Skip to content
Back to skills

Github Delivery Watchdog

ASecurity

Periodically check pull requests and merge only current heads with independent review, tests, and passing CI.

  • 151 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 21, 2026
toolsgit

Works with

  • cli

Security analysis

A100/100

Pro scans all 6 files and shows the line behind each finding

Scanned September 21, 2026

npx -y skills add OpenHands/extensions --skill github-delivery-watchdog --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Github Delivery Watchdog?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Github Delivery Watchdog
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/openhands-github-delivery-watchdog/badge)](https://www.skillsdirectory.com/skills/openhands-github-delivery-watchdog)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: github-delivery-watchdog
description: Periodically check pull requests and merge only current heads with independent review, tests, and passing CI.
triggers:
- /github-delivery-watchdog
---

# GitHub delivery watchdog

This is a deterministic scheduled host command. It creates no agent or
conversation and needs no agent profile. Configure a repository-scoped
fine-grained PAT with Contents and Issues read/write plus Pull requests, Actions,
Commit statuses, and Metadata read. Contents write permits merge; Issues write
retains the review label when the branch is updated. Never put the token value in
the automation definition.

Package `scripts/worker.py` as `worker.py` and the shared
`scripts/github_client.py` as `github_client.py`.
The catalog bundle declares these exact files. Its `config.json` supplies
`repos`, `branch_prefix`, and the saved secret name. The shared GitHub client
resolves only that named secret. Automation owns scheduling and cancellation.

Set `branch_prefix` (default `openhands/issue`), `base_branch` (defaults to the repository's default branch),
and `required_workflow_ids` when particular Actions workflows must run. The
watchdog requires `software-factory/tests` and `software-factory/review` success
statuses on the exact head, all other statuses and Actions passing, a current
base, a non-draft PR, and GitHub reporting it mergeable. Missing, pending, failed,
or inaccessible evidence does not permit merge. A changed head requires fresh
review and tests. When an accepted branch is behind the base, the watchdog asks
GitHub to update it and retains the review trigger label; it considers the new
head only on a later run. The merge request includes the expected head SHA.

Actions are optional when `required_workflow_ids` is empty; the two acceptance
statuses remain mandatory. Configure workflow IDs when GitHub Actions must also
supply evidence. Branch protection remains GitHub's final merge gate.

Files in this skill

  • .plugin/plugin.json256 B
  • README.md531 B
  • SKILL.md1.9 KB
  • commands/github-delivery-watchdog.md281 B
  • scripts/github_client.py37 B
  • scripts/worker.py3.8 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…