> Creates and updates GitHub Actions secrets for PostHog workflows. Use when adding a new CI secret, rotating an existing secret, wiring a workflow to an API token, package registry credential, deploy key, or any value referenced via `${{ secrets.* }}` in `.github/workflows/`.
npx skills add https://github.com/PostHog/posthog --skill managing-github-actions-secrets
PostHog centralizes all GitHub Actions secrets at the organization level
and grants individual repositories access to them. Do not add secrets to a
single repo, even if the secret is only consumed by one workflow today.
posthog org, not on a repo.(selected repositories). Do not make it available to all repos by default
unless the secret is genuinely meant to be shared org-wide.
files. Pipe them in, or paste them only into the GitHub UI's secret field.
gh CLIPipe the secret value into gh secret set with --org posthog. The example
below reads the value from stdin so it never appears in shell history:
# Read from clipboard / a pipe / a file — never inline as an argument
pbpaste | gh secret set POSTHOGOS_PACKAGER_KEY --org posthog
Common variants:
# From a file
gh secret set POSTHOGOS_PACKAGER_KEY --org posthog < secret.txt
# Restrict to selected repositories at creation time
gh secret set POSTHOGOS_PACKAGER_KEY --org posthog \
--visibility selected --repos PostHog/posthog,PostHog/posthog-foss
# Update which repos can access an existing org secret
gh secret set POSTHOGOS_PACKAGER_KEY --org posthog \
--visibility selected --repos PostHog/posthog
Verify:
gh secret list --org posthog | grep POSTHOGOS_PACKAGER_KEY
POSTHOGOS_PACKAGER_KEY).exact repos that need it. Avoid All repositories unless the secret is
safe to expose to every repo in the org.
gh secret set NAME without --org posthog — that creates arepo-level secret on whatever repo gh is currently pointed at.
Settings → Secrets and variables → Actions on anindividual repo to add a secret. If a repo-level secret already exists for
something that should be org-level, migrate it (create at org, grant to the
repo, then delete the repo-level copy).
accidentally exposed, rotate it immediately.
Default answer: at the org level via gh secret set --org posthog, granted
to the specific repos that need it. Only deviate if the user explicitly
overrides this (e.g. for an environment-scoped secret on a deployment
environment, which is a different mechanism).
Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node/TypeScript (MCP SDK).
Automatically creates user-facing changelogs from git commits by analyzing commit history, categorizing changes, and transforming technical commits into clear, customer-friendly release notes. Turns hours of manual changelog writing into minutes of automated generation.
Use when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for merge, PR, or cleanup
Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node/TypeScript (MCP SDK).
React Native and Expo best practices for building performant mobile apps. Use when building React Native components, optimizing list performance, implementing animations, or working with native modules. Triggers on tasks involving React Native, Expo, mobile performance, or native platform APIs.
React and Next.js performance optimization guidelines from Vercel Engineering. This skill should be used when writing, reviewing, or refactoring React/Next.js code to ensure optimal performance patterns. Triggers on tasks involving React components, Next.js pages, data fetching, bundle optimization, or performance improvements.
Next.js best practices - file conventions, RSC boundaries, data patterns, async APIs, metadata, error handling, route handlers, image/font optimization, bundling
Use when starting feature work that needs isolation from current workspace or before executing implementation plans - creates isolated git worktrees with smart directory selection and safety verification
Take posthog/managing-github-actions-secrets from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.