Renovate Actions PR Review
backnotprop/plannotator
Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.
用 Personal Access Token 通过 GitHub REST API 分析 Actions CI 的失败 run/job/step、拉取日志、轮询运行状态、做 PR code review,并驱动 fix → push → watch → iterate 的闭环。Token 只从 GITHUBTOKEN 环境变量读取,不落盘、不回显。适合在 bifrost remote /…
$ npx skills add bifrost-proxy/bifrost --skill github-actions-pat -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install bifrost-proxy/bifrost github-actions-pat --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/bifrost-proxy/bifrost.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/github-actions-pat .claude/skills/github-actions-pat && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "github-actions-pat" agent skill from https://github.com/bifrost-proxy/bifrost/tree/main/.agents/skills/github-actions-pat into .claude/skills/github-actions-pat/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-pat", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/bifrost-proxy/bifrost/tree/main/.agents/skills/github-actions-patType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add bifrost-proxy/bifrost --skill github-actions-pat -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install bifrost-proxy/bifrost github-actions-pat --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bifrost-proxy/bifrost.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/github-actions-pat .agents/skills/github-actions-pat && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "github-actions-pat" agent skill from https://github.com/bifrost-proxy/bifrost/tree/main/.agents/skills/github-actions-pat into .agents/skills/github-actions-pat/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-pat", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add bifrost-proxy/bifrost --skill github-actions-pat -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install bifrost-proxy/bifrost github-actions-pat --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bifrost-proxy/bifrost.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/github-actions-pat .cursor/skills/github-actions-pat && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "github-actions-pat" agent skill from https://github.com/bifrost-proxy/bifrost/tree/main/.agents/skills/github-actions-pat into .cursor/skills/github-actions-pat/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-pat", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/bifrost-proxy/bifrost.git --path .agents/skills/github-actions-pat--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add bifrost-proxy/bifrost --skill github-actions-pat -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install bifrost-proxy/bifrost github-actions-pat --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bifrost-proxy/bifrost.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/github-actions-pat .gemini/skills/github-actions-pat && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "github-actions-pat" agent skill from https://github.com/bifrost-proxy/bifrost/tree/main/.agents/skills/github-actions-pat into .gemini/skills/github-actions-pat/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-pat", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install bifrost-proxy/bifrost github-actions-patInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add bifrost-proxy/bifrost --skill github-actions-pat -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/bifrost-proxy/bifrost.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/github-actions-pat .github/skills/github-actions-pat && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "github-actions-pat" agent skill from https://github.com/bifrost-proxy/bifrost/tree/main/.agents/skills/github-actions-pat into .github/skills/github-actions-pat/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-pat", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add bifrost-proxy/bifrost --skill github-actions-pat -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install bifrost-proxy/bifrost github-actions-pat --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bifrost-proxy/bifrost.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/github-actions-pat .opencode/skills/github-actions-pat && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "github-actions-pat" agent skill from https://github.com/bifrost-proxy/bifrost/tree/main/.agents/skills/github-actions-pat into .opencode/skills/github-actions-pat/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-actions-pat", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
github-actions-pat用 Personal Access Token 通过 GitHub REST API 分析 Actions CI 的失败 run/job/step、拉取日志、轮询运行状态、做 PR code review,并驱动 fix → push → watch → iterate 的闭环。Token 只从 GITHUBTOKEN 环境变量读取,不落盘、不回显。适合在 bifrost remote /…
GitHub Actions Pat is an agent skill from bifrost-proxy/bifrost. 用 Personal Access Token 通过 GitHub REST API 分析 Actions CI 的失败 run/job/step、拉取日志、轮询运行状态、做 PR code review,并驱动 fix → push → watch → iterate 的闭环。Token 只从 GITHUBTOKEN 环境变量读取,不落盘、不回显。适合在 bifrost remote / CI 调度器 / 无头环境里跑。仓库锁定在 AGENTS.md 或调用处通过 GHREPO 显式指定。
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `references/pitfalls.md`, `scripts/common.py` and `scripts/gh_ci.py`).
It sits in DevOps & Cloud, covering CI/CD, REST APIs and Code review. It works with GitHub Actions and GitHub. The repository describes itself as: Bifrost 是一个用 Rust 编写的高性能、AI 友好的代理服务器,它提供强大的请求拦截、修改和规则配置能力,支持 TLS 解密、脚本扩展等高级功能,支持强大的模糊搜索,支持导入导出分享,支持一键重放请求,支持Coding Agent 自主管理。提供类似 postman 的请求管理和验证能力,无缝和代理能力集成。 The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 019b7a4. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 5 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3bashcargogitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GITHUB_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
GitHub Actions Pat loads about 2k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 67 tokens; SKILL.md has 591 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from bifrost-proxy/bifrost at commit 019b7a4, republished under its MIT licence (© bifrost-proxy). 591 words, ~1,962 tokens.
.claude/skills/github-actions-pat/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.把"用 PAT 分析 GitHub Actions CI"这条路径固化成可复用脚本。本 skill 解决的典型场景:
auth 唯一路径:PAT 从 GITHUB_TOKEN 环境变量读取。不支持、不回退到 cookie / OAuth device flow / SSH / gh CLI 登录等其他方式。需要 agent 自主跑的 CI 分析、PR review、fix-push-watch 循环,全部用本 skill。
GITHUB_TOKEN 环境变量)GITHUB_TOKEN 读 token。不落盘、不写日志、不回显原文。# macOS / zsh 用户:交互式 shell 才会加载 ~/.zshrc
zsh -ic 'python3 scripts/gh_ci.py run <run_id>'
# bash 用户
bash -lc 'python3 scripts/gh_ci.py run <run_id>'
# 或在脚本运行前已 export GITHUB_TOKEN 的环境
python3 scripts/gh_ci.py run <run_id>exit 2,提示 ERROR: set GITHUB_TOKEN before running this skill。repo + actions:read(只读分析)。--post 发 review 时额外需要 pull_requests:write。脚本默认读环境变量 GH_REPO(格式 owner/repo),未设置时回退到本仓库。Agent 可在调用前写入:
export GH_REPO=bifrost-proxy/bifrost
python3 scripts/gh_ci.py pr 567或者在 AGENTS.md 顶部的仓库元信息中固化。
scripts/
├── common.py # token/http/分页/日志切片/归因
├── gh_ci.py # run / pr / sha / branch / regression
├── gh_review.py # PR metadata + diff + 分层建议 + 可选 --post
└── poll_run.py # 轮询一个 run 直到完成
references/
└── pitfalls.md # GitHub API 坑点清单(job log 302、Accept 415、system proxy MITM)# 按 run-id 分析
python3 scripts/gh_ci.py run 25269751068
# 按 PR 号找最近一次 failed
python3 scripts/gh_ci.py pr 567
# 按 commit sha 找
python3 scripts/gh_ci.py sha a96a4257
# 按分支找最近一次 failed
python3 scripts/gh_ci.py branch feat/agent --only-failed
# 与上一次 green 做 regression 对比(给出 compare URL + 提交区间)
python3 scripts/gh_ci.py regression 25269751068脚本行为:
GET /repos/{owner}/{repo}/actions/runs/... 拉 run 元数据GET .../jobs 筛出 conclusion=failureGET .../jobs/{id}/logs → 自动处理 302 到 Azure Blob signed URL(不能带 Authorization)error:、FAIL、panicked、##[error]、thread '...' panicked、test result: FAILED 等),抽 ±20 行上下文默认用 watch_jobs.py(fail-fast 模式)—— 只要有任何 job 先失败就立即退出并打印归因,不必等慢的 Windows/macOS bundle 跑完。
# 推荐:fail-fast 看护。任一 job 失败立即 exit 2 并打印归因 markdown
POLL_SEC=20 MAX_WAIT_SEC=3600 python3 scripts/watch_jobs.py <run_id>
# 只有在明确需要"等全部 job 跑完"(例如最终合入前的全绿确认)时才用 poll_run.py
POLL_SEC=45 MAX_WAIT_SEC=1800 python3 scripts/poll_run.py <run_id>
# exit 0 = success, 2 = failure, 3 = timeoutwatch_jobs.py 的退出语义:
0 → run 内所有 job 均 conclusion=success2 → 至少一个 job 进入 terminal-bad(failure / cancelled / timed_out / action_required / startup_failure);stdout 输出首个失败 job 的 name / step / root-cause bucket / 日志片段3 → 超出 MAX_WAIT_SEC 仍有 job 没结束典型闭环(agent 要这么跑,不要反复问用户,必须 fail-fast):
# 1) 修代码
# 2) 本地最小验证:cargo fmt + cargo clippy -D warnings + 相关测试
# 3) push
git push origin feat/agent
# 4) 找到新 run(注意 --any-status,否则 queued/in_progress 会被过滤掉)
python3 scripts/gh_ci.py branch feat/agent --any-status
# 5) fail-fast 看护:任一 job 失败就立刻退出并打印归因
python3 scripts/watch_jobs.py <new_run_id>
# 6) exit 2 → 按 stdout 里的 root-cause bucket + 日志片段立刻回到 (1) 修;
# exit 0 → 全绿,汇报用户;
# exit 3 → 用 gh_ci.py run <id> 查当前状态,延长 MAX_WAIT_SEC 后再 watch。⚠️ 严禁先
poll_run.py等到"整个 run 完成"再看结果。Windows / macOS bundle 这类长尾 job 经常要 20 分钟以上,早期失败的 Unit Tests / E2E 如果等到最后才处理,会把修复时间从"立即"拖成"半小时后"。用户明确要求"遇到异常就开始修复"。
# 只生成 markdown(默认,不发)
python3 scripts/gh_review.py 123
# 聚焦某些路径
python3 scripts/gh_review.py 123 --focus 'crates/agent/**'
# 限制 diff 上下文
python3 scripts/gh_review.py 123 --max-diff-lines 4000
# 显式 post(需要 pull_requests:write)
python3 scripts/gh_review.py 123 --post --event REQUEST_CHANGES默认只生成 markdown 不发;只有用户明确说"发出去 / post it / go ahead" 时才加 --post。
Azure Blob signed URL 不能带 Authorization
GitHub 的 /actions/jobs/{id}/logs 返回 302 指向 *.blob.core.windows.net 签名 URL。如果 HTTP client 自动跟随 redirect 并继续带 Authorization: Bearer ...,Azure 会 401 InvalidAuthenticationInfo。解决:手动拦截 redirect,二次请求移除 Authorization(本 skill 的 _fetch_job_log 已这样做)。
Accept 头不能写 text/plain
jobs/{id}/logs 端点会返回 415 Unsupported 'Accept' header。使用默认 application/vnd.github+json(由服务端 302 到签名 URL,body 是纯文本,直接 decode)。
system proxy 会导致 SSL 证书 MITM 失败
如果用户本机挂了代理(包括 bifrost 自己),Python 的 urllib 可能因 Missing Authority Key Identifier 而 CERTIFICATE_VERIFY_FAILED。跑脚本时 主动清掉代理环境变量:
NO_PROXY=api.github.com,github.com,*.blob.core.windows.net \
HTTPS_PROXY= HTTP_PROXY= ALL_PROXY= https_proxy= http_proxy= all_proxy= \
python3 scripts/gh_ci.py run <id>bifrost remote exec 的 quoting 噩梦
在 bifrost remote 上跑 Python 单行命令,\" 反斜杠层级会叠 3 层。把探针脚本写成文件后上传再执行(用 bifrost remote file write + bifrost remote exec python3 <script>)。
PII mask 会吞掉 token 原文
如果用户直接在聊天里粘 ghp_xxx...,平台 DLP 会把它替换成占位符。Agent 拿不到明文。正确做法:
export GITHUB_TOKEN=... 或写到 ~/.bifrost/gh_token,再告诉 agent 路径zsh -ic / bash -lc 加载 shell rc 读取run log (run-level) vs job log (job-level) run-level 日志是 zip,job-level 是纯文本。定位问题用 job 级别更快。本 skill 默认走 job 级别。
GitHub Actions 的 Accept 为 application/vnd.github+json 时,job log 返回的实际是 302 + 文本 body;不要用 binary 模式以外的逻辑复杂化解析。
[ -n "$GITHUB_TOKEN" ] || { echo "ERROR: GITHUB_TOKEN missing"; exit 2; }zsh -ic 加载用户 shell 配置。GH_REPO:每次调用前确认目标仓库,不要依赖默认值猜测。--post 加锁:执行 --post 前必须在用户消息里有明确同意("发出去 / post it / go ahead")。echo $GITHUB_TOKEN、不把 token 写进日志、不塞进 URL。NO_PROXY=api.github.com,github.com,*.blob.core.windows.net HTTPS_PROXY= HTTP_PROXY= ALL_PROXY= 前缀,避免 MITM 证书问题。| 现象 | 原因 | 处置 |
|---|---|---|
ERROR: set GITHUB_TOKEN | 未 export 或 shell 未加载 rc | zsh -ic / bash -lc,或让用户手动 export |
401 Bad credentials | token 失效 / 被吊销 | 让用户重新签发并 re-export |
401 InvalidAuthenticationInfo on *.blob.core.windows.net | signed URL 被带了 Authorization | 用本 skill 的 _fetch_job_log,不要用原生 urllib 自动跟随 |
415 Unsupported 'Accept' | Accept 设置为 text/plain 访问 logs 端点 | 用默认 Accept,服务端会 302 到 blob |
CERTIFICATE_VERIFY_FAILED: Missing Authority Key Identifier | 走了 bifrost 本身的 system proxy | NO_PROXY=api.github.com,...、HTTPS_PROXY= HTTP_PROXY= |
404 Not Found on run_id | run 在别的 repo / 已清理 / repo 拼错 | 核对 GH_REPO,或换 run_id |
x-ratelimit-remaining: 0 | 命中限流 | 等 x-ratelimit-reset(epoch 秒),或换 token |
github-actions-pat,PAT + Python):所有 GitHub Actions CI 检查、日志分析、PR review、fix-push-watch 闭环的唯一入口。rust-project-validate / e2e-test / e2e-verify:本地测试通过再 push,避免把"能在本地跑通"的活儿甩给 CI。cargo fmt / cargo clippy -D warnings / human_tests 流程。本 skill 只做「拉数据 + 归因 + 闭环驱动」,不替代本地 CI 前置检查。© bifrost-proxy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (scripts, references) in .agents/skills/github-actions-pat of bifrost-proxy/bifrost.
Open the folder on GitHubat commit 019b7a4
GitHub Actions Pat next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| GitHub Actions Pat this skillbifrost-proxy/bifrost | 160 | — | ~2k | Automated safety check: Pass | MIT | |
| Renovate Actions PR Reviewbacknotprop/plannotator | 9.2k | — | ~640 | Automated safety check: Pass | Apache-2.0 | |
| GitHub Automationruvnet/ruflo | 74k | 2 repos | ~368 | Automated safety check: Pass | MIT | |
| ReviewdogAgentSecOps/SecOpsAgentKit | 219 | 1 repos | ~3k | Automated safety check: Pass | Custom licence | |
| Posting Review Summarybitwarden/ai-plugins | 154 | — | ~2.3k | Automated safety check: Pass | Custom licence | |
| Released-kimuson/claude-code-viewer | 1.3k | — | ~1.2k | Automated safety check: Pass | MIT |
backnotprop/plannotator
Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.
ruvnet/ruflo
GitHub workflow automation, PR management, issue tracking, and code review coordination.
AgentSecOps/SecOpsAgentKit
Automated code review and security linting integration for CI/CD pipelines using reviewdog.
bitwarden/ai-plugins
A skill your agent uses when posting the final summary comment, including its No Verdict form when nothing could be reviewed and no inline comments exist.
d-kimuson/claude-code-viewer
Run the claude-code-viewer release flow end-to-end. An agent skill from d-kimuson/claude-code-viewer.
jmfederico/pi-web
A skill your agent uses whenever the user asks for a new npm version, npm release, package release, new release, version bump, publishing to npm, cutting a GitHub release, tagging a release, or…
bifrost-proxy/bifrost
Publish Markdown articles and Bifrost capability series to Juejin, or verify with Microsoft Edge that a published Juejin page's title and body match the local Markdown.
bifrost-proxy/bifrost
Open a target website, wait for user login, verify login with required cookies plus an HTTP probe, and save cookies into .env for later automation.
bifrost-proxy/bifrost
Publish Markdown articles to Zhihu Columns through authentication context recovered locally from Bifrost traffic and a built-in publish payload schema, save drafts, prevent duplicate posts, and…
bifrost-proxy/bifrost
Inspect Codex async task progress from the correct data directory.
bifrost-proxy/bifrost
面向 Bifrost 管理端的端到端 UI 与 API 验证工具. An agent skill from bifrost-proxy/bifrost.
bifrost-proxy/bifrost
A skill your agent uses when changing Bifrost WebUI, desktop shell UI, public site, docs visual style, interaction patterns, layout, copy density, colors, typography, spacing, or component styling.
Works with
Categories
用 Personal Access Token 通过 GitHub REST API 分析 Actions CI 的失败 run/job/step、拉取日志、轮询运行状态、做 PR code review,并驱动 fix → push → watch → iterate 的闭环。Token 只从 GITHUBTOKEN 环境变量读取,不落盘、不回显。适合在 bifrost remote /…. GitHub Actions Pat is an agent skill from bifrost-proxy/bifrost.
GitHub Actions Pat fits situations like: tasks that involve CI/CD; tasks that involve REST APIs; tasks that involve Code review.
Run `npx skills add bifrost-proxy/bifrost --skill github-actions-pat -a claude-code`. Or copy the skill folder (.agents/skills/github-actions-pat in bifrost-proxy/bifrost) into .claude/skills/github-actions-pat in your project. Claude Code loads it when a task matches its description.
Run `npx skills add bifrost-proxy/bifrost --skill github-actions-pat -a codex`. Or copy the skill folder (.agents/skills/github-actions-pat in bifrost-proxy/bifrost) into .agents/skills/github-actions-pat in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bifrost-proxy/bifrost --skill github-actions-pat -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-actions-pat, .gemini/skills/github-actions-pat, .github/skills/github-actions-pat and .opencode/skills/github-actions-pat in your project.
Going by SKILL.md and its folder, GitHub Actions Pat needs Python for the scripts in its folder, the command-line tools its instructions call (python3, bash, cargo and git) and credentials named GITHUB_TOKEN. Our summary lists: Python 3; A credential in GITHUB_TOKEN.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
GitHub Actions Pat is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with GitHub Actions Pat: Renovate Actions PR Review (backnotprop/plannotator, 9.2k stars), GitHub Automation (ruvnet/ruflo, 74k stars), Reviewdog (AgentSecOps/SecOpsAgentKit, 219 stars) and Posting Review Summary (bitwarden/ai-plugins, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
bifrost-proxy (a GitHub user) maintains it in bifrost-proxy/bifrost, which has 160 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 6, 2026.
Source: bifrost-proxy/bifrost on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.