GitHub

Full GitHub access — issues, PRs, repos and code review from your agent

Dev Tools✓ SafeBeginnerv2.4.0
Last verified:March 2026

About

The GitHub skill gives your OpenClaw agent complete access to GitHub — creating and reviewing pull requests, managing issues, listing repositories, checking build status, browsing code and triggering workflows. For developers running OpenClaw as a coding assistant this skill is essential. It closes the loop between your agent writing code and that code actually landing in a repository. Widely used in automated PR workflows, issue triage pipelines and code review automations. Works seamlessly alongside Composio for teams that need multi-service integration.

Use Cases

  • Agent automatically creates a PR when it finishes a coding task
  • Triage and label incoming GitHub issues based on their content automatically
  • Daily standup — agent summarises all open PRs and issues across your repos
  • Code review assistant — agent reviews incoming PRs and posts structured feedback

What GitHub can access

Moderate access

Skim the SKILL.md before installing, and check which credentials it asks for against what it actually claims to do.

  • Needs your credentials

    You must supply secrets for this skill to work. A skill with a valid key can do anything that key permits, so scope each one as narrowly as the provider allows and never reuse an admin key.

    Declares 1 required credential: GITHUB_TOKEN

  • Makes outbound network calls

    It contacts external services. Outbound calls are how data leaves your machine, so it is worth knowing where it connects.

    This skill's own description refers to "integration"

These permissions are inferred from this listing — the credentials it declares, any maintainer warning, and the operations its own description mentions. ClawVault has not audited this skill's source code. Treat it as a starting point for your own review, not a substitute for one.

Installing GitHub on OpenClaw

An OpenClaw skill is a directory containing a SKILL.md file: Markdown with YAML frontmatter. At startup OpenClaw scans the eligible skill directories and injects a compressed description of each skill into its system prompt, so the agent knows what it can do and invokes a skill when a request matches.

  1. 1

    Find the skill in the registry

    openclaw skills search github-skill

    ClawHub is the public registry for OpenClaw skills. Searching first gives you the exact owner-qualified reference, which is what the install command needs. Omit the query to browse the default feed.

  2. 2

    Check what it does and who published it

    openclaw skills verify @<owner>/github-skill

    verify prints ClawHub's verification envelope, including its scan decision and, when available, a commit-pinned source URL. Add --card to read the generated Skill Card instead. Substitute the owner handle returned by the search above.

  3. 3

    Install it

    openclaw skills install @<owner>/github-skill

    Native ClawHub skills use an @owner/slug reference. By default this installs into the active workspace skills/ directory; add --global to install into the shared managed directory instead. You can also install from Git with git:owner/repo, or from a local folder with ./path.

  4. 4

    Confirm the agent can see it

    openclaw skills check

    check reports which ready skills are actually visible to the agent's prompt surface, which is the quickest way to catch a skill that installed but did not load.

Commands follow the official OpenClaw documentation. Placeholders such as <owner> are filled in by the search step, because registry references are publisher-scoped.

Requirements

API Keys & Credentials

GITHUB_TOKEN

Version & Updates

Current Version
2.4.0
Last Updated
March 21, 2026
What's New

Added PR review automation, improved issue management, better workflow triggering

Safety & verification

Listed as safe
No known issues reported for this skill in the OpenClaw ecosystem.

How OpenClaw screens skills

Since February 2026 ClawHub screens submitted skills with VirusTotal: each bundle is hashed and looked up, new bundles are scanned with Code Insight, and results drive an approve, warn or block decision with daily re-scanning. This materially reduces supply-chain risk but does not eliminate it, and independent research has found that different scanners frequently disagree about the same skill. Read the SKILL.md of anything you install, especially if it requests shell access or credentials.

Recommended

Running on a VPS?

Deploy OpenClaw, Hermes, or PicoClaw on Bluehost with the right template for the job.

Related Skills in Dev Tools