Github AutomationCAUTION
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
Overview
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
3e0c089e8335OBSERVED · 2026-09-28What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: github-automation description: > GitHub workflow automation, PR management, issue tracking, and code review coordination. Integrates with GitHub Actions and repository management. Use when: PR creation, code review, issue management, release automation, workflow setup. Skip when: local-only changes, non-GitHub repositories. --- # GitHub Automation Skill ## Purpose GitHub workflow automation, PR management, and repository coordination. ## When to Trigger - Creating pull requests - Managing issues - Setting up CI/CD workflows - Code review automation - Release management ## Commands ### Create Pull Request ```bash gh pr create --title "feat: description" --body "## Summary\n..." ``` ### Review Code ```bash npx claude-flow github review --pr 123 ``` ### Manage Issues ```bash npx claude-flow github issues list --state open npx claude-flow github issues create --title "Bug: ..." ``` ### Setup Workflow ```bash npx claude-flow workflow create --template ci ``` ### Release Management ```bash npx claude-flow deployment release --version 1.0.0 ``` ## Agent Types | Agent | Role | |-------|------| | `pr-manager` | Pull request lifecycle | | `code-review-swarm` | Automated code review | | `issue-tracker` | Issue management | | `release-manager` | Release automation | | `workflow-automation` | GitHub Actions | ## Best Practices 1. Use conventional commits 2. Require reviews before merge 3. Run CI on all PRs 4. Automate release notes
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (4)
crates
plugin/agents
plugin/commands
plugin/skills
Gates applied: no_behavioural_pass.
3e0c089e8335full audit observations/trust-audit/skill/ruvnet__github-automation.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | 3e0c089e8335 | CAUTION | B | 89 | first audit |
Questions
What does the Github Automation skill do?
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
Is Github Automation safe to install?
With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Github Automation access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (3e0c089e8335), read on 2026-09-28. The repository is watched, and a new audit runs when it changes — this is the first audit.