Agent skill

CI CD Security

by aiskillstore in aiskillstore/marketplace

Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no shell execution.

No licenceAuto-check passedDevOps & Cloud

Install CI CD Security

skills CLI
$ npx skills add aiskillstore/marketplace --skill ci-cd-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aiskillstore/marketplace ci-cd-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/superagent-ai/ci-cd-security .claude/skills/ci-cd-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ci-cd-security
GitHub stars
430
Token cost
~3.2k tokens
SKILL.md length
1,545 words
Files
5 (incl. references)
Skills in repo
1,108
Repo updated
First seen
Licence
None found

At a glance

Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no shell execution.

  • Works in 3 steps: Say so explicitly. "No findings against… → Note what wasn't checked: org-level… → Recommend the user check the items in…
  • The user shares a .github/workflows/ file
  • SKILL.md covers Mental model, Scan procedure, Finding format and Severity scale, plus 3 more sections
  • Reaches github.com; needs GITHUB_TOKEN and NPM_TOKEN

What it does

CI CD Security is an agent skill from aiskillstore/marketplace. Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no shell execution. Use this skill whenever the user shares a .github/workflows/ file, pastes workflow YAML, asks for a CI/CD security review, mentions pullrequesttarget, workflowrun, action pinning, GITHUBTOKEN permissions, pwn requests, template injection, cache poisoning, secret exfiltration, supply chain risk, or any GitHub Actions hardening topic. Also…

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/checklist.md`, `references/patterns.md` and `references/triggers.md`).

It sits in DevOps & Cloud, covering CI/CD. It works with GitHub Actions and GitHub. The repository describes itself as: Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified.

When your agent uses it

  • The user shares a .github/workflows/ file
  • Pastes workflow YAML
  • Asks for a CI/CD security review
  • Mentions pullrequesttarget

Example prompts

  • “/ci-cd-security”

Requirements

  • Docker
  • A credential in GITHUB_TOKEN
  • A credential in NPM_TOKEN

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Say so explicitly. "No findings against the standard rule set."
  2. Note what wasn't checked: org-level settings (default token permissions, ruleset enforcement, 2FA), repo-level settings (branch…
  3. Recommend the user check the items in references/checklist.md under "Per repository" and "Per organization" — those need GitHub settings…

What it can do on your machine

Read from SKILL.md and the folder at commit ad8daf7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • NPM_TOKEN
    • PYPI_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

CI CD Security loads about 3.2k tokens when it runs, and up to ~9.3k if it reads all its reference files. Until then it costs about 216 tokens; SKILL.md has 1,545 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~216
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 1,545 words (~3,197 tokens).

“This skill turns the model into a workflow-YAML scanner. Read the file, walk the detection rules, report findings with severity and a concrete rewrite. No tools to install, no commands to run — the analysis is the model reading the…”

— opening of SKILL.md by aiskillstore
name
ci-cd-security

Read the full SKILL.md on GitHub

Files

SKILL.md and 4 other files (references) in skills/superagent-ai/ci-cd-security of aiskillstore/marketplace.

  • SKILL.md
  • references/checklist.md
  • references/patterns.md
  • references/triggers.md
  • skill-report.json

Open the folder on GitHubat commit ad8daf7

Compare with similar skills

CI CD Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

CI CD Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
CI CD Security this skillaiskillstore/marketplace430—~3.2kAutomated safety check: PassNone
GitHub Actions Supply Chain Pinningasyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.0
Secure GitHub Actionsvechain/x-app-template450—~1.2kAutomated safety check: PassMIT
Review Dependenciestobihagemann/turbo407—~1.5kAutomated safety check: PassMIT
Sicurezza GitHubccplugins/awesome-claude-code-plugins968—~486Automated safety check: NotesApache-2.0
Nushellccusage/ccusage19k—~938Automated safety check: PassCustom licence

Similar skills

  • A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

    1.1k GitHub stars~1.9k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Secure GitHub Actions

    vechain/x-app-template

    Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.

    450 GitHub stars~1.2k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Review Dependencies

    tobihagemann/turbo

    Detect package managers and CI action pins, then discover outdated or vulnerable dependencies.

    407 GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Sicurezza GitHub

    ccplugins/awesome-claude-code-plugins

    Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot.

    968 GitHub stars~486 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Nushell

    ccusage/ccusage

    Guides ccusage Nushell scripts. An agent skill from ccusage/ccusage.

    19k GitHub stars~938 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Clawsweeper

    openclaw/openclaw

    A skill your agent uses for all ClawSweeper work: OpenClaw issue/PR sweep reports, repair jobs, cloud fix PRs, @clawsweeper maintainer mention commands, trusted ClawSweeper-reviewed…

    392k GitHub stars~3k tokensUpdated today
    DevOps & CloudAuto-check passed

More from aiskillstore/marketplace

All 1,108 skills in this repo
  • Code Stats

    aiskillstore/marketplace

    Analyze codebase with tokei (fast line counts by language) and difft (semantic AST-aware diffs).

    430 GitHub starsUsed in 2 repos~697 tokens
    Auto-check: notes
  • File Search

    aiskillstore/marketplace

    Modern file and content search using fd, ripgrep (rg), and fzf.

    430 GitHub starsUsed in 2 repos~598 tokens
    Auto-check: notes
  • Data Processing

    aiskillstore/marketplace

    Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 1 repo~720 tokens
    Auto-check: notes
  • Doc Scanner

    aiskillstore/marketplace

    Scans for project documentation files (AGENTS.md, CLAUDE.md, GEMINI.md, COPILOT.md, CURSOR.md, WARP.md, and 15+ other formats) and synthesizes guidance.

    430 GitHub starsUsed in 1 repo~644 tokens
    Auto-check: notes
  • Find Replace

    aiskillstore/marketplace

    Modern find-and-replace using sd (simpler than sed) and batch replacement patterns.

    430 GitHub starsUsed in 1 repo~527 tokens
    Auto-check: notes
  • Investigating Codebases

    aiskillstore/marketplace

    Automatically activated when user asks how something works, wants to understand unfamiliar code, needs to explore a new codebase, or asks questions like "where is X implemented?", "how does Y…

    430 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check: notes

Questions about CI CD Security

What does CI CD Security do?

Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no shell execution. CI CD Security is an agent skill from aiskillstore/marketplace. Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no shell execution.

When should I use CI CD Security?

CI CD Security fits situations like: the user shares a .github/workflows/ file; pastes workflow YAML; asks for a CI/CD security review; mentions pullrequesttarget.

How do I install CI CD Security in Claude Code?

Run `npx skills add aiskillstore/marketplace --skill ci-cd-security -a claude-code`. Or copy the skill folder (skills/superagent-ai/ci-cd-security in aiskillstore/marketplace) into .claude/skills/ci-cd-security in your project. Claude Code loads it when a task matches its description.

How do I install CI CD Security in Codex?

Run `npx skills add aiskillstore/marketplace --skill ci-cd-security -a codex`. Or copy the skill folder (skills/superagent-ai/ci-cd-security in aiskillstore/marketplace) into .agents/skills/ci-cd-security in your project. Codex loads it when a task matches its description.

Can I use CI CD Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aiskillstore/marketplace --skill ci-cd-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ci-cd-security, .gemini/skills/ci-cd-security, .github/skills/ci-cd-security and .opencode/skills/ci-cd-security in your project.

What does CI CD Security need to run?

Going by SKILL.md and its folder, CI CD Security needs credentials named GITHUB_TOKEN, NPM_TOKEN and PYPI_TOKEN. Our summary lists: Docker; A credential in GITHUB_TOKEN; A credential in NPM_TOKEN.

Does CI CD Security access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is CI CD Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does CI CD Security use?

No licence was found for CI CD Security or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does CI CD Security use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.1k tokens, read only when the agent opens those files.

What are the alternatives to CI CD Security?

Skills that share tags, products or a category with CI CD Security: GitHub Actions Supply Chain Pinning (asyncapi/generator, 1.1k stars), Secure GitHub Actions (vechain/x-app-template, 450 stars), Review Dependencies (tobihagemann/turbo, 407 stars) and Sicurezza GitHub (ccplugins/awesome-claude-code-plugins, 968 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains CI CD Security?

aiskillstore (a GitHub organization) maintains it in aiskillstore/marketplace, which has 430 GitHub stars. The repository holds 1,108 skills in this directory. The repository was last updated on October 7, 2026.

Source: aiskillstore/marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.