Skip to content
Back to skills

Github Script

ASecurity

Write robust JavaScript for GitHub Actions github-script steps.

  • 5,344 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 2, 2026
ai-agentsjavascripttypescriptjavagitdocumentation

Security analysis

A100/100

Scanned September 2, 2026

npx -y skills add github/gh-aw --skill github-script --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Github Script?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Github Script
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/github-github-script-gh-aw/badge)](https://www.skillsdirectory.com/skills/github-github-script-gh-aw)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: github-script
description: Write robust JavaScript for GitHub Actions github-script steps.
---

# GitHub Action Script Best Practices

Use these guidelines for JavaScript executed by `actions/github-script@v8`.

## Important Notes

- This action provides `@actions/core` and `@actions/github` packages globally
- Do not add import or require for `@actions/core` 
- Reference documentation:
  - https://github.com/actions/toolkit/blob/main/packages/core/README.md
  - https://github.com/actions/toolkit/blob/main/packages/github/README.md

## Best Practices

- Use `core.info`, `core.warning`, `core.error` for logging, not `console.log` or `console.error`
- Use `core.setOutput` to set action outputs
- Use `core.exportVariable` to set environment variables for subsequent steps
- Use `core.getInput` to get action inputs, with `required: true` for mandatory inputs
- Use `core.setFailed` to mark the action as failed with an error message

## Step Summary

Use `core.summary.*` function to write output the step summary file.

- Use `core.summary.addRaw()` to add raw Markdown content (GitHub Flavored Markdown supported)
- Make sure to call `core.summary.write()` to flush pending writes
- Summary function calls can be chained, e.g. `core.summary.addRaw(...).addRaw(...).write()`

## Common Errors

- Avoid `any` type as much as possible, use specific types or `unknown` instead
- Catch handler: check if error is an instance of Error before accessing message property

```js
catch (error) {
  core.setFailed(error instanceof Error ? error : String(error));
}
```

- `core.setFailed` also calls `core.error`, so do not call both

## Typechecking

Run `make js` to run the typescript compiler.

Run `make lint-cjs` to lint the files.

Run `make fmt-cjs` after editing to format the file.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…