Agent skill

Audit Build CI

by ben-manes in ben-manes/caffeine

Audit build and CI configuration for correctness risks. An agent skill from ben-manes/caffeine.

Apache-2.0Auto-check passed

Install Audit Build CI

skills CLI
$ npx skills add ben-manes/caffeine --skill audit-build-ci -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ben-manes/caffeine audit-build-ci --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ben-manes/caffeine.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/audit-build-ci .claude/skills/audit-build-ci && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-build-ci
GitHub stars
18k
Token cost
~475 tokens
SKILL.md length
236 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit build and CI configuration for correctness risks. An agent skill from ben-manes/caffeine.

  • Calls gh

What it does

Audit Build CI is an agent skill from ben-manes/caffeine. Audit build and CI configuration for correctness risks

Its SKILL.md is about 480 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Gradle. The repository describes itself as: A high performance caching library for Java. The licence is Apache-2.0.

Example prompts

  • “/audit-build-ci”

What it can do on your machine

Read from SKILL.md and the folder at commit 998978c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Build CI loads about 475 tokens when it runs. Until then it costs about 17 tokens; SKILL.md has 236 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~17
When it runs · the whole SKILL.md, loaded when a task matches
~475

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ben-manes/caffeine at commit 998978c, republished under its Apache-2.0 licence (© ben-manes). 236 words, ~475 tokens.

Download SKILL.mdSave it as .claude/skills/audit-build-ci/SKILL.md (or your agent's skills folder).
name
audit-build-ci
description
Audit build and CI configuration for correctness risks
context
fork
agent
auditor
disable-model-invocation
true

Audit the build and CI configuration for subtle correctness risks.

Read the build files and CI workflows before analyzing:

  • build.gradle.kts (root and caffeine module)
  • gradle/plugins/ (custom Gradle plugins)
  • .github/workflows/ (GitHub Actions)
  • gradle.properties

Consider:

  • Misconfigured dependency scopes
  • Incorrect test isolation
  • Non-reproducible builds
  • Incorrect Gradle cache configuration
  • Missing failure modes (tests passing when they shouldn't)
  • Incorrect CI matrix coverage
  • Silent test skipping
  • Multi-line YAML values that get interpolated elsewhere (a > folded scalar keeps a trailing newline; splicing one into another folded scalar embeds that newline mid-string, so a consumer splitting on literal spaces mis-parses the spliced-in value's last token)
  • Performance problems in the build
  • Security issues (dependency vulnerabilities, secret exposure)
  • Bad practices that could cause false confidence
  • Retry and re-run paths (in-job retry loops, workflow_run re-runners) and what each treats as infrastructure. A job that exceeds timeout-minutes concludes cancelled, not failure, and a hung test reaches CI that way
  • Matrix legs that name a JDK distribution: without a vendor constraint, toolchain resolution may pick another detected JDK of the same version

Report only issues that could cause incorrect artifacts, missing failures, or false confidence in test results.

Price a CI finding against live history, not only the YAML: gh api for the ruleset and check-run conclusions, gh run view <id> --log (with --attempt/--job) for what a green run actually hid. A mechanism in a workflow and a run that concealed a failure are separate claims. Read-only queries only.

© ben-manes, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/audit-build-ci of ben-manes/caffeine.

Open the folder on GitHubat commit 998978c

Compare with similar skills

Audit Build CI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Build CI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Build CI this skillben-manes/caffeine18k—~475Automated safety check: PassApache-2.0
Android API Diffgkd-kit/gkd43k—~796Automated safety check: PassGPL-3.0
Exposed Bug Fix WorkflowJetBrains/Exposed9.3k—~3.8kAutomated safety check: PassApache-2.0
Android Developmentdpconde/claude-android-skill336—~1.7kAutomated safety check: PassMIT
Diagnosing Compose StabilityrosuH/EasyWatermark1.9k1 repos~3.3kAutomated safety check: PassApache-2.0
Geb and Spock Browser Testsapache/groovy-geb1.2k—~2.4kAutomated safety check: PassApache-2.0

Similar skills

  • Android API Diff

    gkd-kit/gkd

    Looks up Android framework Java and AIDL APIs across versions with the android-api-diff CLI: signatures, availability, source files and hidden-API access code.

    43k GitHub stars~796 tokensUpdated today
    MobileAuto-check passed
  • Exposed Bug Fix Workflow

    JetBrains/Exposed

    Official

    Takes a GitHub or YouTrack issue for the Exposed project through reproduction, a failing test, a fix, validation and a pull request.

    9.3k GitHub stars~3.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Android Development

    dpconde/claude-android-skill

    Create production-quality Android applications following Google's official architecture guidance and NowInAndroid best practices.

    336 GitHub stars~1.7k tokensUpdated 10 mo ago
    MobileAuto-check passed
  • Diagnosing Compose Stability

    rosuH/EasyWatermark

    A skill your agent uses to diagnose Jetpack Compose stability problems by enabling and reading the Compose Compiler Reports (classes.txt, composables.txt, composables.csv, module.json).

    1.9k GitHub starsUsed in 1 repo~3.3k tokens
    MobileAuto-check passed
  • Writes and reviews Geb browser automation specs with Spock, using Page Objects, at checkers, Modules and explicit waits, for Groovy and Gradle projects.

    1.2k GitHub stars~2.4k tokensUpdated 2 days ago
    Testing & QAAuto-check passed
  • Run Jetpack Android App

    wordpress-mobile/WordPress-Android

    Builds the Jetpack debug app with Gradle and installs it on a connected Android device or an emulator started from an available AVD.

    3.2k GitHub stars~886 tokensUpdated yesterday
    MobileAuto-check passed

More from ben-manes/caffeine

All 33 skills in this repo
  • Runs controlled JMH experiments on the Caffeine cache to find shared contention and hot-path waste, then reviews correctness and returns a reviewable patch.

    18k GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Git History Bug Audit

    ben-manes/caffeine

    Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.

    18k GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Adversarial Codebase Audit

    ben-manes/caffeine

    Runs a hostile review of the Caffeine Java caching library with parallel subagents that get no design docs, then challenges and consolidates their findings.

    18k GitHub stars~1.9k tokensUpdated today
    Auto-check: notes
  • Caffeine Performance Audit

    ben-manes/caffeine

    Audits the Caffeine cache source for hot-path costs such as allocations, contention and memory layout, reporting only findings tied to specific lines.

    18k GitHub stars~855 tokensUpdated today
    Auto-check passed
  • Audit Sibling Divergence

    ben-manes/caffeine

    Compares code paths that should behave the same, such as sync and async cache methods, and requires a concrete scenario where the two observably disagree.

    18k GitHub stars~4.6k tokensUpdated today
    Auto-check: notes
  • Climber Step Minimization

    ben-manes/caffeine

    Prices each step of the window climber algorithm by disabling it in turn, to find steps that no longer earn their keep and branches that no longer fire.

    18k GitHub stars~3k tokensUpdated today
    Auto-check: notes

Works with

Questions about Audit Build CI

What does Audit Build CI do?

Audit build and CI configuration for correctness risks. An agent skill from ben-manes/caffeine. Audit Build CI is an agent skill from ben-manes/caffeine.

How do I install Audit Build CI in Claude Code?

Run `npx skills add ben-manes/caffeine --skill audit-build-ci -a claude-code`. Or copy the skill folder (.claude/skills/audit-build-ci in ben-manes/caffeine) into .claude/skills/audit-build-ci in your project. Claude Code loads it when a task matches its description.

How do I install Audit Build CI in Codex?

Run `npx skills add ben-manes/caffeine --skill audit-build-ci -a codex`. Or copy the skill folder (.claude/skills/audit-build-ci in ben-manes/caffeine) into .agents/skills/audit-build-ci in your project. Codex loads it when a task matches its description.

Can I use Audit Build CI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ben-manes/caffeine --skill audit-build-ci -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-build-ci, .gemini/skills/audit-build-ci, .github/skills/audit-build-ci and .opencode/skills/audit-build-ci in your project.

What does Audit Build CI need to run?

Going by SKILL.md and its folder, Audit Build CI needs the command-line tools its instructions call (gh).

Does Audit Build CI access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Audit Build CI safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Build CI use?

Audit Build CI is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Build CI use?

About 475 tokens (SKILL.md is roughly 1.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Build CI?

Skills that share tags, products or a category with Audit Build CI: Android API Diff (gkd-kit/gkd, 43k stars), Exposed Bug Fix Workflow (JetBrains/Exposed, 9.3k stars), Android Development (dpconde/claude-android-skill, 336 stars) and Diagnosing Compose Stability (rosuH/EasyWatermark, 1.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Build CI?

ben-manes (a GitHub user) maintains it in ben-manes/caffeine, which has 17,881 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 11, 2026.

Source: ben-manes/caffeine on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.