Senior DevOps Toolkit
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
Runs task pins:check to find any third-party GitHub Action, reusable-workflow, or image reference that isn't pinned to an immutable SHA/digest, and pins each one it finds.
$ npx skills add agntcy/coffeeAgntcy --skill checking-pinned-references -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install agntcy/coffeeAgntcy checking-pinned-references --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/agntcy/coffeeAgntcy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/quality-checks/checking-pinned-references .claude/skills/checking-pinned-references && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "checking-pinned-references" agent skill from https://github.com/agntcy/coffeeAgntcy/tree/main/.agents/skills/quality-checks/checking-pinned-references into .claude/skills/checking-pinned-references/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checking-pinned-references", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/agntcy/coffeeAgntcy/tree/main/.agents/skills/quality-checks/checking-pinned-referencesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add agntcy/coffeeAgntcy --skill checking-pinned-references -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install agntcy/coffeeAgntcy checking-pinned-references --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agntcy/coffeeAgntcy.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/quality-checks/checking-pinned-references .agents/skills/checking-pinned-references && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "checking-pinned-references" agent skill from https://github.com/agntcy/coffeeAgntcy/tree/main/.agents/skills/quality-checks/checking-pinned-references into .agents/skills/checking-pinned-references/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checking-pinned-references", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add agntcy/coffeeAgntcy --skill checking-pinned-references -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install agntcy/coffeeAgntcy checking-pinned-references --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agntcy/coffeeAgntcy.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/quality-checks/checking-pinned-references .cursor/skills/checking-pinned-references && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "checking-pinned-references" agent skill from https://github.com/agntcy/coffeeAgntcy/tree/main/.agents/skills/quality-checks/checking-pinned-references into .cursor/skills/checking-pinned-references/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checking-pinned-references", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/agntcy/coffeeAgntcy.git --path .agents/skills/quality-checks/checking-pinned-references--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add agntcy/coffeeAgntcy --skill checking-pinned-references -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install agntcy/coffeeAgntcy checking-pinned-references --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agntcy/coffeeAgntcy.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/quality-checks/checking-pinned-references .gemini/skills/checking-pinned-references && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "checking-pinned-references" agent skill from https://github.com/agntcy/coffeeAgntcy/tree/main/.agents/skills/quality-checks/checking-pinned-references into .gemini/skills/checking-pinned-references/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checking-pinned-references", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install agntcy/coffeeAgntcy checking-pinned-referencesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add agntcy/coffeeAgntcy --skill checking-pinned-references -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/agntcy/coffeeAgntcy.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/quality-checks/checking-pinned-references .github/skills/checking-pinned-references && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "checking-pinned-references" agent skill from https://github.com/agntcy/coffeeAgntcy/tree/main/.agents/skills/quality-checks/checking-pinned-references into .github/skills/checking-pinned-references/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checking-pinned-references", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add agntcy/coffeeAgntcy --skill checking-pinned-references -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install agntcy/coffeeAgntcy checking-pinned-references --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agntcy/coffeeAgntcy.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/quality-checks/checking-pinned-references .opencode/skills/checking-pinned-references && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "checking-pinned-references" agent skill from https://github.com/agntcy/coffeeAgntcy/tree/main/.agents/skills/quality-checks/checking-pinned-references into .opencode/skills/checking-pinned-references/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checking-pinned-references", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
checking-pinned-referencesRuns task pins:check to find any third-party GitHub Action, reusable-workflow, or image reference that isn't pinned to an immutable SHA/digest, and pins each one it finds.
Checking Pinned References is an agent skill from agntcy/coffeeAgntcy. Runs task pins:check to find any third-party GitHub Action, reusable-workflow, or image reference that isn't pinned to an immutable SHA/digest, and pins each one it finds. Use when adding or editing a uses: line, a Dockerfile FROM instruction, or a compose image: field.
Its SKILL.md is about 580 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering CI/CD and Containers. It works with Docker. The repository describes itself as: End-to-end reference application for AGNTCY Components. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit a01cbba. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghdockerFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh and docker, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Checking Pinned References loads about 578 tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 156 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from agntcy/coffeeAgntcy at commit a01cbba, republished under its Apache-2.0 licence (© agntcy). 156 words, ~578 tokens.
.claude/skills/checking-pinned-references/SKILL.md (or your agent's skills folder).Runs task pins:check (defined in Taskfile.yaml,
wrapping
scripts/checks/check_pinned_references.bash)
to scan every .github/workflows/*.y*ml uses: line, every Dockerfile
FROM instruction, and every compose image: field for a reference pinned
by a mutable tag/branch instead of an immutable commit SHA or image
digest. This is the same check task check:all runs as part of
checks.yaml. See
.agents/rules/quality/pinned-external-references.md
for the underlying rule.
- [ ] 1. Run: task pins:check
- [ ] 2. For each flagged GitHub Actions `uses:` line, find its commit SHA:
gh api repos/<owner>/<repo>/commits/<tag> --jq '.sha' - then pin as
owner/repo@<40-char-sha> # <tag>
- [ ] 3. For each flagged Docker image, find its digest:
docker buildx imagetools inspect <image>:<tag> - then pin as
image:<tag>@sha256:<digest>
- [ ] 4. If a reference genuinely can't be pinned (no tags/digests exist
upstream), add a `# pin-exempt: <reason>` comment stating why,
in place of the version comment
- [ ] 5. Re-run task pins:check to confirm it's cleanpin-exempt is a judgment call the person/agent adding the reference
makes and justifies at the point it's added - don't reach for it just to
silence the check.ghcr.io/agntcy/coffee-agntcy/*) using a floating tag like
:latest in a dev compose file is normal usage, not a gap.scripts/checks/check_pinned_references.bash doesn't scan for yet, extend the
script to cover it rather than pinning by hand and leaving the gap for
next time.© agntcy, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/quality-checks/checking-pinned-references of agntcy/coffeeAgntcy.
Open the folder on GitHubat commit a01cbba
Checking Pinned References next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Checking Pinned References this skillagntcy/coffeeAgntcy | 112 | — | ~578 | Automated safety check: Pass | Apache-2.0 | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| GitHub Actions CreatorFNOSP/FlyNarwhal | 495 | 1 repos | ~2.4k | Automated safety check: Pass | AGPL-3.0 | |
| Swig CI Reproswig/swig | 6.3k | — | ~1.2k | Automated safety check: Pass | Custom licence | |
| Megatron-LM Base Image BumpNVIDIA/Megatron-LM | 18k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| DDNS Build and Release MaintenanceNewFuture/DDNS | 4.7k | — | ~444 | Automated safety check: Pass | MIT |
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
FNOSP/FlyNarwhal
A skill your agent uses when the user wants to create, generate, or set up a GitHub Actions workflow.
swig/swig
Reproduce a GitHub Actions Linux CI failure locally when it does not happen on your machine: a podman/docker image that mirrors the ubuntu-22.04 runner by reusing the real Tools/CI-linux-.sh install…
NVIDIA/Megatron-LM
Moves Megatron-LM CI to a newer NVIDIA PyTorch base image, updating both the GitHub and GitLab pins together and handling the CI follow-up.
NewFuture/DDNS
Maintains the DDNS project's GitHub Actions, Docker and Nuitka builds, packaging and release preparation without touching publishing credentials.
kimdre/doco-cd
Review pull request diffs for correctness and regressions, and provide actionable feedback when asked to review a PR.
agntcy/coffeeAgntcy
A skill your agent uses when the user asks about A2A (Agent-to-Agent) protocol communication, OASF record formats, AGNTCY directory operations, agent card parsing, or dirctl CLI usage.
agntcy/coffeeAgntcy
Guides adding a new repository operation (a check, validation, or piece of tooling) through this repo's standard script - Taskfile task - skill - CI enforcement - rule pipeline.
agntcy/coffeeAgntcy
Authors and maintains the human-facing Agentic Workflows API documentation for the lungo subproject at coffeeAGNTCY/coffeeagents/lungo/docs/workflow-instanceapi.md.
agntcy/coffeeAgntcy
Runs task workflows:check-permissions to find any GitHub Actions workflow file with a write-all grant or no declared permissions, and scopes it down to least privilege.
agntcy/coffeeAgntcy
Generates coffeeAgntcy CHANGELOG release notes and README Built With updates from PRs and dependency lockfiles since the previous release tag.
agntcy/coffeeAgntcy
Runs task workflows:lint (actionlint) against every file under .github/workflows/ and fixes what it reports.
Works with
Categories
Runs task pins:check to find any third-party GitHub Action, reusable-workflow, or image reference that isn't pinned to an immutable SHA/digest, and pins each one it finds. Checking Pinned References is an agent skill from agntcy/coffeeAgntcy. Runs task pins:check to find any third-party GitHub Action, reusable-workflow, or image reference that isn't pinned to an immutable SHA/digest, and pins each one it finds.
Checking Pinned References fits situations like: editing a uses: line; A Dockerfile FROM instruction; A compose image: field.
Run `npx skills add agntcy/coffeeAgntcy --skill checking-pinned-references -a claude-code`. Or copy the skill folder (.agents/skills/quality-checks/checking-pinned-references in agntcy/coffeeAgntcy) into .claude/skills/checking-pinned-references in your project. Claude Code loads it when a task matches its description.
Run `npx skills add agntcy/coffeeAgntcy --skill checking-pinned-references -a codex`. Or copy the skill folder (.agents/skills/quality-checks/checking-pinned-references in agntcy/coffeeAgntcy) into .agents/skills/checking-pinned-references in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agntcy/coffeeAgntcy --skill checking-pinned-references -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/checking-pinned-references, .gemini/skills/checking-pinned-references, .github/skills/checking-pinned-references and .opencode/skills/checking-pinned-references in your project.
Going by SKILL.md and its folder, Checking Pinned References needs the command-line tools its instructions call (gh and docker). Our summary lists: Docker.
SKILL.md contains no URLs. Its commands use gh and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Checking Pinned References is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 578 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Checking Pinned References: Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), GitHub Actions Creator (FNOSP/FlyNarwhal, 495 stars), Swig CI Repro (swig/swig, 6.3k stars) and Megatron-LM Base Image Bump (NVIDIA/Megatron-LM, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
agntcy (a GitHub organization) maintains it in agntcy/coffeeAgntcy, which has 112 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 7, 2026.
Source: agntcy/coffeeAgntcy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.