Agent skill

Checking Pinned References

by agntcy in agntcy/coffeeAgntcy

Runs task pins:check to find any third-party GitHub Action, reusable-workflow, or image reference that isn't pinned to an immutable SHA/digest, and pins each one it finds.

Apache-2.0Auto-check passedDevOps & Cloud

Install Checking Pinned References

skills CLI
$ npx skills add agntcy/coffeeAgntcy --skill checking-pinned-references -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agntcy/coffeeAgntcy checking-pinned-references --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agntcy/coffeeAgntcy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/quality-checks/checking-pinned-references .claude/skills/checking-pinned-references && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
checking-pinned-references
GitHub stars
112
Token cost
~578 tokens
SKILL.md length
156 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runs task pins:check to find any third-party GitHub Action, reusable-workflow, or image reference that isn't pinned to an immutable SHA/digest, and pins each one it finds.

  • Editing a uses: line
  • SKILL.md covers What this skill does, Workflow and Notes
  • Calls gh and docker
  • A Dockerfile FROM instruction

What it does

Checking Pinned References is an agent skill from agntcy/coffeeAgntcy. Runs task pins:check to find any third-party GitHub Action, reusable-workflow, or image reference that isn't pinned to an immutable SHA/digest, and pins each one it finds. Use when adding or editing a uses: line, a Dockerfile FROM instruction, or a compose image: field.

Its SKILL.md is about 580 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering CI/CD and Containers. It works with Docker. The repository describes itself as: End-to-end reference application for AGNTCY Components. The licence is Apache-2.0.

When your agent uses it

  • Editing a uses: line
  • A Dockerfile FROM instruction
  • A compose image: field

Example prompts

  • “/checking-pinned-references”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit a01cbba. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Checking Pinned References loads about 578 tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 156 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~578

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from agntcy/coffeeAgntcy at commit a01cbba, republished under its Apache-2.0 licence (© agntcy). 156 words, ~578 tokens.

Download SKILL.mdSave it as .claude/skills/checking-pinned-references/SKILL.md (or your agent's skills folder).
name
checking-pinned-references
description
Runs task pins:check to find any third-party GitHub Action, reusable-workflow, or image reference that isn't pinned to an immutable SHA/digest, and pins each one it finds. Use when adding or editing a `uses:` line, a Dockerfile FROM instruction, or a compose image: field.

Checking pinned references

What this skill does

Runs task pins:check (defined in Taskfile.yaml, wrapping scripts/checks/check_pinned_references.bash) to scan every .github/workflows/*.y*ml uses: line, every Dockerfile FROM instruction, and every compose image: field for a reference pinned by a mutable tag/branch instead of an immutable commit SHA or image digest. This is the same check task check:all runs as part of checks.yaml. See .agents/rules/quality/pinned-external-references.md for the underlying rule.

Workflow

- [ ] 1. Run: task pins:check
- [ ] 2. For each flagged GitHub Actions `uses:` line, find its commit SHA:
        gh api repos/<owner>/<repo>/commits/<tag> --jq '.sha' - then pin as
        owner/repo@<40-char-sha> # <tag>
- [ ] 3. For each flagged Docker image, find its digest:
        docker buildx imagetools inspect <image>:<tag> - then pin as
        image:<tag>@sha256:<digest>
- [ ] 4. If a reference genuinely can't be pinned (no tags/digests exist
        upstream), add a `# pin-exempt: <reason>` comment stating why,
        in place of the version comment
- [ ] 5. Re-run task pins:check to confirm it's clean

Notes

  • pin-exempt is a judgment call the person/agent adding the reference makes and justifies at the point it's added - don't reach for it just to silence the check.
  • This only covers third-party references - an image this repo publishes itself (ghcr.io/agntcy/coffee-agntcy/*) using a floating tag like :latest in a dev compose file is normal usage, not a gap.
  • If a new kind of floating reference shows up that scripts/checks/check_pinned_references.bash doesn't scan for yet, extend the script to cover it rather than pinning by hand and leaving the gap for next time.

© agntcy, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/quality-checks/checking-pinned-references of agntcy/coffeeAgntcy.

Open the folder on GitHubat commit a01cbba

Compare with similar skills

Checking Pinned References next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Checking Pinned References compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Checking Pinned References this skillagntcy/coffeeAgntcy112—~578Automated safety check: PassApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
GitHub Actions CreatorFNOSP/FlyNarwhal4951 repos~2.4kAutomated safety check: PassAGPL-3.0
Swig CI Reproswig/swig6.3k—~1.2kAutomated safety check: PassCustom licence
Megatron-LM Base Image BumpNVIDIA/Megatron-LM18k—~2.8kAutomated safety check: PassApache-2.0
DDNS Build and Release MaintenanceNewFuture/DDNS4.7k—~444Automated safety check: PassMIT

Similar skills

  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • GitHub Actions Creator

    FNOSP/FlyNarwhal

    A skill your agent uses when the user wants to create, generate, or set up a GitHub Actions workflow.

    495 GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • Swig CI Repro

    swig/swig

    Reproduce a GitHub Actions Linux CI failure locally when it does not happen on your machine: a podman/docker image that mirrors the ubuntu-22.04 runner by reusing the real Tools/CI-linux-.sh install…

    6.3k GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Megatron-LM Base Image Bump

    NVIDIA/Megatron-LM

    Official

    Moves Megatron-LM CI to a newer NVIDIA PyTorch base image, updating both the GitHub and GitLab pins together and handling the CI follow-up.

    18k GitHub stars~2.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Maintains the DDNS project's GitHub Actions, Docker and Nuitka builds, packaging and release preparation without touching publishing credentials.

    4.7k GitHub stars~444 tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • PR Review

    kimdre/doco-cd

    Review pull request diffs for correctness and regressions, and provide actionable feedback when asked to review a PR.

    1.7k GitHub stars~311 tokensUpdated today
    DevOps & CloudAuto-check passed

More from agntcy/coffeeAgntcy

All 17 skills in this repo
  • A2a Protocol

    agntcy/coffeeAgntcy

    A skill your agent uses when the user asks about A2A (Agent-to-Agent) protocol communication, OASF record formats, AGNTCY directory operations, agent card parsing, or dirctl CLI usage.

    112 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Add Repo Operation

    agntcy/coffeeAgntcy

    Guides adding a new repository operation (a check, validation, or piece of tooling) through this repo's standard script - Taskfile task - skill - CI enforcement - rule pipeline.

    112 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Authors and maintains the human-facing Agentic Workflows API documentation for the lungo subproject at coffeeAGNTCY/coffeeagents/lungo/docs/workflow-instanceapi.md.

    112 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • Runs task workflows:check-permissions to find any GitHub Actions workflow file with a write-all grant or no declared permissions, and scopes it down to least privilege.

    112 GitHub stars~513 tokensUpdated yesterday
    Auto-check passed
  • Generate Release Notes

    agntcy/coffeeAgntcy

    Generates coffeeAgntcy CHANGELOG release notes and README Built With updates from PRs and dependency lockfiles since the previous release tag.

    112 GitHub stars~535 tokensUpdated yesterday
    Auto-check passed
  • Linting GitHub Workflows

    agntcy/coffeeAgntcy

    Runs task workflows:lint (actionlint) against every file under .github/workflows/ and fixes what it reports.

    112 GitHub stars~507 tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Checking Pinned References

What does Checking Pinned References do?

Runs task pins:check to find any third-party GitHub Action, reusable-workflow, or image reference that isn't pinned to an immutable SHA/digest, and pins each one it finds. Checking Pinned References is an agent skill from agntcy/coffeeAgntcy. Runs task pins:check to find any third-party GitHub Action, reusable-workflow, or image reference that isn't pinned to an immutable SHA/digest, and pins each one it finds.

When should I use Checking Pinned References?

Checking Pinned References fits situations like: editing a uses: line; A Dockerfile FROM instruction; A compose image: field.

How do I install Checking Pinned References in Claude Code?

Run `npx skills add agntcy/coffeeAgntcy --skill checking-pinned-references -a claude-code`. Or copy the skill folder (.agents/skills/quality-checks/checking-pinned-references in agntcy/coffeeAgntcy) into .claude/skills/checking-pinned-references in your project. Claude Code loads it when a task matches its description.

How do I install Checking Pinned References in Codex?

Run `npx skills add agntcy/coffeeAgntcy --skill checking-pinned-references -a codex`. Or copy the skill folder (.agents/skills/quality-checks/checking-pinned-references in agntcy/coffeeAgntcy) into .agents/skills/checking-pinned-references in your project. Codex loads it when a task matches its description.

Can I use Checking Pinned References in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agntcy/coffeeAgntcy --skill checking-pinned-references -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/checking-pinned-references, .gemini/skills/checking-pinned-references, .github/skills/checking-pinned-references and .opencode/skills/checking-pinned-references in your project.

What does Checking Pinned References need to run?

Going by SKILL.md and its folder, Checking Pinned References needs the command-line tools its instructions call (gh and docker). Our summary lists: Docker.

Does Checking Pinned References access the network?

SKILL.md contains no URLs. Its commands use gh and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Checking Pinned References safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Checking Pinned References use?

Checking Pinned References is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Checking Pinned References use?

About 578 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Checking Pinned References?

Skills that share tags, products or a category with Checking Pinned References: Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), GitHub Actions Creator (FNOSP/FlyNarwhal, 495 stars), Swig CI Repro (swig/swig, 6.3k stars) and Megatron-LM Base Image Bump (NVIDIA/Megatron-LM, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Checking Pinned References?

agntcy (a GitHub organization) maintains it in agntcy/coffeeAgntcy, which has 112 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 7, 2026.

Source: agntcy/coffeeAgntcy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.