Official agent skill

Workflow Audit

by bitwarden in bitwarden/ai-plugins

Run the Bitwarden workflow linter (bwwl) against one or more repos and report findings.

OfficialCustom licenceAuto-check passedDevelopment

Install Workflow Audit

skills CLI
$ npx skills add bitwarden/ai-plugins --skill workflow-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bitwarden/ai-plugins workflow-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bitwarden/ai-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/bitwarden-devops-engineer/skills/workflow-audit .claude/skills/workflow-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
workflow-audit
GitHub stars
154
Token cost
~696 tokens
SKILL.md length
270 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
Custom licence

At a glance

Run the Bitwarden workflow linter (bwwl) against one or more repos and report findings.

  • Works in 5 steps: Verify Prerequisites → Determine Scope → Run the Linter → …
  • Workflow-audit for that repo </example <example User: Lint the workflows across server
  • SKILL.md covers Rules, Step 1: Verify Prerequisites, Step 2: Determine Scope and Step 3: Run the Linter, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Workflow Audit is an agent skill from bitwarden/ai-plugins, published by the product's own GitHub organization. Run the Bitwarden workflow linter (bwwl) against one or more repos and report findings. Strictly read-only — does not modify any files. Categorizes findings as mechanical or judgment using the bitwarden-workflow-linter-rules skill. Supports single repo, multiple repos, or single file/directory scope. <example User: Run the workflow linter on the server repo Action: Trigger workflow-audit for that repo </example <example User: Lint the workflows across server, clients, and android Action: Trigger workflow-audit in…

Its SKILL.md is about 700 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Linting and formatting. It works with Android and GitHub Actions. The repository describes itself as: AI plugin marketplace.

When your agent uses it

  • Workflow-audit for that repo </example <example User: Lint the workflows across server
  • Android Action: Trigger workflow-audit in multi-repo mode </example

Example prompts

  • “/workflow-audit”

Requirements

  • Pre-approved tools (allowed-tools): Read, Glob, Grep, Skill, Bash(bwwl:*)

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Verify Prerequisites
  2. Determine Scope
  3. Run the Linter
  4. Parse and Categorize Findings
  5. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 0047fdf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Glob
    • Grep
    • Skill
    • Bash(bwwl:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Workflow Audit loads about 696 tokens when it runs. Until then it costs about 141 tokens; SKILL.md has 270 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~141
When it runs · the whole SKILL.md, loaded when a task matches
~696

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 270 words (~696 tokens).

name
workflow-audit
allowed-tools
Read, Glob, Grep, Skill, Bash(bwwl:*)

Read the full SKILL.md on GitHub

Files

Just SKILL.md in plugins/bitwarden-devops-engineer/skills/workflow-audit of bitwarden/ai-plugins.

Open the folder on GitHubat commit 0047fdf

Compare with similar skills

Workflow Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Workflow Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Workflow Audit this skillbitwarden/ai-plugins154—~696Automated safety check: PassCustom licence
Post Edit VerificationGerardPaligot/Confily152—~1.1kAutomated safety check: PassApache-2.0
Babysit PR To Pass CIsgl-project/sglang37k2 repos~3kAutomated safety check: PassApache-2.0
File Good First BugBrowserWorks/waterfox-android3761 repos~2kAutomated safety check: PassCustom licence
Dep Validateblokadaorg/blokada3.3k—~5.7kAutomated safety check: NotesMPL-2.0
Android Code Quality Checkerwordpress-mobile/WordPress-Android3.2k—~587Automated safety check: PassGPL-2.0

Similar skills

  • Post Edit Verification

    GerardPaligot/Confily

    Use this skill after every working session where Kotlin or Android code was created or modified, and ALWAYS before committing, opening a PR, or reporting work as done.

    152 GitHub stars~1.1k tokensUpdated 10 days ago
    MobileAuto-check passed
  • Babysit PR To Pass CI

    sgl-project/sglang

    Start and persistently pursue a goal to babysit an SGLang pull request until selected GitHub Actions workflows pass on the latest PR head.

    37k GitHub starsUsed in 2 repos~3k tokens
    DevelopmentAuto-check passed
  • File Good First Bug

    BrowserWorks/waterfox-android

    A skill your agent uses when the user wants to file good-first-bugs in Bugzilla for Firefox.

    376 GitHub starsUsed in 1 repo~2k tokens
    DevelopmentAuto-check passed
  • Dep Validate

    blokadaorg/blokada

    A skill your agent uses to validate risky dependency bumps end to end as a local or cloud-launched agent.

    3.3k GitHub stars~5.7k tokensUpdated today
    DevelopmentAuto-check: notes
  • Android Code Quality Checker

    wordpress-mobile/WordPress-Android

    Runs detekt, checkstyle, and Android lint together, reads their reports, and proposes approved fixes grouped by file.

    3.2k GitHub stars~587 tokensUpdated today
    DevelopmentAuto-check passed
  • Update Dependencies

    alorence/django-modern-rpc

    Routine update of all project dependencies — uv itself, uv.lock (all groups), tool versions pinned in GitHub workflows and .pre-commit-config.yaml (uv, ruff, mypy...), and SHA-pinned GitHub Actions.

    111 GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check passed

More from bitwarden/ai-plugins

All 33 skills in this repo
  • Reviewing Claude Config

    bitwarden/ai-plugins

    Official

    Reviews Claude configuration files for security, structure, and prompt engineering quality.

    154 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Managing Workflow Secrets

    bitwarden/ai-plugins

    Official

    Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions…

    154 GitHub stars~4k tokensUpdated today
    Auto-check passed
  • Official

    This skill should be used when the user asks to "review the security architecture", "check authentication patterns", "evaluate trust boundaries", "review encryption implementation", "assess…

    154 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Official

    Audits an external (third-party) Claude Code plugin pinned in this marketplace for security risk before it is vendored, and writes the report to a file for downstream posting.

    154 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Action Audit

    bitwarden/ai-plugins

    Official

    Audit GitHub Actions action usage across an org. An agent skill from bitwarden/ai-plugins.

    154 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Action Remediate

    bitwarden/ai-plugins

    Official

    Remediate GitHub Actions action findings identified by the action-audit skill.

    154 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Categories

Questions about Workflow Audit

What does Workflow Audit do?

Run the Bitwarden workflow linter (bwwl) against one or more repos and report findings. Workflow Audit is an agent skill from bitwarden/ai-plugins, published by the product's own GitHub organization. Run the Bitwarden workflow linter (bwwl) against one or more repos and report findings.

When should I use Workflow Audit?

Workflow Audit fits situations like: workflow-audit for that repo </example <example User: Lint the workflows across server; android Action: Trigger workflow-audit in multi-repo mode </example.

How do I install Workflow Audit in Claude Code?

Run `npx skills add bitwarden/ai-plugins --skill workflow-audit -a claude-code`. Or copy the skill folder (plugins/bitwarden-devops-engineer/skills/workflow-audit in bitwarden/ai-plugins) into .claude/skills/workflow-audit in your project. Claude Code loads it when a task matches its description.

How do I install Workflow Audit in Codex?

Run `npx skills add bitwarden/ai-plugins --skill workflow-audit -a codex`. Or copy the skill folder (plugins/bitwarden-devops-engineer/skills/workflow-audit in bitwarden/ai-plugins) into .agents/skills/workflow-audit in your project. Codex loads it when a task matches its description.

Can I use Workflow Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bitwarden/ai-plugins --skill workflow-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/workflow-audit, .gemini/skills/workflow-audit, .github/skills/workflow-audit and .opencode/skills/workflow-audit in your project.

What does Workflow Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Workflow Audit is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Glob, Grep, Skill, Bash(bwwl:*).

Does Workflow Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Workflow Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Workflow Audit use?

Workflow Audit has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Workflow Audit use?

About 696 tokens (SKILL.md is roughly 2.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Workflow Audit?

Skills that share tags, products or a category with Workflow Audit: Post Edit Verification (GerardPaligot/Confily, 152 stars), Babysit PR To Pass CI (sgl-project/sglang, 37k stars), File Good First Bug (BrowserWorks/waterfox-android, 376 stars) and Dep Validate (blokadaorg/blokada, 3.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Workflow Audit?

bitwarden (a GitHub organization, an official publisher) maintains it in bitwarden/ai-plugins, which has 154 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 6, 2026.

Source: bitwarden/ai-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.