Contribute Publish
Overview
Perform exactly one approved GitHub mutation from a completed local preparation
packet. This skill has no authority to discover unrelated work, create persistent
state, install dependencies, or expand the approved scope.
Prerequisites
- A completed
contribute-prepare review packet with final content, target,
commit SHA, changed files, and passing evidence.
- GitHub CLI authenticated through the user's existing credential store.
- A clean understanding of the upstream's contribution, disclosure, CLA/DCO,
branch, and review policies.
Mandatory approval boundary
Before any external action, show all of the following:
- GitHub repository and issue or pull-request target.
- Exact action and command category (
issue comment, issue create, pr create,
pr comment, or git push).
- Complete content that will be posted, or the exact branch/ref that will be
pushed.
- Exact prepared commit SHA and changed-file list when code is involved.
- Test and lint evidence.
- Any warnings, overrides, AI-use disclosure, CLA, or DCO requirement.
Then ask for explicit approval for that exact action. Approval must appear in the
current conversation after the review packet. Earlier blanket permission,
installation, authentication, repository ownership, or approval of a different
target does not count.
Instructions
- Use Read only to inspect the final prepared packet and approved body file.
- Present the mandatory approval boundary below.
- Wait for fresh approval for the exact action.
- Execute once, read back the resulting GitHub object, and stop.
- Execute only the approved action and target.
- Use the user's existing
gh authentication; never request, read, or print a
token.
- Do not merge, force-push, approve reviews, bypass repository rules, close an
issue, or delete a branch unless that exact operation received its own review
packet and explicit approval.
- If content or the target changes after approval, present the revised packet and
ask again.
- After execution, read back the resulting GitHub object and report its URL and
authoritative state.
- On failure, report the error and stop. Do not broaden permissions or retry with
a more powerful command.
Supported actions
gh issue comment "$ISSUE_NUMBER" --repo "$REPOSITORY" --body-file "$APPROVED_FILE"
gh issue create --repo "$REPOSITORY" --title "$APPROVED_TITLE" --body-file "$APPROVED_FILE"
git -C "$APPROVED_WORKTREE" push "$APPROVED_REMOTE" "$APPROVED_REFSPEC"
gh pr create --repo "$REPOSITORY" --head "$APPROVED_HEAD" --base "$APPROVED_BASE" \
--title "$APPROVED_TITLE" --body-file "$APPROVED_FILE"
These are examples, not permission to run them. Never combine multiple mutations
under one approval unless the review packet explicitly lists each one.
Examples
publish this approved claim comment — show the final comment and target,
obtain fresh approval, post once, then read back the issue comment URL.
open the prepared pull request — verify the prepared SHA and checks, show the
exact base/head/title/body, obtain fresh approval, create once, and read back
the pull request state.
push this prepared branch — show the exact worktree, remote, commit, and
refspec; approval applies only to that push.
Output
Return the action performed, repository and target, resulting URL, resulting
state read back from GitHub, and any remaining local-only follow-up.
Error handling
| Condition |
Response |
| No fresh explicit approval |
Stop without mutation |
| Packet lacks tests, SHA, target, or final content |
Return to contribute-prepare |
| GitHub rejects the action |
Report the error; do not bypass controls |
| Target/content changed |
Invalidate approval and present a new packet |
Resources
1---2name: contribute-publish3description: Publish one prepared OSS contribution action to GitHub after a fresh human approval boundary. Shows the exact target, content, command, commit, and test evidence before any mutation. Use when local preparation is complete and the user explicitly asks to post a claim, create a Design Issue, comment, push a branch, or open a pull request. Trigger with "/contribute-publish" or "publish this prepared contribution".4license: MIT5---6
7# Contribute Publish
8
9## Overview
10
11Perform exactly one approved GitHub mutation from a completed local preparation
12packet. This skill has no authority to discover unrelated work, create persistent
13state, install dependencies, or expand the approved scope.
14
15## Prerequisites
16
17- A completed `contribute-prepare` review packet with final content, target,
18 commit SHA, changed files, and passing evidence.
19- GitHub CLI authenticated through the user's existing credential store.
20- A clean understanding of the upstream's contribution, disclosure, CLA/DCO,
21 branch, and review policies.
22
23## Mandatory approval boundary
24
25Before any external action, show all of the following:
26
271. GitHub repository and issue or pull-request target.
282. Exact action and command category (`issue comment`, `issue create`, `pr create`,
29 `pr comment`, or `git push`).
303. Complete content that will be posted, or the exact branch/ref that will be
31 pushed.
324. Exact prepared commit SHA and changed-file list when code is involved.
335. Test and lint evidence.
346. Any warnings, overrides, AI-use disclosure, CLA, or DCO requirement.
35
36Then ask for explicit approval for that exact action. Approval must appear in the
37current conversation after the review packet. Earlier blanket permission,
38installation, authentication, repository ownership, or approval of a different
39target does not count.
40
41## Instructions
42
431. Use Read only to inspect the final prepared packet and approved body file.
442. Present the mandatory approval boundary below.
453. Wait for fresh approval for the exact action.
464. Execute once, read back the resulting GitHub object, and stop.
47
48- Execute only the approved action and target.
49- Use the user's existing `gh` authentication; never request, read, or print a
50 token.
51- Do not merge, force-push, approve reviews, bypass repository rules, close an
52 issue, or delete a branch unless that exact operation received its own review
53 packet and explicit approval.
54- If content or the target changes after approval, present the revised packet and
55 ask again.
56- After execution, read back the resulting GitHub object and report its URL and
57 authoritative state.
58- On failure, report the error and stop. Do not broaden permissions or retry with
59 a more powerful command.
60
61## Supported actions
62
63```bash
64gh issue comment "$ISSUE_NUMBER" --repo "$REPOSITORY" --body-file "$APPROVED_FILE"
65gh issue create --repo "$REPOSITORY" --title "$APPROVED_TITLE" --body-file "$APPROVED_FILE"
66git -C "$APPROVED_WORKTREE" push "$APPROVED_REMOTE" "$APPROVED_REFSPEC"
67gh pr create --repo "$REPOSITORY" --head "$APPROVED_HEAD" --base "$APPROVED_BASE" \
68 --title "$APPROVED_TITLE" --body-file "$APPROVED_FILE"
69```
70
71These are examples, not permission to run them. Never combine multiple mutations
72under one approval unless the review packet explicitly lists each one.
73
74## Examples
75
76- `publish this approved claim comment` — show the final comment and target,
77 obtain fresh approval, post once, then read back the issue comment URL.
78- `open the prepared pull request` — verify the prepared SHA and checks, show the
79 exact base/head/title/body, obtain fresh approval, create once, and read back
80 the pull request state.
81- `push this prepared branch` — show the exact worktree, remote, commit, and
82 refspec; approval applies only to that push.
83
84## Output
85
86Return the action performed, repository and target, resulting URL, resulting
87state read back from GitHub, and any remaining local-only follow-up.
88
89## Error handling
90
91| Condition | Response |
92|---|---|
93| No fresh explicit approval | Stop without mutation |
94| Packet lacks tests, SHA, target, or final content | Return to `contribute-prepare` |
95| GitHub rejects the action | Report the error; do not bypass controls |
96| Target/content changed | Invalidate approval and present a new packet |
97
98## Resources
99
100- [Approval contract](references/approval-contract.md)
101- [GitHub CLI authentication](https://cli.github.com/manual/gh_auth_status)