Agent skill

Linting GitHub Workflows

by agntcy in agntcy/coffeeAgntcy

Runs task workflows:lint (actionlint) against every file under .github/workflows/ and fixes what it reports.

Apache-2.0Auto-check passedDevelopment

Install Linting GitHub Workflows

skills CLI
$ npx skills add agntcy/coffeeAgntcy --skill linting-github-workflows -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agntcy/coffeeAgntcy linting-github-workflows --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agntcy/coffeeAgntcy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/quality-checks/linting-github-workflows .claude/skills/linting-github-workflows && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
linting-github-workflows
GitHub stars
112
Token cost
~507 tokens
SKILL.md length
121 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runs task workflows:lint (actionlint) against every file under .github/workflows/ and fixes what it reports.

  • Editing a workflow file
  • SKILL.md covers What this skill does, Workflow and Notes
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Before finishing such a change

What it does

Linting GitHub Workflows is an agent skill from agntcy/coffeeAgntcy. Runs task workflows:lint (actionlint) against every file under .github/workflows/ and fixes what it reports. Use when writing or editing a workflow file, before finishing such a change, or when asked to lint GitHub Actions workflows.

Its SKILL.md is about 510 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Linting and formatting. It works with GitHub Actions. The repository describes itself as: End-to-end reference application for AGNTCY Components. The licence is Apache-2.0.

When your agent uses it

  • Editing a workflow file
  • Before finishing such a change
  • Asked to lint GitHub Actions workflows

Example prompts

  • “/linting-github-workflows”

What it can do on your machine

Read from SKILL.md and the folder at commit 36f1923. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Linting GitHub Workflows loads about 507 tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 121 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~507

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from agntcy/coffeeAgntcy at commit 36f1923, republished under its Apache-2.0 licence (© agntcy). 121 words, ~507 tokens.

Download SKILL.mdSave it as .claude/skills/linting-github-workflows/SKILL.md (or your agent's skills folder).
name
linting-github-workflows
description
Runs task workflows:lint (actionlint) against every file under .github/workflows/ and fixes what it reports. Use when writing or editing a workflow file, before finishing such a change, or when asked to lint GitHub Actions workflows.

Linting GitHub workflows

What this skill does

Runs task workflows:lint (defined in Taskfile.yaml, wrapping scripts/lint/lint_workflows.bash) to check every file under .github/workflows/ with actionlint, then fixes whatever it reports. This is the exact command task check:all runs as part of checks.yaml in CI. See .agents/rules/quality/workflow-file-linting.md for the underlying rule.

Workflow

- [ ] 1. If actionlint isn't already available, run: task setup && source
        scripts/env.sh (bootstraps it into .tools/bin/, pinned to
        scripts/lib/versions.sh)
- [ ] 2. Run: task workflows:lint
- [ ] 3. For a schema/syntax/structure finding, fix the workflow file
        directly
- [ ] 4. For a shellcheck finding inside a `run:` block, fix the
        underlying issue - or, if it's a genuine false positive (e.g. a
        variable only read through indirect expansion), add a targeted
        `# shellcheck disable=SCxxxx` comment with a reason next to that
        line
- [ ] 5. Re-run task workflows:lint to confirm it's clean

Notes

  • actionlint's shellcheck integration reports every severity (including shellcheck's own "warning" level, e.g. SC2034), unlike some CI wrappers that only fail above a configured severity threshold - so a finding showing up here is a real gate-blocker, not advisory.
  • Don't reach for a blanket -ignore pattern to silence a whole class of finding; suppress the specific line with a reason instead, so a future genuine instance of that same check still gets caught.

© agntcy, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/quality-checks/linting-github-workflows of agntcy/coffeeAgntcy.

Open the folder on GitHubat commit 36f1923

Compare with similar skills

Linting GitHub Workflows next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Linting GitHub Workflows compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Linting GitHub Workflows this skillagntcy/coffeeAgntcy112—~507Automated safety check: PassApache-2.0
Babysit PR To Pass CIsgl-project/sglang37k2 repos~3kAutomated safety check: PassApache-2.0
Update Dependenciesalorence/django-modern-rpc111—~1.3kAutomated safety check: PassMIT
Golang Continuous Integrationsamber/cc-skills-golang3.4k—~3.7kAutomated safety check: PassMIT
Align Recipe pyproject.tomlgoogle/adk-recipes10k—~4.6kAutomated safety check: PassApache-2.0
Golang Continuous Integrationcontext-labs/whip1.1k—~3.5kAutomated safety check: PassMIT

Similar skills

  • Babysit PR To Pass CI

    sgl-project/sglang

    Start and persistently pursue a goal to babysit an SGLang pull request until selected GitHub Actions workflows pass on the latest PR head.

    37k GitHub starsUsed in 2 repos~3k tokens
    DevelopmentAuto-check passed
  • Update Dependencies

    alorence/django-modern-rpc

    Routine update of all project dependencies — uv itself, uv.lock (all groups), tool versions pinned in GitHub workflows and .pre-commit-config.yaml (uv, ruff, mypy...), and SHA-pinned GitHub Actions.

    111 GitHub stars~1.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Golang Continuous Integration

    samber/cc-skills-golang

    GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release…

    3.4k GitHub stars~3.7k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Align Recipe pyproject.toml

    google/adk-recipes

    Official

    Brings a Python recipe's pyproject.toml in line with the repo's CI rules, either as a read-only dry run or by rewriting the file while keeping comments.

    10k GitHub stars~4.6k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines.

    1.1k GitHub stars~3.5k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Python Pypi Package Builder

    github/awesome-copilot

    Official

    End-to-end skill for building, testing, linting, versioning, and publishing a production-grade Python library to PyPI.

    40k GitHub starsUsed in 1 repo~4.6k tokens
    DevelopmentAuto-check passed

More from agntcy/coffeeAgntcy

All 16 skills in this repo
  • A2a Protocol

    agntcy/coffeeAgntcy

    A skill your agent uses when the user asks about A2A (Agent-to-Agent) protocol communication, OASF record formats, AGNTCY directory operations, agent card parsing, or dirctl CLI usage.

    112 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Add Repo Operation

    agntcy/coffeeAgntcy

    Guides adding a new repository operation (a check, validation, or piece of tooling) through this repo's standard script - Taskfile task - skill - CI enforcement - rule pipeline.

    112 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Authors and maintains the human-facing Agentic Workflows API documentation for the lungo subproject at coffeeAGNTCY/coffeeagents/lungo/docs/workflow-instanceapi.md.

    112 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • Checking Pinned References

    agntcy/coffeeAgntcy

    Runs task pins:check to find any third-party GitHub Action, reusable-workflow, or image reference that isn't pinned to an immutable SHA/digest, and pins each one it finds.

    112 GitHub stars~578 tokensUpdated yesterday
    Auto-check passed
  • Runs task workflows:check-permissions to find any GitHub Actions workflow file with a write-all grant or no declared permissions, and scopes it down to least privilege.

    112 GitHub stars~513 tokensUpdated yesterday
    Auto-check passed
  • Generate Release Notes

    agntcy/coffeeAgntcy

    Generates coffeeAgntcy CHANGELOG release notes and README Built With updates from PRs and dependency lockfiles since the previous release tag.

    112 GitHub stars~535 tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Linting GitHub Workflows

What does Linting GitHub Workflows do?

Runs task workflows:lint (actionlint) against every file under .github/workflows/ and fixes what it reports. Linting GitHub Workflows is an agent skill from agntcy/coffeeAgntcy.github/workflows/ and fixes what it reports.

When should I use Linting GitHub Workflows?

Linting GitHub Workflows fits situations like: editing a workflow file; before finishing such a change; asked to lint GitHub Actions workflows.

How do I install Linting GitHub Workflows in Claude Code?

Run `npx skills add agntcy/coffeeAgntcy --skill linting-github-workflows -a claude-code`. Or copy the skill folder (.agents/skills/quality-checks/linting-github-workflows in agntcy/coffeeAgntcy) into .claude/skills/linting-github-workflows in your project. Claude Code loads it when a task matches its description.

How do I install Linting GitHub Workflows in Codex?

Run `npx skills add agntcy/coffeeAgntcy --skill linting-github-workflows -a codex`. Or copy the skill folder (.agents/skills/quality-checks/linting-github-workflows in agntcy/coffeeAgntcy) into .agents/skills/linting-github-workflows in your project. Codex loads it when a task matches its description.

Can I use Linting GitHub Workflows in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agntcy/coffeeAgntcy --skill linting-github-workflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/linting-github-workflows, .gemini/skills/linting-github-workflows, .github/skills/linting-github-workflows and .opencode/skills/linting-github-workflows in your project.

What does Linting GitHub Workflows need to run?

SKILL.md names no scripts, command-line tools or credentials: Linting GitHub Workflows is instructions for the agent only.

Does Linting GitHub Workflows access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Linting GitHub Workflows safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Linting GitHub Workflows use?

Linting GitHub Workflows is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Linting GitHub Workflows use?

About 507 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Linting GitHub Workflows?

Skills that share tags, products or a category with Linting GitHub Workflows: Babysit PR To Pass CI (sgl-project/sglang, 37k stars), Update Dependencies (alorence/django-modern-rpc, 111 stars), Golang Continuous Integration (samber/cc-skills-golang, 3.4k stars) and Align Recipe pyproject.toml (google/adk-recipes, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Linting GitHub Workflows?

agntcy (a GitHub organization) maintains it in agntcy/coffeeAgntcy, which has 112 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 6, 2026.

Source: agntcy/coffeeAgntcy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.