add-github skill
Add GitHub channel integration via Chat SDK. PR and issue comment threads as conversations.
Is the add-github skill safe?
Clean: nothing in its files matched our rules. We read 3 files in the folder on 2026-09-28.
No findings.
Install the add-github skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/nanocoai/nanoclaw.git /tmp/nanoclaw mkdir -p ~/.claude/skills cp -r /tmp/nanoclaw/.claude/skills/add-github ~/.claude/skills/add-github
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Add GitHub Channel
Adds GitHub support via the Chat SDK bridge. The agent participates in PR and issue comment threads. NanoClaw doesn't ship channels in trunk — this skill copies the GitHub adapter in from the channels branch.
The mechanical steps under Apply carry nc: directive fences: an agent reads the prose and applies them, and a parser can apply them deterministically from the same document. Every directive is idempotent, so the whole skill is safe to re-run; anything a parser can't apply falls back to the prose beside it.
Prerequisites
You need a dedicated GitHub bot account (not your personal account). The adapter uses this account to post replies and filters out its own messages to avoid loops. Create a free GitHub account for your bot (e.g. my-org-bot), then invite it as a collaborator with write access to the repos you want monitored.
Apply
1. Copy the adapter
Fetch the channels branch and copy the GitHub adapter into src/channels/ (overwrite — the branch is canonical):
src/channels/github.ts
src/channels/github-registration.test.ts2. Register the adapter
Append the self-registration import to the channel barrel (skipped if the line is already present). This one line is the skill's only reach-in into core:
import './github.js';3. Install the adapter package
Pinned to an exact version — the supply-chain policy rejects ranges and latest:
@chat-adapter/github@4.29.04. Build and validate
The build guards the typed createChatSdkBridge(...) core call and proves the dependency is installed (the adapter import throws if @chat-adapter/github isn't present):
pnpm run buildpnpm exec vitest run src/channels/github-registration.test.tsgithub-registration.test.ts imports the real channel barrel and asserts the registry contains github. It goes red if the import line is deleted or drifts, if the barrel fails to evaluate, or if @chat-adapter/github isn't installed (the import throws) — so it also covers the dependency from step 3.
End-to-end message delivery against a real GitHub repo is verified manually once the service is running — see Next Steps and the webhook setup below.
Credentials
1. Create a Personal Access Token for the bot account
Log in as your bot account, then:
- Go to Settings > Developer Settings > Personal Access Tokens
- Create a Fine-grained token with:
- Repository access: select the repos you want the bot to monitor
- Permissions: Pull requests (Read & Write), Issues (Read & Write)
- Copy the token
2. Set up a webhook on each repo
On each repo (logged in as the repo owner/admin):
- Go to Settings > Webhooks > Add webhook
- Payload URL: https://your-domain/webhook/github (the shared webhook server, default port 3000)
- Content type: application/json
- Secret: generate a random string (e.g. openssl rand -hex 20)
- Events: select Issue comments and Pull request review comments
3. Configure environment
Capture the three values, then write them. prompt only asks and binds the answer to a name; a separate directive consumes it — so the same prompts could feed ncl or the OneCLI vault instead of .env by swapping only the consumer. Here they go to .env (set-if-absent — a value you've already filled in is never overwritten):
Paste the Fine-grained Personal Access Token for the bot account — starts with `github_pat_`.Paste the webhook secret you generated for the repo webhook(s).Enter the bot account's GitHub username exactly (used for @-mention detection).GITHUB_TOKEN={{github_token}}
GITHUB_WEBHOOK_SECRET={{webhook_secret}}
GITHUB_BOT_USERNAME={{bot_username}}GITHUBBOTUSERNAME must match the bot account's GitHub username exactly. This is used for @-mention detection — the agent responds when someone writes @your-bot-username in a PR or issue comment.
Wiring
Ask the user: Is this a private or public repo?
- Private repo — use unknownsenderpolicy: 'public'. Only collaborators can comment anyway, so it's safe to let all comments through.
- Public repo — use unknownsenderpolicy: 'strict'. Only registered members can trigger the agent, preventing strangers from consuming agent resources. Add trusted collaborators as members (see below).
Run /manage-channels to wire the GitHub channel to an agent group, or create the rows directly with ncl. The host service must be running — ncl connects to it over a Unix socket:
# Create messaging group (one per repo)
ncl messaging-groups create --channel-type github --platform-id "github:owner/repo" \
--name "owner/repo" --is-group 1 --unknown-sender-policy <policy>
# Wire to agent group (engage mode/pattern default to the GitHub adapter's
# declared channel defaults; grab the mg id from the create output above)
ncl wirings create --messaging-group-id <mg-id> --agent-group-id <your-agent-group-id> \
--session-mode per-threadReplace with public or strict based on the user's choice above.
Adding members (for strict mode)
When using strict, add each GitHub user who should be able to trigger the agent:
# Add user (kind = 'github', id = 'github:<numeric-user-id>')
ncl users create --id "github:<user-id>" --kind github --display-name "<username>"
# Grant membership to the agent group
ncl members add --user "github:<user-id>" --group "<agent-group-id>"To find a GitHub user's numeric ID: gh api users/ --jq .id
Use per-thread session mode so each PR/issue gets its own agent session.
Next Steps
If you're in the middle of /setup, return to the setup flow now.
Otherwise, restart the service to pick up the new channel.
Run from your NanoClaw project root:
source setup/lib/install-slug.sh
launchctl kickstart -k gui/$(id -u)/$(launchd_label) # macOS
systemctl --user restart $(systemd_unit) # LinuxChannel Info
- type: github
- terminology: GitHub has "repositories" containing "pull requests" and "issues." Each PR or issue comment thread is a separate conversation.
- how-to-find-id: The platform ID is github:owner/repo (e.g. github:acme/backend). Each PR/issue becomes its own thread automatically.
- supports-threads: yes (PR and issue comment threads are native conversations)
- typical-use: Webhook-driven — the agent receives PR and issue comment events and responds in comment threads when @-mentioned. After the first mention, the thread is subscribed and the agent responds to all follow-up comments.
- default-isolation: Use per-thread session mode. Each PR or issue gets its own isolated agent session. Typically wire to a dedicated agent group if the repo contains sensitive code.
Troubleshooting
API calls return 401/403 with the token. The token must be a fine-grained PAT starting githubpat, created while logged in as the bot account (Settings → Developer Settings → Personal Access Tokens → Fine-grained tokens), with the monitored repos selected under Repository access and both Pull requests and Issues set to Read & Write. A classic ghp_ token, or one minted on your personal account, is the usual miss.
Webhook deliveries show red in the repo settings. Open Settings → Webhooks → Recent Deliveries on the repo: a 401 response means the secret in the webhook form doesn't match GITHUBWEBHOOKSECRET; a timeout means https://your-domain/webhook/github isn't publicly reachable on the shared webhook port (3000). Fix, then use Redeliver to retest without writing a new comment.
Comments never trigger the agent. The @-mention must match GITHUBBOTUSERNAME exactly, and the webhook must subscribe to Issue comments and Pull request review comments (not just pushes). Comments authored by the bot account itself are filtered by design — test from a different account than the bot.
Adapter installed but the channel is dead. Run pnpm exec vitest run src/channels/github-registration.test.ts — red means the barrel import or the @chat-adapter/github install drifted, so re-run the Apply steps. If green, restart the service (see Next Steps) so it loads the adapter and the new .env values.
More skills from nanocoai/nanoclaw
- Aadd-anydocAdd local office-document-to-Markdown conversion to NanoClaw agent containers with the pinned Firecrawl AnyDoc CLI. Use when agents need to read attached Word, PowerPoint, Excel, OpenDocument, RTF, EPUB, CSV, or text-based PDF files without uploading them to a hosted parser.
- Aadd-atomic-chat-toolAdd Atomic Chat MCP server so the container agent can call local models served by the Atomic Chat desktop app via its OpenAI-compatible API.
- Fadd-clidashAdd clidash — a zero-dependency, read-only web dashboard that derives its tabs and tables at runtime from any CLI that lists resources as JSON. Ships pre-wired for NanoClaw's ncl CLI (agent groups, sessions, channels, users, roles), plus message-activity charts, a log tail, and a read-only file viewer for group skills/CLAUDE.md/profiles.
- Aadd-codexUse Codex (OpenAI's codex app-server) as a full agent provider — planning, tool orchestration, MCP tools, server-side history, session resume — alongside or instead of Claude. ChatGPT subscription or OpenAI API key, vault-only via the selected gateway. Per-group via `ncl groups config update --provider codex`. Distinct from using OpenAI as an MCP tool (where Claude remains the planner).
- Aadd-dashboardAdd a monitoring dashboard to NanoClaw. Installs @nanoco/nanoclaw-dashboard and a pusher that sends periodic JSON snapshots.
- Aadd-deltachatAdd DeltaChat channel integration via @deltachat/stdio-rpc-server. Native adapter — no Chat SDK bridge. Email-based messaging with end-to-end encryption.
- Cadd-dialAdd Dial channel integration — a real phone number for SMS and AI voice calls via the Dial platform (getdial.ai). Native adapter — no Chat SDK bridge.
- Aadd-dial-numberAdd another phone number to an existing Dial channel — a second (or third) public line for the agent, so one NanoClaw install answers SMS and AI voice calls on multiple numbers. Use when Dial is already installed and the operator wants an additional number (e.g. a personal line plus a support line). Requires the Dial channel to already be installed (see /add-dial).
- Aadd-dial-toolGive chosen NanoClaw agents a real phone number as a container tool — the `dial` CLI baked into the agent image plus OneCLI credential injection for api.getdial.ai, scoped per agent, so the agents you pick can send SMS, place AI voice calls, and receive verification codes from inside the sandbox. Independent of the Dial channel; idempotent; re-run to change which agents may use it. Use when the user wants agents to text, call, or run `dial …` from a chat, without wiring Dial as a messaging channel.
- Aadd-discordAdd Discord bot channel integration via Chat SDK.
- Aadd-emacsAdd Emacs as a channel. Opens an interactive chat buffer and org-mode integration so you can talk to NanoClaw from within Emacs (Doom, Spacemacs, or vanilla). Local HTTP bridge — no bot token or external service needed.
- Aadd-gchatAdd Google Chat channel integration via Chat SDK.