Agent skill

Vellum GitHub App Setup

by vellum-ai in vellum-ai/vellum-assistant

Create and configure a GitHub App so the assistant can push commits, open PRs, and comment under its own bot identity.

MITAuto-check passedDevelopment

Install Vellum GitHub App Setup

skills CLI
$ npx skills add vellum-ai/vellum-assistant --skill vellum-github-app-setup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vellum-ai/vellum-assistant vellum-github-app-setup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vellum-ai/vellum-assistant.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vellum-github-app-setup .claude/skills/vellum-github-app-setup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vellum-github-app-setup
GitHub stars
1.4k
Token cost
~3.1k tokens
SKILL.md length
1,237 words
Files
4 (incl. scripts, assets)
Skills in repo
108
Repo updated
First seen
Licence
MIT

At a glance

Create and configure a GitHub App so the assistant can push commits, open PRs, and comment under its own bot identity.

  • Works in 6 steps: Create the GitHub App → Store Credentials → Install the App on Repositories → …
  • The user wants the assistant to have its own GitHub identity
  • SKILL.md covers Overview, What Gets Created, Prerequisites and Setup Flow, plus 4 more sections
  • Runs Python and JavaScript scripts from its folder; calls git, bun and python3; reaches github.com and api.github.com

What it does

Vellum GitHub App Setup is an agent skill from vellum-ai/vellum-assistant. Create and configure a GitHub App so the assistant can push commits, open PRs, and comment under its own bot identity. Use when the user wants the assistant to have its own GitHub identity, or when setting up git push access for the first time.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and assets (for example `scripts/create-github-app.py`). Compatibility notes: Designed for Vellum personal assistants. Requires Python 3, bun, and the assistant credentials CLI.

It sits in Development, covering Git workflow. It works with GitHub and Git. The repository describes itself as: An AI Assistant that’s easy to setup, does your work 24/7, knows your preferences and gets better over time. The licence is MIT.

When your agent uses it

  • The user wants the assistant to have its own GitHub identity
  • Setting up git push access for the first time

Example prompts

  • “/vellum-github-app-setup”

Requirements

  • Python 3
  • Node.js
  • Compatibility (from SKILL.md): Designed for Vellum personal assistants. Requires Python 3, bun, and the assistant credentials CLI.

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Create the GitHub App
  2. Store Credentials
  3. Install the App on Repositories
  4. Configure Git
  5. Set the App Logo (Optional)
  6. Verify

What it can do on your machine

Read from SKILL.md and the folder at commit c92ead1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python and JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • bun
    • python3
    • jq
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • api.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Vellum personal assistants. Requires Python 3, bun, and the assistant credentials CLI.

    From compatibility in the SKILL.md frontmatter.

Context cost

Vellum GitHub App Setup loads about 3.1k tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 1,237 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from vellum-ai/vellum-assistant at commit c92ead1, republished under its MIT licence (© vellum-ai). 1,237 words, ~3,071 tokens.

Download SKILL.mdSave it as .claude/skills/vellum-github-app-setup/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
vellum-github-app-setup
description
Create and configure a GitHub App so the assistant can push commits, open PRs, and comment under its own bot identity. Use when the user wants the assistant to have its own GitHub identity, or when setting up git push access for the first time.
compatibility
Designed for Vellum personal assistants. Requires Python 3, bun, and the assistant credentials CLI.
metadata.icon
assets/icon.svg
metadata.emoji
🤖
metadata.author
vellum-ai
metadata.version
1.0

Overview

This skill creates a GitHub App under a GitHub organization, giving the assistant its own bot identity for git operations. After setup, commits, PRs, and comments will attribute to <app-name>[bot] instead of the user's personal account.

Total manual effort: 7 interactions — Continue to GitHub → Create App → 3 secure credential prompts → Install on repo → (optional) upload avatar. Everything else is automated.

Note: This skill currently supports GitHub organizations only, not personal accounts.

What Gets Created

  • A GitHub App owned by the org (not the user's personal account)
  • Installation on selected repositories with configurable permissions (default: contents:write, pull_requests:write, checks:read, metadata:read)
  • Credentials stored in the assistant's encrypted vault (7 fields)
  • Token helper script at bin/gh-app-token.mjs (in the workspace root) for refreshing auth tokens

Prerequisites

  • User must be an admin of the GitHub organization
  • User must be logged into GitHub in their browser
  • The assistant credentials CLI must be available
  • Python 3 on the host machine (for the manifest flow server)
  • bun in the container (for the token helper script)

Setup Flow

Step 1: Create the GitHub App

Run the manifest flow script on the user's host machine (it needs to open a browser and catch a localhost callback):

bash
python3 scripts/create-github-app.py \
  --org=ORG_NAME \
  --name=APP_NAME \
  --url="https://example.com" \
  --output=/tmp/github-app-credentials.json

This starts a local server on localhost:29170, opens the browser, and guides the user through two clicks:

  1. "Continue to GitHub" — submits the pre-filled manifest form
  2. "Create GitHub App for ORG" — confirms on GitHub's page

The callback server catches the redirect and exchanges the code for credentials automatically. The credentials JSON is saved to --output.

Important manifest details (learned the hard way):

  • hook_attributes MUST include a nested url field, even if webhooks are disabled. Without it, GitHub rejects the manifest with a misleading "url" wasn't supplied error — it's not about the top-level url.
  • The form must use <input type="text"> (not hidden) with the value set via JSON.stringify() in JavaScript.
  • A state query parameter must be included on the form action URL.
  • The redirect_url must point to the local callback server.
Step 2: Store Credentials

The credentials JSON from Step 1 lives on the user's host. Store the non-secret identifier fields inline, then collect the secret fields from the user via the secure prompt.

Non-secret fields — read them from the credentials JSON and store them inline. These values come from the manifest API exchange (never typed or pasted by the user), so pass --generated:

bash
assistant credentials set --service github-app --field app_id "APP_ID" --generated
assistant credentials set --service github-app --field app_slug "APP_SLUG" --generated
assistant credentials set --service github-app --field client_id "CLIENT_ID" --generated

Secret fields (client_secret, webhook_secret, and the private key) — never read these into the conversation, ask for them in chat, or pass them inline to assistant credentials set (the CLI refuses inline user-supplied secrets). Collect each one with assistant credentials prompt — a secure input whose value never enters the chat transcript — and have the user copy the values out of the credentials JSON on their host:

bash
assistant credentials prompt --service github-app --field client_secret \
  --label "GitHub App Client Secret" \
  --description "Copy the client_secret value from the credentials JSON (e.g. /tmp/github-app-credentials.json)"
assistant credentials prompt --service github-app --field webhook_secret \
  --label "GitHub App Webhook Secret" \
  --description "Copy the webhook_secret value from the credentials JSON"

For the PEM (private key), the secure prompt input is single-line — pasting a multi-line key strips its newlines and the mangled key fails JWT signing. Have the user base64-encode the key to a single line on their host and paste that into the secure prompt. It is stored as field pem_b64; scripts/gh-app-token.mjs (copied into the workspace in Step 4) is the sole decode site — it reveals and base64-decodes the key internally at JWT-signing time, so the plaintext PEM never appears anywhere. If a step genuinely needs the decoded key in a shell, capture it in a variable — PEM="$(assistant credentials reveal --service github-app --field pem_b64 | base64 -d)" — and never run the reveal|decode pipeline bare: it prints the private key into the transcript, evading every redaction layer. Print the single-line value for copying:

bash
jq -r .pem /tmp/github-app-credentials.json | base64 | tr -d '\n'
bash
assistant credentials prompt --service github-app --field pem_b64 \
  --label "GitHub App Private Key (base64-encoded PEM)" \
  --description "Paste the single-line output of: jq -r .pem /tmp/github-app-credentials.json | base64 | tr -d '\n'"

Note: The installation_id credential is stored in Step 3 after installing the app.

Step 3: Install the App on Repositories

Open the installation page for the user:

https://github.com/apps/APP_SLUG/installations/select_target

The user selects the org, chooses "Only select repositories", picks the target repos, and clicks Install.

After installation, retrieve the installation ID using the app's JWT auth. Generate a JWT from the stored credentials:

javascript
// Use the JWT generation logic from gh-app-token.mjs,
// but call /app/installations instead of /access_tokens
const resp = await fetch("https://api.github.com/app/installations", {
  headers: {
    Authorization: `Bearer ${jwt}`,
    Accept: "application/vnd.github+json",
  },
});
const installations = await resp.json();
// installations[0].id is the installation ID

Then store it (an API-derived identifier, so --generated applies):

bash
assistant credentials set --service github-app --field installation_id "INSTALLATION_ID" --generated
Step 4: Configure Git

Copy the token helper to the workspace:

bash
cp scripts/gh-app-token.mjs "$WORKSPACE_ROOT/bin/gh-app-token.mjs"
chmod +x "$WORKSPACE_ROOT/bin/gh-app-token.mjs"

Configure the local repo clone:

bash
cd "$WORKSPACE_ROOT/REPO_NAME"
git config user.name "APP_SLUG[bot]"
git config user.email "APP_ID+APP_SLUG[bot]@users.noreply.github.com"

Before each push, refresh the remote URL with a fresh token (tokens expire after 1 hour):

bash
TOKEN=$(bun "$WORKSPACE_ROOT/bin/gh-app-token.mjs")
git remote set-url origin "https://x-access-token:${TOKEN}@github.com/OWNER/REPO.git"
git push origin BRANCH
Step 5: Set the App Logo (Optional)

The manifest flow does not support setting a logo — there's no field for it and no REST API endpoint. The logo can only be uploaded through the GitHub web UI.

If the assistant has an avatar (typically at data/avatar/avatar-image.png in the workspace root), send it to the user as a chat attachment:

<vellum-attachment source="sandbox" path="data/avatar/avatar-image.png" />

Then direct them to the app settings page to upload it:

https://github.com/organizations/ORG/settings/apps/APP_SLUG

Scroll to "Display information" → "Upload a logo" → drag in the image file → Save.

Show full SKILL.md (466 more words)Show less
Step 6: Verify

Test the full flow:

  1. Create a test branch
  2. Commit a trivial change
  3. Push the branch
  4. Open a PR via the GitHub API (using the installation token as a Bearer token)
  5. Post a comment on the PR via the GitHub API
  6. Verify the commit, PR, and comment all attribute to APP_SLUG[bot]
  7. Close the PR and delete the branch

Token Refresh

Installation tokens expire after 1 hour. The helper script gh-app-token.mjs generates a fresh one each time by:

  1. Reading app_id and pem_b64 from the vault (base64-decoding the key before signing)
  2. Signing a JWT with the private key
  3. Exchanging the JWT for an installation token via POST /app/installations/{id}/access_tokens

Always refresh before pushing:

bash
TOKEN=$(bun "$WORKSPACE_ROOT/bin/gh-app-token.mjs")
git remote set-url origin "https://x-access-token:${TOKEN}@github.com/OWNER/REPO.git"

Permission Reference

The default permission set covers the full range of actions the assistant may need to perform on a repository:

PermissionLevelPurpose
contentswritePush commits, create/delete branches
pull_requestswriteOpen PRs, post PR comments and reviews
checksreadRead CI check-run status (e.g. gh pr checks)
metadatareadRequired by GitHub for all App installations (auto-added)

Credential Reference

All credentials are stored under service: github-app:

FieldDescriptionWhen Set
app_idNumeric GitHub App IDStep 2
app_slugURL-friendly app name (e.g. credence-the-bot)Step 2
client_idOAuth client IDStep 2
client_secretOAuth client secretStep 2
pem_b64Base64-encoded (single-line) RSA private key; decoded at JWT-signing timeStep 2
webhook_secretWebhook verification secretStep 2
installation_idNumeric installation ID for the orgStep 3

Troubleshooting

"url wasn't supplied" error during manifest submission

The manifest JSON must include hook_attributes.url — a nested URL inside the hook_attributes object. GitHub's error message is misleading; it's not referring to the top-level url field.

Token generation fails

Check that all three required credentials are set: app_id, pem_b64, installation_id. Use assistant credentials list --search github-app to verify.

Push rejected with 403

The installation token may have expired (1-hour lifetime). Regenerate with bun bin/gh-app-token.mjs (from the workspace root) and update the remote URL.

PEM won't store or fails JWT signing

The secure prompt input is single-line, so a raw multi-line PEM cannot be pasted into it — newlines are stripped and the mangled key fails JWT signing. Re-store the key base64-encoded as pem_b64 using the procedure in Step 2. Never paste the PEM into chat, write it to a host file the agent reads, pass it inline to assistant credentials set, or run the reveal|decode pipeline bare — those paths leak the key into the transcript.

Port 29170 already in use

Another process is using the callback port. Either kill it or pass --port=DIFFERENT_PORT to the creation script.

App only shows for orgs, not personal accounts

The manifest flow script currently only supports organization-owned apps (it uses the /organizations/{org}/settings/apps/new endpoint). Personal account apps would use /settings/apps/new instead — this is not yet implemented.

© vellum-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, assets) in skills/vellum-github-app-setup of vellum-ai/vellum-assistant.

  • SKILL.md
  • assets/icon.svg
  • scripts/create-github-app.py
  • scripts/gh-app-token.mjs

Open the folder on GitHubat commit c92ead1

Compare with similar skills

Vellum GitHub App Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vellum GitHub App Setup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vellum GitHub App Setup this skillvellum-ai/vellum-assistant1.4k—~3.1kAutomated safety check: PassMIT
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Create Pull Requestcline/cline70k1 repos~1.6kAutomated safety check: PassApache-2.0
Release Bumpjamiepine/voicebox57k—~1.1kAutomated safety check: PassMIT
Creating Description For Gh PRredis/jedis12k—~838Automated safety check: PassMIT
Create Pull Request with Work Item IDmakeplane/plane61k—~824Automated safety check: PassAGPL-3.0

Similar skills

  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Release Bump

    jamiepine/voicebox

    Ends a release cycle by moving the Unreleased changelog notes under a dated version heading, bumping version files with bumpversion and tagging the commit.

    57k GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Official

    Generate a clear, concise GitHub PR title and description from the diff between two local git branches, and save it to prDescription.md in the repo root.

    12k GitHub stars~838 tokensUpdated today
    DevelopmentAuto-check passed
  • Opens a pull request for the current branch using the repo's template, a work item ID in the title and a description filled in from the actual diff.

    61k GitHub stars~824 tokensUpdated today
    DevelopmentAuto-check passed
  • React Router Pull Request Creator

    remix-run/react-router

    Packages finished React Router work into a draft pull request: branch, commit, push, a written PR body and the right GitHub labels.

    57k GitHub stars~2.5k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from vellum-ai/vellum-assistant

All 108 skills in this repo
  • Discord App Setup

    vellum-ai/vellum-assistant

    Connect a Discord bot to the assistant via the Discord Gateway with guided application creation and intent configuration

    1.4k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Sentry App Setup

    vellum-ai/vellum-assistant

    Create and configure a Sentry internal integration so the assistant can manage issues, alerts, and releases under its own identity

    1.4k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Memory Corpus Ingest

    vellum-ai/vellum-assistant

    Ingest a large dataset into memory as a skimmed map. An agent skill from vellum-ai/vellum-assistant.

    1.4k GitHub stars~3k tokensUpdated today
    Auto-check: notes
  • Plugin Builder

    vellum-ai/vellum-assistant

    A skill your agent uses when the user wants to build, scaffold, ship, or edit a Vellum plugin that bundles multiple surfaces (hooks, tools, skills, and more) into one installable package.

    1.4k GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Slack App Setup

    vellum-ai/vellum-assistant

    Connect a Slack app to the Vellum Assistant via Socket Mode.

    1.4k GitHub stars~2.5k tokensUpdated today
    Auto-check: warnings
  • Amazon

    vellum-ai/vellum-assistant

    Shop on Amazon and Amazon Fresh through your browser. An agent skill from vellum-ai/vellum-assistant.

    1.4k GitHub stars~1.2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Vellum GitHub App Setup

What does Vellum GitHub App Setup do?

Create and configure a GitHub App so the assistant can push commits, open PRs, and comment under its own bot identity. Vellum GitHub App Setup is an agent skill from vellum-ai/vellum-assistant. Create and configure a GitHub App so the assistant can push commits, open PRs, and comment under its own bot identity.

When should I use Vellum GitHub App Setup?

Vellum GitHub App Setup fits situations like: the user wants the assistant to have its own GitHub identity; setting up git push access for the first time.

How do I install Vellum GitHub App Setup in Claude Code?

Run `npx skills add vellum-ai/vellum-assistant --skill vellum-github-app-setup -a claude-code`. Or copy the skill folder (skills/vellum-github-app-setup in vellum-ai/vellum-assistant) into .claude/skills/vellum-github-app-setup in your project. Claude Code loads it when a task matches its description.

How do I install Vellum GitHub App Setup in Codex?

Run `npx skills add vellum-ai/vellum-assistant --skill vellum-github-app-setup -a codex`. Or copy the skill folder (skills/vellum-github-app-setup in vellum-ai/vellum-assistant) into .agents/skills/vellum-github-app-setup in your project. Codex loads it when a task matches its description.

Can I use Vellum GitHub App Setup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vellum-ai/vellum-assistant --skill vellum-github-app-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vellum-github-app-setup, .gemini/skills/vellum-github-app-setup, .github/skills/vellum-github-app-setup and .opencode/skills/vellum-github-app-setup in your project.

What does Vellum GitHub App Setup need to run?

Going by SKILL.md and its folder, Vellum GitHub App Setup needs Python and JavaScript for the scripts in its folder and the command-line tools its instructions call (git, bun, python3, jq and gh). Our summary lists: Python 3; Node.js. Compatibility (from SKILL.md): Designed for Vellum personal assistants. Requires Python 3, bun, and the assistant credentials CLI..

Does Vellum GitHub App Setup access the network?

SKILL.md names 2 domains. In commands or code: github.com and api.github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Vellum GitHub App Setup safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Vellum GitHub App Setup use?

Vellum GitHub App Setup is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vellum GitHub App Setup use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vellum GitHub App Setup?

Skills that share tags, products or a category with Vellum GitHub App Setup: Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars), Create Pull Request (cline/cline, 70k stars), Release Bump (jamiepine/voicebox, 57k stars) and Creating Description For Gh PR (redis/jedis, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vellum GitHub App Setup?

vellum-ai (a GitHub organization) maintains it in vellum-ai/vellum-assistant, which has 1,397 GitHub stars. The repository holds 108 skills in this directory. The repository was last updated on October 7, 2026.

Source: vellum-ai/vellum-assistant on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.