| name | add-skill-github |
| description | Add GitHub API access to NanoTars. Enables agents to monitor repos, check PRs, issues, commits, and CI status. Guides through Personal Access Token setup. Triggers on "add github", "github setup", "github integration", "github token". |
Add GitHub
Configures GitHub API access for agent containers, enabling repo monitoring, PR/issue tracking, and CI status checks.
Preflight
Before installing, verify NanoTars is set up:
[ -d node_modules ] && echo "DEPS: ok" || echo "DEPS: missing"
docker image inspect nanoclaw-agent:latest &>/dev/null && echo "IMAGE: ok" || echo "IMAGE: not built"
if grep -q "ANTHROPIC_API_KEY\|CLAUDE_CODE_OAUTH_TOKEN" .env 2>/dev/null || [ -f "$HOME/.claude/.credentials.json" ]; then echo "AUTH: ok"; else echo "AUTH: missing"; fi
If any check fails, tell the user to run /nanotars-setup first and stop.
Prerequisites
Install
-
Create a fine-grained Personal Access Token:
- Go to https://github.com/settings/tokens?type=beta
- Click Generate new token
- Set expiration (recommended: 90 days or longer)
- Under Repository access, select repos to monitor
- Under Permissions, enable read-only for: Contents, Pull requests, Issues, Actions
- Click Generate token and copy it
-
Add to .env:
echo 'GH_TOKEN=YOUR_TOKEN_HERE' >> .env
-
Plugin Configuration -- Ask the user which groups should have access to GitHub:
- All groups (default) -- every group's agent can query repos, PRs, issues, and CI status
- Specific groups only -- e.g., only
main
If the user wants to restrict access, update plugins/github/plugin.json after copying (step 4) to set "groups" to the list of group folder names:
"groups": ["main"]
If all groups (or the user doesn't care), leave as "groups": ["*"].
Restricting access means only those groups' agents will have GitHub tools. Other groups won't see the GitHub API or credentials.
Also ask about channel types. If the user wants this plugin available on all channel types (WhatsApp, Discord, etc.), leave "channels": ["*"]. To restrict, set "channels" to specific types (e.g., ["whatsapp"]). Most users will want the default.
-
Copy plugin files:
cp -r ${CLAUDE_PLUGIN_ROOT}/files/ plugins/github/
-
Rebuild and restart:
npm run build
nanotars restart
Verify
Test the token:
source .env
curl -s -H "Authorization: Bearer $GH_TOKEN" https://api.github.com/user | python3 -c "
import sys, json
r = json.load(sys.stdin)
if 'login' in r:
print(f'OK - {r[\"login\"]}')
else:
print(f'FAILED - {r}')
"
Existing Installation (Per-Group Credentials)
If this plugin is already installed and you want different credentials for a specific group (e.g., a work account for one group, personal for another):
-
Check which groups exist:
ls -d groups/*/
-
Ask the user which group should get separate credentials.
-
Collect the new GitHub token for that group.
-
Write to the group's .env file (creates if needed):
echo 'GH_TOKEN=github_pat_...' >> groups/{folder}/.env
These values override the global .env for that group's containers only.
-
Restart NanoTars:
nanotars restart
Remove
-
rm -rf plugins/github/
- Remove
GH_TOKEN from .env
- Rebuild and restart