Agent skill

GitHub Actions

by BagelHole in BagelHole/DevOps-Security-Agent-Skills

Build, test, and deploy applications using GitHub Actions workflows.

MITAuto-check passedDevOps & Cloud

Install GitHub Actions

skills CLI
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill github-actions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BagelHole/DevOps-Security-Agent-Skills github-actions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/devops/ci-cd/github-actions .claude/skills/github-actions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
github-actions
GitHub stars
1.1k
Token cost
~1.7k tokens
SKILL.md length
262 words
Files
2 (incl. references)
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

Build, test, and deploy applications using GitHub Actions workflows.

  • Working with GitHub repositories
  • SKILL.md covers When to Use This Skill, Prerequisites, Workflow File Structure and Common Triggers, plus 9 more sections
  • Calls curl; reaches github.com; needs AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY
  • Automating builds

What it does

GitHub Actions is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Build, test, and deploy applications using GitHub Actions workflows. Create CI/CD pipelines, configure runners, manage secrets, and automate software delivery. Use when working with GitHub repositories, automating builds, running tests, or deploying applications.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/workflow-patterns.md`).

It sits in DevOps & Cloud, covering CI/CD. It works with GitHub Actions, GitHub, Docker and GitLab. The repository describes itself as: Agent-ready DevOps, security, infrastructure, and compliance knowledge base with 80+ skills across Kubernetes, Terraform, AWS/Azure/GCP, AI platform operations, container… The licence is MIT.

When your agent uses it

  • Working with GitHub repositories
  • Automating builds
  • Deploying applications

Example prompts

  • “/github-actions”

Requirements

  • Node.js
  • Docker
  • A credential in AWS_SECRET_ACCESS_KEY
  • A credential in STAGING_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 0365f57. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AWS_ACCESS_KEY_ID
    • AWS_SECRET_ACCESS_KEY
    • DOCKER_PASSWORD
    • STAGING_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GitHub Actions loads about 1.7k tokens when it runs, and up to ~2.2k if it reads all its reference files. Until then it costs about 70 tokens; SKILL.md has 262 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BagelHole/DevOps-Security-Agent-Skills at commit 0365f57, republished under its MIT licence (© BagelHole). 262 words, ~1,683 tokens.

Download SKILL.mdSave it as .claude/skills/github-actions/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
github-actions
description
Build, test, and deploy applications using GitHub Actions workflows. Create CI/CD pipelines, configure runners, manage secrets, and automate software delivery. Use when working with GitHub repositories, automating builds, running tests, or deploying applications.
license
MIT
metadata.author
devops-skills
metadata.version
1.0

GitHub Actions

Automate software workflows directly in your GitHub repository with GitHub Actions.

When to Use This Skill

Use this skill when:

  • Setting up CI/CD pipelines for GitHub repositories
  • Automating build, test, and deployment workflows
  • Creating reusable workflow components
  • Configuring self-hosted runners
  • Managing workflow secrets and variables
  • Debugging failed workflow runs

Prerequisites

  • GitHub repository with write access
  • Understanding of YAML syntax
  • For self-hosted runners: server with Docker (optional)

Workflow File Structure

Workflows are defined in .github/workflows/ directory:

yaml
name: CI Pipeline

on:
  push:
    branches: [main, develop]
  pull_request:
    branches: [main]

jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - name: Setup Node.js
        uses: actions/setup-node@v4
        with:
          node-version: '20'
          cache: 'npm'
      - run: npm ci
      - run: npm test

Common Triggers

Push and Pull Request
yaml
on:
  push:
    branches: [main]
    paths:
      - 'src/**'
      - 'package.json'
  pull_request:
    branches: [main]
Scheduled Runs
yaml
on:
  schedule:
    - cron: '0 2 * * *'  # Daily at 2 AM UTC
Manual Dispatch
yaml
on:
  workflow_dispatch:
    inputs:
      environment:
        description: 'Deployment environment'
        required: true
        default: 'staging'
        type: choice
        options:
          - staging
          - production

Job Configuration

Matrix Builds
yaml
jobs:
  test:
    runs-on: ubuntu-latest
    strategy:
      matrix:
        node-version: [18, 20, 22]
        os: [ubuntu-latest, windows-latest]
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-node@v4
        with:
          node-version: ${{ matrix.node-version }}
      - run: npm test
Job Dependencies
yaml
jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - run: npm run build
      
  test:
    needs: build
    runs-on: ubuntu-latest
    steps:
      - run: npm test
      
  deploy:
    needs: [build, test]
    runs-on: ubuntu-latest
    steps:
      - run: ./deploy.sh
Environment Protection
yaml
jobs:
  deploy:
    runs-on: ubuntu-latest
    environment:
      name: production
      url: https://example.com
    steps:
      - run: ./deploy.sh

Secrets and Variables

Using Secrets
yaml
steps:
  - name: Deploy
    env:
      AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
      AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
    run: aws s3 sync ./dist s3://my-bucket
Using Variables
yaml
steps:
  - name: Build
    env:
      API_URL: ${{ vars.API_URL }}
    run: npm run build

Caching Dependencies

yaml
- uses: actions/cache@v4
  with:
    path: ~/.npm
    key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
    restore-keys: |
      ${{ runner.os }}-node-

Artifacts

Upload Artifacts
yaml
- uses: actions/upload-artifact@v4
  with:
    name: build-output
    path: dist/
    retention-days: 5
Download Artifacts
yaml
- uses: actions/download-artifact@v4
  with:
    name: build-output
    path: dist/

Docker Builds

yaml
jobs:
  docker:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      
      - name: Login to Docker Hub
        uses: docker/login-action@v3
        with:
          username: ${{ secrets.DOCKER_USERNAME }}
          password: ${{ secrets.DOCKER_PASSWORD }}
      
      - name: Build and push
        uses: docker/build-push-action@v5
        with:
          context: .
          push: true
          tags: user/app:latest

Reusable Workflows

Define Reusable Workflow
yaml
# .github/workflows/reusable-deploy.yml
name: Reusable Deploy

on:
  workflow_call:
    inputs:
      environment:
        required: true
        type: string
    secrets:
      deploy_key:
        required: true

jobs:
  deploy:
    runs-on: ubuntu-latest
    environment: ${{ inputs.environment }}
    steps:
      - run: echo "Deploying to ${{ inputs.environment }}"
Call Reusable Workflow
yaml
jobs:
  deploy-staging:
    uses: ./.github/workflows/reusable-deploy.yml
    with:
      environment: staging
    secrets:
      deploy_key: ${{ secrets.STAGING_KEY }}

Self-Hosted Runners

Register Runner
bash
# Download runner
mkdir actions-runner && cd actions-runner
curl -o actions-runner-linux-x64.tar.gz -L https://github.com/actions/runner/releases/download/v2.311.0/actions-runner-linux-x64-2.311.0.tar.gz
tar xzf actions-runner-linux-x64.tar.gz

# Configure
./config.sh --url https://github.com/OWNER/REPO --token TOKEN

# Run
./run.sh
Use Self-Hosted Runner
yaml
jobs:
  build:
    runs-on: self-hosted
    steps:
      - uses: actions/checkout@v4

Debugging Workflows

Enable Debug Logging

Set repository secrets:

  • ACTIONS_RUNNER_DEBUG: true
  • ACTIONS_STEP_DEBUG: true
Debug Step
yaml
- name: Debug
  run: |
    echo "GitHub context: ${{ toJson(github) }}"
    echo "Job context: ${{ toJson(job) }}"

Common Issues

Issue: Workflow Not Triggering

Problem: Workflow doesn't run on push/PR Solution: Check branch filters, path filters, and ensure workflow file is on the default branch

Issue: Permission Denied

Problem: Actions can't push or create PRs Solution: Configure permissions in workflow or update repository settings

yaml
permissions:
  contents: write
  pull-requests: write
Issue: Cache Not Restoring

Problem: Cache misses despite existing cache Solution: Verify cache key matches exactly, check runner OS

Best Practices

  • Pin action versions to specific commits or tags
  • Use caching for dependencies to speed up builds
  • Minimize secrets exposure with environment scoping
  • Use matrix builds for cross-platform testing
  • Implement proper error handling with continue-on-error
  • Keep workflows DRY with reusable workflows and composite actions

© BagelHole, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in devops/ci-cd/github-actions of BagelHole/DevOps-Security-Agent-Skills.

  • SKILL.md
  • references/workflow-patterns.md

Open the folder on GitHubat commit 0365f57

Compare with similar skills

GitHub Actions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitHub Actions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitHub Actions this skillBagelHole/DevOps-Security-Agent-Skills1.1k—~1.7kAutomated safety check: PassMIT
CI CDEliasOulkadi/shokunin114—~3.4kAutomated safety check: NotesMIT
GitHub Actionssickn33/agentic-awesome-skills47k1 repos~1.9kAutomated safety check: PassMIT
Megalinter Checknvuillam/npm-groovy-lint2481 repos~3.9kAutomated safety check: NotesMIT
Migrate To TeamcityJetBrains/teamcity-cli125—~1.3kAutomated safety check: PassApache-2.0
CI CDahmedasmar/devops-claude-skills203—~3.5kAutomated safety check: PassNone

Similar skills

  • CI CD

    EliasOulkadi/shokunin

    Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary)…

    114 GitHub stars~3.4k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • GitHub Actions

    sickn33/agentic-awesome-skills

    Build, test, and deploy applications using GitHub Actions workflows.

    47k GitHub starsUsed in 1 repo~1.9k tokens
    DevOps & CloudAuto-check passed
  • Megalinter Check

    nvuillam/npm-groovy-lint

    Collect MegaLinter lint errors for the current repository. An agent skill from nvuillam/npm-groovy-lint.

    248 GitHub starsUsed in 1 repo~3.9k tokens
    DevOps & CloudAuto-check: notes
  • Migrate To Teamcity

    JetBrains/teamcity-cli

    Official

    Migrating CI/CD pipelines to TeamCity. An agent skill from JetBrains/teamcity-cli.

    125 GitHub stars~1.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • CI CD

    ahmedasmar/devops-claude-skills

    CI/CD pipeline design, optimization, DevSecOps security scanning, and troubleshooting.

    203 GitHub stars~3.5k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check passed
  • Official

    Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run.

    5.6k GitHub starsUsed in 1 repo~2.3k tokens
    DevOps & CloudAuto-check passed

More from BagelHole/DevOps-Security-Agent-Skills

All 39 skills in this repo
  • Hashicorp Vault

    BagelHole/DevOps-Security-Agent-Skills

    Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~2k tokensUpdated 4 mo ago
    Auto-check passed
  • Incident Response

    BagelHole/DevOps-Security-Agent-Skills

    Handle security incidents with IR playbooks and procedures. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~4.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Kubernetes Ops

    BagelHole/DevOps-Security-Agent-Skills

    Deploy, scale, and manage Kubernetes workloads. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~2.3k tokensUpdated 4 mo ago
    Auto-check passed
  • Linux Hardening

    BagelHole/DevOps-Security-Agent-Skills

    Apply CIS benchmarks and secure Linux servers. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~662 tokensUpdated 4 mo ago
    Auto-check: notes
  • Prometheus Grafana

    BagelHole/DevOps-Security-Agent-Skills

    Set up metrics collection and visualization with Prometheus and Grafana.

    1.1k GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Vulnerability Scanning

    BagelHole/DevOps-Security-Agent-Skills

    Scan systems and dependencies for CVEs and security vulnerabilities.

    1.1k GitHub stars~2.4k tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about GitHub Actions

What does GitHub Actions do?

Build, test, and deploy applications using GitHub Actions workflows. GitHub Actions is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Build, test, and deploy applications using GitHub Actions workflows.

When should I use GitHub Actions?

GitHub Actions fits situations like: working with GitHub repositories; automating builds; deploying applications.

How do I install GitHub Actions in Claude Code?

Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill github-actions -a claude-code`. Or copy the skill folder (devops/ci-cd/github-actions in BagelHole/DevOps-Security-Agent-Skills) into .claude/skills/github-actions in your project. Claude Code loads it when a task matches its description.

How do I install GitHub Actions in Codex?

Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill github-actions -a codex`. Or copy the skill folder (devops/ci-cd/github-actions in BagelHole/DevOps-Security-Agent-Skills) into .agents/skills/github-actions in your project. Codex loads it when a task matches its description.

Can I use GitHub Actions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill github-actions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-actions, .gemini/skills/github-actions, .github/skills/github-actions and .opencode/skills/github-actions in your project.

What does GitHub Actions need to run?

Going by SKILL.md and its folder, GitHub Actions needs the command-line tools its instructions call (curl) and credentials named AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, DOCKER_PASSWORD and STAGING_KEY. Our summary lists: Node.js; Docker; A credential in AWS_SECRET_ACCESS_KEY; A credential in STAGING_KEY.

Does GitHub Actions access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is GitHub Actions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does GitHub Actions use?

GitHub Actions is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitHub Actions use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 507 tokens, read only when the agent opens those files.

What are the alternatives to GitHub Actions?

Skills that share tags, products or a category with GitHub Actions: CI CD (EliasOulkadi/shokunin, 114 stars), GitHub Actions (sickn33/agentic-awesome-skills, 47k stars), Megalinter Check (nvuillam/npm-groovy-lint, 248 stars) and Migrate To Teamcity (JetBrains/teamcity-cli, 125 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitHub Actions?

BagelHole (a GitHub user) maintains it in BagelHole/DevOps-Security-Agent-Skills, which has 1,141 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on May 22, 2026.

Source: BagelHole/DevOps-Security-Agent-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.