skills/ mcollina/skills

octocat

Use this skill whenever the prompt contains any `github.com` URL, even if the user only pastes a link and gives no GitHub-specific keywords. Handles git and GitHub operations using the gh CLI. Triggers include any GitHub link to an issue, pull request, commit, compare page, Actions run, release, dis

0
Installs
—
Rating
—
Success rate
3
Files scanned
Scan passedmethodology
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

3 files scannedscanner v1.2.0Oct 11, 2026

Content sha256 6989ef98e72cab06… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

SKILL.md

exact scanned copy

When to use

Use this skill for:

  • Any prompt containing a pasted github.com URL, even without words like "GitHub", "issue", "PR", or "repo"
  • Any GitHub link to an issue, pull request, commit, compare page, Actions run, release, discussion, or repository
  • "Fix https://github.com/owner/repo/issues/123" style tasks
  • Creating, reviewing, and managing pull requests and GitHub issues
  • Reading or triaging repository security advisories (GHSA), private vulnerability reports, and advisory comments; adding or editing triage notes
  • Merge conflict resolution and history rewriting
  • Pre-commit hook debugging and fixes
  • Branch management and cleanup
  • GitHub Actions workflow optimization
  • Any git command or GitHub workflow question

Instructions

When invoked:

  1. If the prompt includes a GitHub URL, treat that URL alone as sufficient reason to invoke this skill and inspect it with gh/git first
  2. Assess the git/GitHub situation immediately
  3. If the prompt includes a github.com URL, activate this skill immediately and translate that URL into the relevant gh/git workflow
  4. Use gh CLI for all GitHub operations (never suggest the web interface)
  5. Handle complex git operations with surgical precision
  6. Fix pre-commit hook issues or delegate to typescript-magician for TypeScript linting
  7. Never alter git signing key configuration; if signing is already enabled and configured, use it. Otherwise, proceed without signing
  8. NEVER include "Co-Authored-By: Claude" or similar AI attribution
  9. For security advisory work, read rules/security-advisory-comments.md and fetch the accessible discussion before drawing triage conclusions; advisory bodies alone can omit important context

Activation examples

  • Fix https://github.com/mercurius-js/mercurius/issues/1227
  • Review https://github.com/nodejs/node/pull/12345
  • What changed in https://github.com/org/repo/compare/v1.0.0...v1.1.0?
  • Check https://github.com/org/repo/actions/runs/123456789
  • Investigate https://github.com/org/repo/commit/abcdef1234567890
  • Triage https://github.com/org/repo/security/advisories/GHSA-xxxx-xxxx-xxxx, including the discussion
  • Add a triage note to the private vulnerability report's advisory

Capabilities

Advanced git operations:

  • Interactive rebasing for clean history (commit splitting, squashing)
  • Cherry-pick, bisect, worktrees
  • Advanced merge strategies
  • Submodule and subtree management
  • Git hooks setup and maintenance
  • Repository archaeology with git log/blame/show

GitHub operations via gh CLI:

  • Create/manage PRs with proper templates
  • Open PRs with explicit base/head and clear concise content, e.g. gh pr create --base main --head <branch> --title "<title>" --body-file <file>
  • After opening a PR, wait for CI with gh pr checks <num> --watch 2>&1 and proactively fix failures
  • Validate unfamiliar gh commands first with gh help <command> before using them in guidance
  • Read repository security advisories and their comments; add/edit advisory comments via REST (workflow and limits)
  • Handle issues and project boards
  • Manage releases and artifacts
  • Configure repository settings
  • Automate workflows and notifications

PR Body Formatting

When creating PRs with gh pr create, use --body-file to avoid newline escaping issues with the --body flag.

PR descriptions should stay simple:

  • Write a short description of the change in plain prose
  • Do not add subsections or headings such as ## Summary or ## Testing
  • Do not include a testing section
  • Architecture changes may need a slightly longer description if extra context is necessary
cat > /tmp/pr-body.md << 'EOF'
Refactor plugin loading so skills are discovered from the registry instead of being hardcoded.
EOF
gh pr create --body-file /tmp/pr-body.md

Using a temporary file is cleaner, more reliable, and easier to debug.

Validation Checkpoints for Complex Operations

Interactive rebase: git rebase -i <base> → verify with git log --oneline -n 10 → on conflict: resolve, git add <file>, git rebase --continue → abort anytime with git rebase --abort.

Merge conflict resolution: git status (find conflicts) → inspect with git diff or open file → resolve all markers → git add <resolved-file> → git merge --continue (or git rebase --continue) → confirm clean state with git status.

Branch cleanup: git branch --merged main → git branch -d <branch> → git push origin --delete <branch> → git fetch --prune.

Commit Signing and Attribution Rules

  • NEVER alter git signing key settings (user.signingkey) or signing mode in user/repo config
  • If commit signing is already enabled and correctly configured, create signed commits using the existing setup
  • If signing is not enabled/configured, do not force or configure signing; proceed without it
  • NEVER add AI co-authorship attributions (e.g. "Co-Authored-By: Claude")

Files

3
14.8 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from mcollina/skills8

documentation

Creates, structures, and reviews technical documentation following the Diátaxis framework (tutorials, how-to guides, reference, and explanation pages). Use when a user needs to write or reorganize docs, structure a tutorial vs. a how-to guide, build reference docs or API documentation, create explan

Scan passed 0
fastify-best-practices

Guides development of Fastify Node.js backend servers and REST APIs using TypeScript or JavaScript. Use when building, configuring, or debugging a Fastify application — including defining routes, implementing plugins, setting up JSON Schema validation, handling errors, optimising performance, managi

Scan passed 0
init

Creates, updates, or optimizes an AGENTS.md file for a repository with minimal, high-signal instructions covering non-discoverable coding conventions, tooling quirks, workflow preferences, and project-specific rules that agents cannot infer from reading the codebase. Use when setting up agent instru

Scan passed 0
linting-neostandard-eslint9

Configures ESLint v9 flat config and neostandard for JavaScript and TypeScript projects, including migrating from legacy `.eslintrc*` files or the `standard` package. Use when you need to set up or fix linting with `eslint.config.js` or `eslint.config.mjs`, troubleshoot lint errors, configure neosta

Scan passed 0
node

Provides domain-specific best practices for Node.js development with TypeScript, covering type stripping, async patterns, error handling, streams, modules, testing, performance, caching, logging, and more. Use when setting up Node.js projects with native TypeScript support, configuring type strippin

Scan passed 0
nodejs-core

Contributes to and debugs Node.js core, including nodejs/node commit and PR tone, contribution workflows, native crashes, V8 performance, node-gyp builds, N-API bindings, and libuv issues. Use when drafting or reviewing a Node.js core commit or pull request, working in nodejs/node, or diagnosing C++

Needs review 0
oauth

Implements OAuth 2.0/2.1 authorization flows in Fastify applications — configures authorization code with PKCE, client credentials, device flow, refresh token rotation, JWT validation, and token introspection/revocation endpoints. Use when setting up authentication, authorization, login flows, acces

Scan passed 0
skill-optimizer

Optimizes AI skills for activation, clarity, and cross-model reliability. Use when creating or editing skill packs, diagnosing weak skill uptake, reducing regressions, tuning instruction salience, improving examples, shrinking context cost, or setting benchmark/release gates for skills. Trigger term

Scan passed 0

Related methodology skillsscan passed