Agent skill

GitHub Actions Generator

by akin-ozer in akin-ozer/cc-devops-skills

Create, generate, or scaffold GitHub Actions workflows, action.yml, or .github/workflows CI/CD pipelines.

Apache-2.0Auto-check passedDevOps & Cloud

Install GitHub Actions Generator

skills CLI
$ npx skills add akin-ozer/cc-devops-skills --skill github-actions-generator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install akin-ozer/cc-devops-skills github-actions-generator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/akin-ozer/cc-devops-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/devops-skills-plugin/skills/github-actions-generator .claude/skills/github-actions-generator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
github-actions-generator
GitHub stars
319
Token cost
~3.1k tokens
SKILL.md length
1,010 words
Files
39 (incl. scripts, references, assets)
Skills in repo
30
Repo updated
First seen
Licence
Apache-2.0

At a glance

Create, generate, or scaffold GitHub Actions workflows, action.yml, or .github/workflows CI/CD pipelines.

  • Works in 6 steps: Generate Workflows → Generate Custom Actions → Generate Reusable Workflows → …
  • Tasks that involve CI/CD
  • SKILL.md covers Quick Reference, Trigger Decision Tree, Progressive Disclosure Route and Core Capabilities, plus 7 more sections
  • Runs Shell and JavaScript scripts from its folder; reaches github.com

What it does

GitHub Actions Generator is an agent skill from akin-ozer/cc-devops-skills. Create, generate, or scaffold GitHub Actions workflows, action.yml, or .github/workflows CI/CD pipelines.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 47 other files, including scripts, reference files and assets (for example `assets/templates/action/composite/action.yml`, `assets/templates/action/docker/action.yml` and `assets/templates/action/docker/entrypoint.sh`).

It sits in DevOps & Cloud, covering CI/CD. It works with GitHub Actions. The repository describes itself as: DevOps skills for Claude Code and Codex. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve CI/CD

Example prompts

  • “/github-actions-generator”

Requirements

  • Node.js
  • A Bash shell
  • Docker

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Generate Workflows
  2. Generate Custom Actions
  3. Generate Reusable Workflows
  4. Generate Security Workflows
  5. Modern Features
  6. Third-Party Action Documentation and Citation

What it can do on your machine

Read from SKILL.md and the folder at commit 276af75. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell and JavaScript, from the files we listed), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GitHub Actions Generator loads about 3.1k tokens when it runs, and up to ~27k if it reads all its reference files. Until then it costs about 33 tokens; SKILL.md has 1,010 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~33
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~27k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from akin-ozer/cc-devops-skills at commit 276af75, republished under its Apache-2.0 licence (© akin-ozer). 1,010 words, ~3,053 tokens.

Download SKILL.mdSave it as .claude/skills/github-actions-generator/SKILL.md (or your agent's skills folder). This skill also uses 38 other files; get the full folder from GitHub.
name
github-actions-generator
description
Create, generate, or scaffold GitHub Actions workflows, action.yml, or .github/workflows CI/CD pipelines.

GitHub Actions Generator

Generate production-ready GitHub Actions workflows and custom actions following current best practices, security standards, and naming conventions. All generated resources are automatically validated using the devops-skills:github-actions-validator skill.

Quick Reference

CapabilityWhen to UseReference
WorkflowsCI/CD, automation, testingreferences/best-practices.md
Composite ActionsReusable step combinationsreferences/custom-actions.md
Docker ActionsCustom environments/toolsreferences/custom-actions.md
JavaScript ActionsAPI interactions, complex logicreferences/custom-actions.md
Reusable WorkflowsShared patterns across reposreferences/advanced-triggers.md
Security ScanningDependency review, SBOMreferences/best-practices.md
Modern FeaturesSummaries, environmentsreferences/modern-features.md

Trigger Decision Tree

Route every request through this decision tree before reading references or generating files:

  1. If the user asks for .github/workflows/*.yml CI/CD automation, choose Workflow Generation.
  2. If the user asks for action.yml or a reusable step package, choose Custom Action Generation.
  3. If the user asks for workflow_call or shared pipelines across repositories, choose Reusable Workflow Generation.
  4. If the request includes security-only scanning (dependency review, SBOM, CodeQL), stay on Workflow Generation with the security pattern.
  5. If intent is ambiguous, ask one disambiguation question: "Do you want a workflow, a custom action, or a reusable workflow?"

Progressive Disclosure Route

Load only what is needed for the selected route, in this order:

RouteLoad First (required)Load Next (only if needed)Primary Template
Workflow Generationreferences/best-practices.mdreferences/common-actions.md, references/expressions-and-contexts.md, references/modern-features.mdassets/templates/workflow/basic_workflow.yml
Custom Action Generationreferences/custom-actions.mdreferences/best-practices.mdassets/templates/action/composite/action.yml, assets/templates/action/docker/, assets/templates/action/javascript/
Reusable Workflow Generationreferences/advanced-triggers.mdreferences/best-practices.md, references/common-actions.mdassets/templates/workflow/reusable_workflow.yml

If a required reference/template is unavailable, continue with the closest available reference and report the fallback explicitly in output.


Core Capabilities

1. Generate Workflows

Triggers: "Create a workflow for...", "Build a CI/CD pipeline..."

Process:

  1. Understand requirements (triggers, runners, dependencies)
  2. Define trust boundaries (internal branches vs fork PRs vs external triggers)
  3. Set default permissions to read-only, then elevate only per job when required
  4. Reference references/best-practices.md for patterns
  5. Reference references/common-actions.md for action versions
  6. Generate workflow with:
    • Semantic names, pinned actions (SHA), explicit permissions
    • Concurrency controls, caching, matrix strategies
    • Fork-safe PR handling (no secrets in untrusted contexts)
  7. Validate with devops-skills:github-actions-validator skill
  8. Fix issues and re-validate if needed

Minimal Example:

yaml
name: CI Pipeline

on:
  push:
    branches: [main]
  pull_request:
    branches: [main]

permissions:
  contents: read

concurrency:
  group: ${{ github.workflow }}-${{ github.ref }}
  cancel-in-progress: true

jobs:
  test:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
      - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6.2.0
        with:
          node-version: '24'
          cache: 'npm'
      - run: npm ci
      - run: npm test

Untrusted PR Guardrail (required for secret-using jobs):

yaml
jobs:
  deploy:
    if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
2. Generate Custom Actions

Triggers: "Create a composite action...", "Build a Docker action...", "Create a JavaScript action..."

Types:

  • Composite: Combine multiple steps → Fast startup
  • Docker: Custom environment/tools → Isolated
  • JavaScript: API access, complex logic → Fastest

Process:

  1. Use templates from assets/templates/action/
  2. Follow structure in references/custom-actions.md
  3. Include branding, inputs/outputs, documentation
  4. Validate with devops-skills:github-actions-validator skill

See references/custom-actions.md for:

  • Action metadata and branding
  • Directory structure patterns
  • Versioning and release workflows
3. Generate Reusable Workflows

Triggers: "Create a reusable workflow...", "Make this workflow callable..."

Key Elements:

  • workflow_call trigger with typed inputs
  • Explicit secrets (avoid secrets: inherit)
  • Explicit trusted-caller expectations (document org/repo boundaries)
  • Outputs mapped from job outputs
  • Minimal permissions
yaml
on:
  workflow_call:
    inputs:
      environment:
        required: true
        type: string
    secrets:
      deploy-token:
        required: false
    outputs:
      result:
        value: ${{ jobs.build.outputs.result }}

When secrets are required, pass only the exact secret names needed and prefer environment protection rules for deployment stages.

See references/advanced-triggers.md for complete patterns.

4. Generate Security Workflows

Triggers: "Add security scanning...", "Add dependency review...", "Generate SBOM..."

Components:

  • Dependency Review: actions/dependency-review-action@v4
  • SBOM Attestations: actions/attest-sbom@v2
  • CodeQL Analysis: github/codeql-action

Permission Model: Use a read-only workflow-level baseline, then elevate only in the security job that requires write scopes.

yaml
permissions:
  contents: read

jobs:
  security-scan:
    permissions:
      contents: read
      security-events: write  # For CodeQL
      id-token: write         # For attestations
      attestations: write     # For attestations

See references/best-practices.md section on security.

5. Modern Features

Triggers: "Add job summaries...", "Use environments...", "Run in container..."

See references/modern-features.md for:

  • Job summaries ($GITHUB_STEP_SUMMARY)
  • Deployment environments with approvals
  • Container jobs with services
  • Workflow annotations
6. Third-Party Action Documentation and Citation

When using third-party actions (any uses: entry not in the same repository):

  1. Search for documentation:

    "[owner/repo] [version] github action documentation"
  2. Or use Context7 MCP:

    • mcp__context7__resolve-library-id to find action
    • mcp__context7__query-docs for documentation
  3. Pin to SHA with version comment:

    yaml
    - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
  4. Cite source and version in the response:

    • Action source (repository URL)
    • Version source (release/tag/changelog URL)
    • Selected commit SHA and human-readable version
    • Access date for the source used

See references/common-actions.md for pre-verified action versions.


Show full SKILL.md (383 more words)Show less

Validation Workflow

CRITICAL: Every generated resource MUST be validated.

  1. Generate workflow/action file
  2. Invoke devops-skills:github-actions-validator skill
  3. If errors: fix and re-validate
  4. If success: present with usage instructions

Skip validation only for:

  • Partial code snippets
  • Documentation examples
  • User explicitly requests skip

Fallback Behavior (Tooling and Environment Constraints)

If required tooling or network access is unavailable, use this deterministic fallback order:

  1. If devops-skills:github-actions-validator is unavailable, run local fallback checks:
    • actionlint (if installed)
    • yamllint (if installed)
    • manual YAML/schema review with a clear "not tool-validated" note
  2. If Context7 or internet access is unavailable:
    • use references/common-actions.md for known action versions
    • state that external version verification could not be completed
  3. If a template path is missing:
    • generate from the closest template pattern in assets/templates/
    • document which template was substituted

Fallback usage must always be reported in the final output.


Mandatory Standards

All generated resources must follow:

StandardImplementation
SecurityPin to SHA, minimal permissions, mask secrets
PerformanceCaching, concurrency, shallow checkout
NamingDescriptive names, lowercase-hyphen files
Error HandlingTimeouts, cleanup with if: always()

See references/best-practices.md for complete guidelines.


Resources

Reference Documents
DocumentContentWhen to Use
references/best-practices.mdSecurity, performance, patternsEvery workflow
references/common-actions.mdAction versions, inputs, outputsPublic action usage
references/expressions-and-contexts.md${{ }} syntax, contexts, functionsComplex conditionals
references/advanced-triggers.mdworkflow_run, dispatch, ChatOpsWorkflow orchestration
references/custom-actions.mdMetadata, structure, versioningCustom action creation
references/modern-features.mdSummaries, environments, containersEnhanced workflows
Templates
TemplateLocation
Basic Workflowassets/templates/workflow/basic_workflow.yml
Reusable Workflowassets/templates/workflow/reusable_workflow.yml
Composite Actionassets/templates/action/composite/action.yml
Docker Actionassets/templates/action/docker/
JavaScript Actionassets/templates/action/javascript/

Common Patterns

Matrix Testing
yaml
strategy:
  matrix:
    os: [ubuntu-latest, windows-latest]
    node: [18, 20, 22]
  fail-fast: false
Conditional Deployment
yaml
deploy:
  if: github.event_name == 'push' && github.ref == 'refs/heads/main'
Artifact Sharing
yaml
# Upload
- uses: actions/upload-artifact@5d5d22a31266ced268874388b861e4b58bb5c2f3 # v4.3.1
  with:
    name: build-${{ github.sha }}
    path: dist/

# Download (in dependent job)
- uses: actions/download-artifact@c850b930e6ba138125429b7e5c93fc707a7f8427 # v4.1.4
  with:
    name: build-${{ github.sha }}
Third-Party Action Citation Block
text
Third-party action citations:
- actions/checkout: https://github.com/actions/checkout (version: v6.0.2, sha: de0fac2e4500dabe0009e67214ff5f5447ce83dd, accessed: 2026-02-28)

Done Criteria

The task is complete only when all checks below pass:

  1. The request route was selected using the trigger decision tree.
  2. Only the minimum required references/templates were loaded first.
  3. Every third-party action is pinned to a commit SHA and has source/version citation.
  4. Validation was run, or a skip exception/fallback path was explicitly documented.
  5. Output includes assumptions, security-sensitive decisions (permissions/secrets), and generated file paths.

Workflow Summary

  1. Route the request using the trigger decision tree
  2. Load the minimum references/templates for that route
  3. Generate using mandatory security and naming standards
  4. Cite and pin third-party actions (source, version, SHA)
  5. Validate with devops-skills:github-actions-validator (or documented fallback)
  6. Fix and re-validate until clean
  7. Present validated output with citations, assumptions, and file paths

© akin-ozer, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 38 other files (scripts, references, assets) in devops-skills-plugin/skills/github-actions-generator of akin-ozer/cc-devops-skills.

  • SKILL.md
  • assets/templates/action/composite/action.yml
  • assets/templates/action/docker/Dockerfile
  • assets/templates/action/docker/action.yml
  • assets/templates/action/docker/entrypoint.sh
  • assets/templates/action/javascript/action.yml
  • assets/templates/action/javascript/index.js
  • assets/templates/action/javascript/package.json
  • assets/templates/workflow/basic_workflow.yml
  • assets/templates/workflow/reusable_workflow.yml
  • examples/README.md
  • examples/actions/setup-node-cached
  • … and 27 more

Open the folder on GitHubat commit 276af75

Compare with similar skills

GitHub Actions Generator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitHub Actions Generator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitHub Actions Generator this skillakin-ozer/cc-devops-skills319—~3.1kAutomated safety check: PassApache-2.0
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
GitHub Actions Templatesbartstc/vite-ts-react-template12214 repos~1.9kAutomated safety check: PassMIT
Nushellccusage/ccusage19k—~938Automated safety check: PassCustom licence
Repo Hygiene Scan and FixQwenLM/qwen-code28k—~1.7kAutomated safety check: PassApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence

Similar skills

  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • GitHub Actions Templates

    bartstc/vite-ts-react-template

    Create production-ready GitHub Actions workflows for automated testing, building, and deploying applications.

    122 GitHub starsUsed in 14 repos~1.9k tokens
    DevOps & CloudAuto-check passed
  • Nushell

    ccusage/ccusage

    Guides ccusage Nushell scripts. An agent skill from ccusage/ccusage.

    19k GitHub stars~938 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Scheduled CI skill that scans a repository for small, certain docs, test and code hygiene issues and fixes them on one branch with a commit per finding.

    28k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • CI Failure Triage and Repair

    Chachamaru127/claude-code-harness

    Diagnoses failing CI pipelines and tests, deciding first whether the test or the implementation is at fault, and hands hard cases to a dedicated fixer subagent.

    3.2k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check: notes

More from akin-ozer/cc-devops-skills

All 30 skills in this repo
  • Helm Generator

    akin-ozer/cc-devops-skills

    Create, scaffold, or generate Helm charts, Chart.yaml, values.yaml, templates, helpers.

    319 GitHub stars~2.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Jenkinsfile Generator

    akin-ozer/cc-devops-skills

    Generate/create/scaffold Jenkinsfile — declarative, scripted, shared library, CI/CD pipelines.

    319 GitHub stars~3.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Dockerfile Validator

    akin-ozer/cc-devops-skills

    Validate, lint, audit, or scan a Dockerfile for security and best practices.

    319 GitHub stars~2.3k tokensUpdated 2 mo ago
    Auto-check passed
  • GitHub Actions Validator

    akin-ozer/cc-devops-skills

    Validate, lint, audit, fix GitHub Actions workflows (.github/workflows).

    319 GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Jenkinsfile Validator

    akin-ozer/cc-devops-skills

    Validate, lint, audit, or check Jenkinsfiles and shared libraries.

    319 GitHub stars~2.7k tokensUpdated 2 mo ago
    Auto-check passed
  • K8s Debug

    akin-ozer/cc-devops-skills

    Diagnose and fix Kubernetes pods, CrashLoopBackOff, Pending, DNS, networking, storage, and rollout failures with kubectl.

    319 GitHub stars~2.9k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Categories

Questions about GitHub Actions Generator

What does GitHub Actions Generator do?

Create, generate, or scaffold GitHub Actions workflows, action.yml, or .github/workflows CI/CD pipelines. GitHub Actions Generator is an agent skill from akin-ozer/cc-devops-skills.github/workflows CI/CD pipelines.

When should I use GitHub Actions Generator?

GitHub Actions Generator fits situations like: tasks that involve CI/CD.

How do I install GitHub Actions Generator in Claude Code?

Run `npx skills add akin-ozer/cc-devops-skills --skill github-actions-generator -a claude-code`. Or copy the skill folder (devops-skills-plugin/skills/github-actions-generator in akin-ozer/cc-devops-skills) into .claude/skills/github-actions-generator in your project. Claude Code loads it when a task matches its description.

How do I install GitHub Actions Generator in Codex?

Run `npx skills add akin-ozer/cc-devops-skills --skill github-actions-generator -a codex`. Or copy the skill folder (devops-skills-plugin/skills/github-actions-generator in akin-ozer/cc-devops-skills) into .agents/skills/github-actions-generator in your project. Codex loads it when a task matches its description.

Can I use GitHub Actions Generator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add akin-ozer/cc-devops-skills --skill github-actions-generator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-actions-generator, .gemini/skills/github-actions-generator, .github/skills/github-actions-generator and .opencode/skills/github-actions-generator in your project.

What does GitHub Actions Generator need to run?

Going by SKILL.md and its folder, GitHub Actions Generator needs a shell and JavaScript for the scripts in its folder. Our summary lists: Node.js; A Bash shell; Docker.

Does GitHub Actions Generator access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is GitHub Actions Generator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does GitHub Actions Generator use?

GitHub Actions Generator is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitHub Actions Generator use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 24k tokens, read only when the agent opens those files.

What are the alternatives to GitHub Actions Generator?

Skills that share tags, products or a category with GitHub Actions Generator: Analyze GitHub Action Logs (withastro/astro, 63k stars), GitHub Actions Templates (bartstc/vite-ts-react-template, 122 stars), Nushell (ccusage/ccusage, 19k stars) and Repo Hygiene Scan and Fix (QwenLM/qwen-code, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitHub Actions Generator?

akin-ozer (a GitHub user) maintains it in akin-ozer/cc-devops-skills, which has 319 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on July 26, 2026.

Source: akin-ozer/cc-devops-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.