← Back to Skills Marketplace
jeromestein

Code Share

by Jiayi Wang · GitHub ↗ · v0.2.0
cross-platform ✓ Security Clean
811
Downloads
2
Stars
1
Active Installs
1
Versions
Install in OpenClaw
/install code-share
Description
Share code via GitHub Gist instead of inline chat blocks. Use when code output exceeds 10 lines, when the user asks for copy-friendly code sharing in Discord...
README (SKILL.md)

Gist Code Share

When returning code:

  1. If code is 10 lines or fewer, inline code block is allowed.
  2. If code is over 10 lines, prefer GitHub Gist.
  3. Default to secret gist unless user asks for public.
  4. Return a short summary + gist URL; avoid pasting long duplicate code in chat.
  5. Never publish secrets in shared code. If sensitive values are needed, use placeholders and tell user to fill them locally.

Required checks

  • Verify GitHub CLI auth: gh auth status
  • If not authenticated (or missing gist scope), ask user to run: gh auth login
  • Keep behavior simple: do not auto-fallback to alternate sharing backends by default; prefer guiding user to configure GitHub properly.

Sensitive data policy (mandatory)

Before sharing code, scan for sensitive data and remove it.

  • Never include API keys, tokens, passwords, private keys, cookies, session IDs, webhook secrets, phone/email PII, or absolute local secret paths.
  • If code requires secrets, replace with placeholders, for example:
    • API_KEY="\x3CFILL_ME>"
    • TOKEN="\x3CYOUR_TOKEN_HERE>"
    • .env entry with empty value
  • Add a short note telling the user to fill placeholders locally after copying.

Update mode (same URL)

When user asks to modify previously shared code, prefer updating the same gist link (new revision) instead of creating a new gist.

Use:

./scripts/update_gist.sh \x3Cgist_url_or_id> \x3Cfile> "\x3Cshort description>" [public|secret] [lang]

Behavior:

  • Keep the same gist URL.
  • Save changes as a new revision.
  • Return the same fixed 3-line response format.

Create a new gist only when:

  • user explicitly asks for a new link, or
  • existing gist is not editable by current GitHub account.

Create gist

Use:

gh gist create \x3Cfile> --desc "\x3Cshort description>"

If code is generated in-session, write it to a temp file in workspace first. Use language-appropriate extension (.py, .js, .ts, etc.) so Gist syntax highlighting works well.

With bundled script:

./scripts/create_gist.sh \x3Cfile> "\x3Cshort description>" [public|secret] [lang]

If \x3Cfile> has no extension, pass [lang] (for example python, typescript) so the script can upload with a proper extension.

Default behavior: do not use --web (automation-friendly). Optional: use --web only when the user explicitly asks to open the gist in browser immediately.

Response format (fixed)

Always use exactly this 3-line format:

  1. One sentence on what was shared.
  2. Gist URL (separate line).
  3. File: \x3Cfilename> · Lines: \x3Cline_count>

Example:

Shared the full script as a secret Gist for clean copy/paste. https://gist.github.com/... File: lc761_solution.py · Lines: 42

Usage Guidance
This skill appears to do what it says: create and update GitHub Gists via the gh CLI. Before installing or using it: 1) Ensure the GitHub CLI (gh) is installed and authenticated with gist scope — SKILL.md expects gh but registry metadata omitted that requirement. 2) Review and be comfortable with gh's stored authentication on your machine (gh uses your GitHub token); the scripts call gh api/gh gist which operate with that account. 3) Remember that 'secret' gists are unlisted but not private to GitHub — anyone with the link can view them. 4) The skill includes a sensible sensitive-data policy; nevertheless, avoid uploading real secrets and verify placeholders are used. If you need stronger guarantees (audit logs, org-owned gists, or access controls), modify workflow to use an org/service account with appropriate governance rather than a personal gh token.
Capability Analysis
Type: OpenClaw Skill Name: code-share Version: 0.2.0 The skill is designed to share code via GitHub Gist, with explicit instructions in SKILL.md for the AI agent to prioritize secret gists and strictly remove sensitive data (API keys, tokens, PII) before sharing. The accompanying shell scripts (`create_gist.sh`, `update_gist.sh`) implement this functionality using the standard `gh` CLI, employing safe practices like `mktemp` for temporary files and quoting arguments. There is no evidence of malicious intent, data exfiltration beyond the stated purpose, persistence mechanisms, or prompt injection attempts to subvert the agent's security directives.
Capability Assessment
Purpose & Capability
Name/description (share code via Gist) align with the scripts and SKILL.md. However, the registry metadata lists no required binaries while the instructions and scripts require the GitHub CLI (gh). This is likely a metadata omission rather than malicious, but it is an inconsistency.
Instruction Scope
SKILL.md restricts behavior to creating/updating GitHub Gists via gh, scanning for secrets, and writing temp files for upload. It does not instruct reading unrelated system files or transmitting data to unexpected endpoints. The sensitive-data policy is explicit and appropriate.
Install Mechanism
There is no install spec (instruction-only), and the included shell scripts are simple wrappers around the gh CLI. No remote downloads or archive extraction are present. Low install risk.
Credentials
The skill does not request environment variables or credentials itself. It relies on the user's gh CLI authentication (stored/managed by gh). That is proportionate for a GitHub Gist integration.
Persistence & Privilege
always is false, no requests to modify other skills or global agent settings, and the scripts only operate on files passed to them and temporary files they create. No elevated persistence requested.
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install code-share
  3. After installation, invoke the skill by name or use /code-share
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v0.2.0
Add update mode, security policy, language-extension hinting, and concise sharing workflow docs.
Metadata
Slug code-share
Version 0.2.0
License
All-time Installs 1
Active Installs 1
Total Versions 1
Frequently Asked Questions

What is Code Share?

Share code via GitHub Gist instead of inline chat blocks. Use when code output exceeds 10 lines, when the user asks for copy-friendly code sharing in Discord... It is an AI Agent Skill for Claude Code / OpenClaw, with 811 downloads so far.

How do I install Code Share?

Run "/install code-share" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.

Is Code Share free?

Yes, Code Share is completely free (open-source). You can download, install and use it at no cost.

Which platforms does Code Share support?

Code Share is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created Code Share?

It is built and maintained by Jiayi Wang (@jeromestein); the current version is v0.2.0.

💬 Comments