Agentic GitHub Actions Auditor
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
The non-obvious invariants of the proactive nightly Claude audit workflow (.github/workflows/claude-nightly-audit.yml): the day-of-week mode selector, the two-key dedup scheme (clusterkey per…
$ npx skills add amd/gaia --skill weekly-audit-patterns -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install amd/gaia weekly-audit-patterns --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/amd/gaia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/weekly-audit-patterns .claude/skills/weekly-audit-patterns && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "weekly-audit-patterns" agent skill from https://github.com/amd/gaia/tree/main/.claude/skills/weekly-audit-patterns into .claude/skills/weekly-audit-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "weekly-audit-patterns", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/amd/gaia/tree/main/.claude/skills/weekly-audit-patternsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add amd/gaia --skill weekly-audit-patterns -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install amd/gaia weekly-audit-patterns --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/amd/gaia.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/weekly-audit-patterns .agents/skills/weekly-audit-patterns && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "weekly-audit-patterns" agent skill from https://github.com/amd/gaia/tree/main/.claude/skills/weekly-audit-patterns into .agents/skills/weekly-audit-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "weekly-audit-patterns", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add amd/gaia --skill weekly-audit-patterns -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install amd/gaia weekly-audit-patterns --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/amd/gaia.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/weekly-audit-patterns .cursor/skills/weekly-audit-patterns && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "weekly-audit-patterns" agent skill from https://github.com/amd/gaia/tree/main/.claude/skills/weekly-audit-patterns into .cursor/skills/weekly-audit-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "weekly-audit-patterns", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/amd/gaia.git --path .claude/skills/weekly-audit-patterns--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add amd/gaia --skill weekly-audit-patterns -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install amd/gaia weekly-audit-patterns --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/amd/gaia.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/weekly-audit-patterns .gemini/skills/weekly-audit-patterns && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "weekly-audit-patterns" agent skill from https://github.com/amd/gaia/tree/main/.claude/skills/weekly-audit-patterns into .gemini/skills/weekly-audit-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "weekly-audit-patterns", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install amd/gaia weekly-audit-patternsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add amd/gaia --skill weekly-audit-patterns -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/amd/gaia.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/weekly-audit-patterns .github/skills/weekly-audit-patterns && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "weekly-audit-patterns" agent skill from https://github.com/amd/gaia/tree/main/.claude/skills/weekly-audit-patterns into .github/skills/weekly-audit-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "weekly-audit-patterns", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add amd/gaia --skill weekly-audit-patterns -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install amd/gaia weekly-audit-patterns --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/amd/gaia.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/weekly-audit-patterns .opencode/skills/weekly-audit-patterns && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "weekly-audit-patterns" agent skill from https://github.com/amd/gaia/tree/main/.claude/skills/weekly-audit-patterns into .opencode/skills/weekly-audit-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "weekly-audit-patterns", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
weekly-audit-patternsThe non-obvious invariants of the proactive nightly Claude audit workflow (.github/workflows/claude-nightly-audit.yml): the day-of-week mode selector, the two-key dedup scheme (clusterkey per…
Weekly Audit Patterns is an agent skill from amd/gaia. The non-obvious invariants of the proactive nightly Claude audit workflow (.github/workflows/claude-nightly-audit.yml): the day-of-week mode selector, the two-key dedup scheme (clusterkey per defect, dedupkey per location) that keeps one defect from becoming N issues, the four audit dimensions (security has its own nightly workflow, claude-security-audit.yml) and which one owns the Fail-Loudly check, and the bug-label → auto-fix promotion path. Read before editing that workflow, changing its cadence, changing how…
Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Security review. It works with GitHub Actions. The repository describes itself as: Build AI agents for your PC. The licence is MIT.
Read from SKILL.md and the folder at commit 6c3bb5c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Weekly Audit Patterns loads about 4.4k tokens when it runs. Until then it costs about 151 tokens; SKILL.md has 2,431 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from amd/gaia at commit 6c3bb5c, republished under its MIT licence (© amd). 2,431 words, ~4,366 tokens.
.claude/skills/weekly-audit-patterns/SKILL.md (or your agent's skills folder)..github/workflows/claude-nightly-audit.yml is the repo's one proactive Claude
lens — a scheduled deep review (not triggered by a PR) that fans out one read-only
Claude job per dimension and files one issue per defect. Everything else in
claude.yml is reactive. These are the invariants a future editor will otherwise break.
Naming: this ran weekly before it moved to a nightly cron (10:37 UTC ≈ 3am Pacific, deep on Sundays). The filename,
name:, cron, and concurrency group now all say nightly. Two identifiers still sayweeklyand are correct as they are:
- the
weekly-auditlabel — a provenance label ("a proactive Claude audit filed this"), shared with the genuinely-weeklyclaude-weekly-doc-walkthrough.yml. No cadence word fits both workflows, so it keeps the neutral name it happens to have; its--descriptionin both workflows says exactly that.- this skill's
name, referenced fromCLAUDE.md.An earlier version of this note justified the label by claiming a rename "would re-file every open finding." That is false, and worth correcting because it is the reasoning a future editor inherits: GitHub renames a label in place and every issue keeps it, and dedup never matched on the label text — it reads the
audit-key/audit-clustermarkers in issue bodies. The label only scopes which issues get scanned for those markers (--labelinscripts/audit/prepare_synthesis.py, one default to update).
correctness, docs, tests, features — a matrix of one Claude job each. Security
is NOT a dimension here — it moved to its own workflow, claude-security-audit.yml
(deterministic semgrep + a Claude taint/authz/suppression sweep, CVSS-scored, findings to
the private code-scanning tab). Don't re-add it here; that created two half-owners and the
single general "security lens" is what missed the hub tar-slip.
The lenses overlap unless the prompt keeps them disjoint, and the first run proved it:
correctness findings (a rollback that never rolls back, a poller returning null, a mode
that no-ops) leaked into features, and the priciest job's output vanished from what got
filed. The decisive question for a broken thing: is the code wired but
misbehaving (correctness), never written (features), or contradicted by its docs
(docs)?
correctness owns wired-but-broken behavior AND the CLAUDE.md "Fail Loudly" check
(except Exception: pass, try/except returning a placeholder, silent degradation).features is only genuinely-missing/half-shipped capability — a TODO for code never
written. Wired-but-broken is correctness, not features.docs owns doc-vs-code drift, including a feature documented as working but stubbed.tests in deep mode gives every plain "module X has no coverage" the shared
cluster_key tests:aggregate-untested-modules so they merge into one issue; separate
findings only for risk-bearing untested logic (auth/gate/precedence/error-mapping/#1655).Adding a dimension means: add it to the matrix, describe its disjoint lens in the shared
prompt, and the synthesis picks up its findings-<dim>.json automatically.
Published agents are the shop window — the prompt makes every lens double-check them and
bump any gap up one severity (never 🟡; a default-path break is 🔴). Detect them by a
release_agent_<id>.yml, a shipped SCORECARD.md, or a released version: in
gaia-agent.yaml — currently the email agent and the gaia flagship agent. The bar: in-sync high-quality
README/SPEC.md/SKILL.md/CHANGELOG.md (+ any contract spec) with a real eval SCORECARD.md
(gated by gaia.eval.scorecard_gate, never hand-authored) linked from the README; bulletproof
runtime code (no stubs/silent-fallbacks); solid #1655-grade tests. When a new agent publishes,
the detection generalizes to it automatically — no prompt edit needed.
Green (🟢) reads as "pass/good," so it's banned. Broken behavior always outranks a missing test — never rate "module X has no tests" above a feature that's actually broken. High = security / data loss / default-path break; medium = broken user-facing behavior, a false doc, or a missing test guarding auth/a gate/destructive logic; low = missing tests on non-risk logic, cosmetic gaps. The synthesis emits a section per dimension (fixed order: Correctness, Features, Docs, Tests), grouping each finding under the dimension it declares — it never re-buckets.
Only high/medium defects are filed (and thus get one-click bug→auto-fix promotion). 🟡
(low) findings appear in the run's job-summary report and nowhere else — this caps tracker
churn; the first deep run filed 19 issues, ~13 of them low-value coverage nits. Each
finding carries an auto_fixable boolean, and the issue body says whether applying bug
will let auto-fix land it (locatable/small) or whether it needs a human (a test suite, a
refactor) — so maintainers don't promote something auto-fix can't handle.
The lenses report everything they can ground in something they read — including
findings they are unsure about. Synthesis is the only filter. This split is deliberate
and load-bearing on Claude Opus 5: a lens prompt that says "be conservative", "precision
beats recall", or "skip anything you aren't confident is real" gets followed literally
— the model investigates just as hard and then silently reports less. Both this workflow
and claude-security-audit.yml previously said exactly that. Do not put it back. (The
security audit's own origin story is a recall failure: its predecessor missed the hub
tar-slip, CWE-22, by sampling and trusting a suppression comment.)
What each side owns:
evidence with what you actually read. No
evidence, no finding — the one hard filter upstream. Express doubt through
severity (file it 🟡 and say so in why), never by dropping the item.path/symbol for every 🔴/🟠 before
filing, and demotes over-stated findings rather than deleting them. The mechanical
half of its old job — merging one defect's locations, including across dimensions —
now happens before it, in the deterministic dedup pass below.If the tracker gets noisy, tighten synthesis. Do not re-muzzle the lenses.
Every filed issue follows CLAUDE.md → How You
Communicate: the title and opening line say what
broke and who it hurts, in plain words; the path:line evidence goes underneath in a
sub-bullet or a <details> block. A finding that opens with a symbol name is one a
triager skips.
A defect is what a maintainer fixes, not where they see it. One root cause spanning 39
files is one fix, so it gets ONE issue listing 39 locations. Both halves of this have
already broken, in a single night each: file-scoped keys turned one dead
lemonade-server serve command into five issues, and dedup that searched only the
weekly-audit label could not see the four-month-old #1077, so the audit re-discovered it
14 times.
Every finding carries two keys, and they are not interchangeable:
cluster_key = <dimension>:<root-cause-slug> identifies the DEFECT and contains
no path. Every location of one defect carries the identical key and merges into
one issue. The test the lens prompt gives: how many separate PRs would fix all of
this? — that is how many cluster keys there should be.dedup_key = <dimension>:<path>:<symbol-or-section> identifies the LOCATION. The
symbol is a function/class name or doc heading, NEVER a line number (line numbers
move, so a line-based key re-files the same finding every run).Filed issues embed both as <!-- audit-cluster: KEY --> and <!-- audit-key: KEY -->, and
the dedup pass reads either marker — that back-compatibility is what stopped the
two-key change from re-filing the ~130 findings already open.
scripts/audit/prepare_synthesis.py is the dedup pass, run by the synthesize job of
both this workflow and the doc walkthrough, before the Claude filing step. It merges
findings by cluster_key, searches the whole open backlog (not one label) for an issue
already tracking each defect, flags likely sibling clusters within a run, and writes
synthesis-dossier.md as the model's worklist. It is deterministic on purpose: asking a
model to eyeball dedup across ~900 open issues produced a 2.35x duplication ratio. Do not
move this back into the prompt, and do not narrow the search back to one label.
Synthesis then picks exactly one of three outcomes per defect: drop it (the evidence gate), comment on the existing backlog issue the dossier surfaced, or file one new issue. Commenting is the #1077 fix — err toward it, because a comment on the wrong issue is trivially undone and a duplicate issue is what created this backlog.
Suppression is load-bearing, and it is now SCOPED to the key that carries it. Closing
an issue with audit-wontfix (open or closed) is still the only way to permanently
silence accepted debt, but which key that issue carries decides how much it silences:
audit-cluster key silences the whole defect — it never comes back;audit-key silences only that one location; the defect's other locations still
get filed, minus the suppressed one.Two matching rules follow the same split, and both exist because the naive version loses
real findings: one old per-file wontfix must not mute a defect later found in 38 more
places, and a single months-old issue must not make 38 newly-found locations vanish. So a
location-key match against an open issue leaves the defect new and hands the issue
number to synthesis as a comment target — which is also how the ~130 pre-clustering
one-issue-per-file findings get consolidated instead of orphaned.
Neither this workflow nor the doc walkthrough files a Nightly audit — <run-id> /
Doc walkthrough — <run-id> issue. Synthesis writes triage-report.md and a following
step appends it to $GITHUB_STEP_SUMMARY. There is no parent issue, no chain, no
cross-linking a prior run, and no "never close a parent" rule — that whole mechanism is
gone. It filed one bookkeeping issue per run and accumulated 19 of them, none actionable.
The report is a one-line tally (filed / commented / low / dropped) then a section per
dimension in fixed order — Correctness, Features, Docs, Tests — with each defect under the
dimension it declares, never re-bucketed, and 🔴 → 🟠 → 🟡 within a section. 🟡 lines
live here and nowhere else. The publishing step is plain bash under if: always(), so the
report survives a synthesis step that errored after writing it.
Still enforced: the workflow never closes an issue. Only a human does. An earlier version auto-closed the previous parent as "superseded" and silently hid 18 unaddressed findings the moment the next run fired (#2010). The parents are gone; the no-auto-close rule outlives them and applies to every issue the audits file or comment on.
Security moved to .github/workflows/claude-security-audit.yml (see its own patterns
skill). This audit files public issues, which is the wrong channel for a
vulnerability — so the prompt now tells every lens to hand off any security issue it
notices rather than file it, and the synthesis emits no security section. Do not
re-add a security dimension here or route a security finding into a public issue.
bug label → existing auto-fix jobFiled issues are opened without any auto-fix trigger label. A maintainer promotes
one to a PR by applying the bug label; the existing auto-fix job in
claude.yml (gated on label.name == 'bug' and contains(labels,'bug')) then
creates the branch + PR. There is no PR-creation code in this workflow — humans
gate every code change. A documentation/tests label alone does NOT trigger auto-fix;
route promotions through bug unless you deliberately widen the auto-fix if.
AUDIT_MODEL (top-level env, claude-opus-5-5 — $4/$20 per MTok, under half
Fable's price for comparable static-review quality, run at its default medium effort). One place to change it; swap to claude-fable-5 for maximum depth at ~2x
cost. A measured Fable deep run was ~$45 of API-equivalent subscription usage; Opus
roughly halves that.
⚠️ Model support is gated by the pinned claude-code-action version — the action
bundles the CLI that resolves model names, so a model newer than the pin is
unresolvable and fails as a broken job rather than a clear error. Bump the SHA in the
same change and prove it first with
gh workflow run claude-auth-canary.yml -f model=<new-id>.max-parallel: 1 so the run is a steady
drip, not a 4-job burst — this keeps it under the Max subscription's rolling (5-hour)
rate limit. If you re-parallelize, expect a token spike that can trip that limit.preflight before any Claude call on a night
with no commits. Deep mode never skips. This matters more now the cadence is nightly.claude-security-audit.yml also runs nightly, deliberately ~1.4h earlier at 09:13 UTC
so the two proactive Claude runs never stack on the shared subscription pool.normal = last N days' diff (window_days, default 1); deep = whole
codebase, auto-selected on Sundays.
⚠️ The selector keys off ISO day-of-week (date -u +%u, 7 = Sunday), NOT
day-of-month. It previously read day-of-month ≤ 7 and was only correct because the
cron fired on Mondays alone. Under the nightly cron that test matches the 1st–7th of
every month — seven consecutive whole-codebase deep sweeps instead of one. Do not
"simplify" it back to a day-of-month check.--allowedTools Read,Grep,Glob,Bash —
no Edit/Write, never install or run repo code (same rule as claude.yml review jobs).{"findings": []} even when
clean, so a missing file means the lens never ran: the upload fails on it, and synthesis
hard-fails if fewer files arrive than preflight declared dimensions. The doc
walkthrough gained the same gate per discovered guide (#3058) — without it a night where
every judge crashed reached synthesis, found nothing to file, and reported a clean run.claude-nightly-audit (not cancel-in-progress) so two scheduled
runs never overlap and double-file.dry_run dispatch input (both this workflow and the doc walkthrough): files and
comments nothing, and reports what it would have done in the job summary. This is the
only way to validate a dedup change against the live backlog without polluting it — a
bad dedup pass files dozens of duplicates, which is expensive to undo and untestable any
other way. Don't remove it.claude.yml job.
claude-auth-canary.yml covers the credentials — it does not cover the actor gate
below, because the canary runs on dispatch with a human actor.allowed_bots must name every bot that can actor a schedule event. On schedule
the actor is whoever last touched the default branch: github-merge-queue[bot] normally,
github-actions[bot] after a release workflow commits. A bot missing from the list means
claude-code-action rejects the run before Claude starts — and the run still reports
green. That failure went unnoticed for five weeks, and then recurred when the fix was
applied to the canary but not the six other steps (#3059). Every
anthropics/claude-code-action step in a scheduled workflow now needs
allowed_bots: "github-merge-queue,github-actions";
tests/unit/test_claude_audit_workflow_contract.py fails if one drops it.© amd, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/weekly-audit-patterns of amd/gaia.
Open the folder on GitHubat commit 6c3bb5c
Weekly Audit Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Weekly Audit Patterns this skillamd/gaia | 1.6k | — | ~4.4k | Automated safety check: Pass | MIT | |
| Agentic GitHub Actions Auditortrailofbits/skills | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Warden Security ReviewUsefulSoftwareCo/executor | 4.1k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Gha Security Reviewgetsentry/skills | 1k | 3 repos | ~2.2k | Automated safety check: Notes | Apache-2.0 | |
| Secure GitHub Actionsvechain/x-app-template | 450 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Fix Scan Findingmalloydata/publisher | 116 | — | ~5.1k | Automated safety check: Pass | MIT |
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
UsefulSoftwareCo/executor
Run Warden security scans in this repo using Sentry's warden-skills.
getsentry/skills
GitHub Actions security review for workflow exploitation vulnerabilities.
vechain/x-app-template
Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.
malloydata/publisher
Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…
semgrep/skills
Security guidelines for writing secure code. An agent skill from semgrep/skills.
amd/gaia
Adds a release eval scorecard to a GAIA hub agent by writing a harness adapter, running a real eval, and wiring the result into the agent's README and release gate.
amd/gaia
Walks through releasing a GAIA sidecar agent as a frozen binary plus npm client through the tag-triggered Agent Hub CI pipeline, with a human gate before publishing.
amd/gaia
Mines local Claude Code session transcripts with a deterministic Python pipeline to show what the agent is actually used for, how often it fails and what it costs.
amd/gaia
Benchmarks AMD's GAIA agent against Claude Code and across models on quality, honesty, steps, tokens, time and real cost, using gaia eval tasks.
amd/gaia
Guides safe code changes by finding the right file with grep or semantic search, reading before editing, reproducing bugs first, and proving a fix with a real test run.
amd/gaia
Walks through scaffolding, writing and testing a new GAIA agent as a Python class with the SDK, from the base Agent subclass to registered tool methods.
Works with
Categories
The non-obvious invariants of the proactive nightly Claude audit workflow (.github/workflows/claude-nightly-audit.yml): the day-of-week mode selector, the two-key dedup scheme (clusterkey per…. Weekly Audit Patterns is an agent skill from amd/gaia.yml) and which one owns the Fail-Loudly check, and the bug-label → auto-fix promotion path.
Weekly Audit Patterns fits situations like: tasks that involve Security review.
Run `npx skills add amd/gaia --skill weekly-audit-patterns -a claude-code`. Or copy the skill folder (.claude/skills/weekly-audit-patterns in amd/gaia) into .claude/skills/weekly-audit-patterns in your project. Claude Code loads it when a task matches its description.
Run `npx skills add amd/gaia --skill weekly-audit-patterns -a codex`. Or copy the skill folder (.claude/skills/weekly-audit-patterns in amd/gaia) into .agents/skills/weekly-audit-patterns in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add amd/gaia --skill weekly-audit-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/weekly-audit-patterns, .gemini/skills/weekly-audit-patterns, .github/skills/weekly-audit-patterns and .opencode/skills/weekly-audit-patterns in your project.
Going by SKILL.md and its folder, Weekly Audit Patterns needs the command-line tools its instructions call (gh).
SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Weekly Audit Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.4k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Weekly Audit Patterns: Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars), Warden Security Review (UsefulSoftwareCo/executor, 4.1k stars), Gha Security Review (getsentry/skills, 1k stars) and Secure GitHub Actions (vechain/x-app-template, 450 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
amd (a GitHub organization) maintains it in amd/gaia, which has 1,580 GitHub stars. The repository holds 44 skills in this directory. The repository was last updated on October 6, 2026.
Source: amd/gaia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.