Token导航 LogoToken导航TokenDH.com
开发敏感数据github未标认证来源可访问许可证需确认审计提醒

github-scriptGitHub script 开发

Agent Skill

用于围绕 GitHub 仓库、Issue、Pull Request、分支、提交和代码协作流程提供辅助能力。它适合让 Agent 查询项目状态、整理变更、辅助创建或检查协作事项,并把仓库中的信息转成可执行的下一步。使用时需要区分只读查询和写入操作;涉及创建 PR、修改 Issue、推送分支或访问私有仓库时,应确认 token 权限、目标仓库范围和用户授权。

总安装

192

周安装

8

GitHub Stars

公开资料未说明

下载量

64
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:github-script(GitHub script 开发)
来源仓库:https://github.com/kjanat/skills
仓库路径:skills/github-script
安装命令:
npx skills add https://github.com/kjanat/skills --skill github-script
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/kjanat/skills --skill github-script

简介

用于围绕 GitHub 仓库、Issue 和 Pull Request 提供辅助能力。

  • 适合查询项目状态、整理变更或创建协作事项。
  • 区分只读查询和写入操作,避免越权行为。
  • 涉及私有仓库或推送分支时应确认 token 权限和授权范围。
  • github-script 属于开发类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

github-script

Use for authoring or reviewing uses: actions/github-script@v8 workflow steps.

with.script runs as an async function body; use await import(...) for module imports.

Defaults

  • Pin actions/github-script@v8
  • Runtime is Node 24
  • Self-hosted runner minimum is v2.327.1
  • Prefer github.rest.* endpoint methods; use github.request(...) for raw requests.
  • Prefer ESM modules (.mjs or .js with // @ts-check); avoid CommonJS (require, module.exports).
  • If authoring helpers in TypeScript, compile to .mjs/.js and import the built file in workflow steps.

Fast workflow

  1. Define step id if downstream steps need outputs.
  2. Prefer context and context.payload for event data already provided.
  3. Pass only missing values through env.
  4. Keep inline script tiny; delegate logic to external ESM file.
  5. Read env values via process.env inside module only when needed.
  6. Use github.rest.*, github.graphql, or github.request.
  7. Return value only when output needed.
  8. Configure retries for flaky API calls.

ESM-first architecture

  • Inline script should usually do one thing: import + call exported function.
  • Put reusable logic in scripts/*.mjs modules.
  • Share logic across workflows via one core module + small entry modules.
  • Typecheck modules locally (enable checkJs in tsconfig.json or add // @ts-check for JS).
  • For .ts source files, keep runtime imports pointed at compiled JS outputs.

See references/external-files.md for patterns.

Reading order

TaskRead
Write new stepSKILL.md, references/external-files.md, references/examples.md, references/security.md
Review existing stepSKILL.md, references/security.md, references/inputs-outputs-retries.md
Migrate old workflowSKILL.md, references/runtime-and-migrations.md

Security rules

  • Never inline ${{...}} expressions directly inside script.
  • Expressions are evaluated before script; direct interpolation can cause injection or invalid JavaScript.
  • If value exists in context, use it there; do not mirror into env.
  • Use env boundary and parse/validate in script.

See references/security.md for patterns.

Script arguments available in script body

  • github: authenticated Octokit client with pagination plugins
  • octokit: alias for github
  • context: workflow run context
  • core, glob, io, exec
  • wrapped require plus escape hatch __original_require__ (legacy; prefer ESM import)

If you need source-level API details, inspect the action repo: https://github.com/actions/github-script (for example action.yml, types/async-function.d.ts, src/main.ts).

This action (upstream model)

with.script is the body of an async function. These values are pre-defined (no import needed):

Output model

  • Function return value becomes steps.<id>.outputs.result
  • Default result encoding is JSON
  • Use result-encoding: string for raw string output

Retry model

  • Enable retries with retries: <n>
  • Default retry-exempt status codes: 400,401,403,404,422
  • Override with retry-exempt-status-codes

See references/inputs-outputs-retries.md for details.

Token model

  • Default token is the action's github-token input default (typically workflow token, repo-scoped)
  • Use github-token with PAT secret for cross-repo or broader scopes

In this reference

FilePurpose
references/security.mdinjection avoidance and env-boundary patterns
references/inputs-outputs-retries.mdinputs, outputs, retry semantics
references/runtime-and-migrations.mdv5-v8 changes and upgrade checks
references/external-files.mdexternal ESM architecture, reuse, typecheck
references/examples.mdminimal templates for common tasks

Scope note

Upstream repository currently does not accept general contributions. Security fixes and major breakage fixes still maintained.

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

36.44%
按下载量换算23

Claude

28.14%
按下载量换算18

Cursor

19.31%
按下载量换算12

Gemini CLI

9.04%
按下载量换算6

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

可疑

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills