publisher) maintains it in github/gh-aw, which has 5,359 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 8, 2026.
Source: github/gh-aw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.