Agent skill

Cb Automation

by BlkLeg in BlkLeg/CircuitBreaker

The maintenance automation around Circuit Breaker — which bots and scheduled workflows exist (Discord notifications, ledger watch, branch cleanup, Dependabot lockfile sync, the required-checks…

MITAuto-check passedDevelopment

Install Cb Automation

skills CLI
$ npx skills add BlkLeg/CircuitBreaker --skill cb-automation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BlkLeg/CircuitBreaker cb-automation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BlkLeg/CircuitBreaker.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/cb-automation .claude/skills/cb-automation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cb-automation
GitHub stars
201
Token cost
~2.4k tokens
SKILL.md length
1,167 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

The maintenance automation around Circuit Breaker — which bots and scheduled workflows exist (Discord notifications, ledger watch, branch cleanup, Dependabot lockfile sync, the required-checks…

  • Works in 5 steps: Events caused by GITHUB_TOKEN start no… → Draft releases are invisible without… → workflow_run and schedule only fire from… → …
  • Tasks that involve Dependency management
  • SKILL.md covers What runs on its own, GITHUB_TOKEN rules everything…, Discord and Adding an automation — checklist, plus 2 more sections
  • Calls make, gh and bash; needs GITHUB_TOKEN and COPILOT_GITHUB_TOKEN

What it does

Cb Automation is an agent skill from BlkLeg/CircuitBreaker. The maintenance automation around Circuit Breaker — which bots and scheduled workflows exist (Discord notifications, ledger watch, branch cleanup, Dependabot lockfile sync, the required-checks dispatcher, the post-release follow-up), the GITHUBTOKEN rules they are built around, how to add a new one safely, and the guardrails for AI agents (Copilot cloud agent, Agentic Workflows, Copilot CLI on the headless box). Use this whenever adding or changing a scheduled or bot workflow, anything under scripts/ci/, a…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management. It works with Discord and GitHub. The repository describes itself as: Bring your homelab to life. A self-hosted IPAM and service mapper that visualizes complex hardware, compute, and network relationships in real-time. The licence is MIT.

When your agent uses it

  • Tasks that involve Dependency management

Example prompts

  • “/cb-automation”

Requirements

  • Python 3
  • A credential in GITHUB_TOKEN
  • A credential in COPILOT_GITHUB_TOKEN

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Events caused by GITHUB_TOKEN start no workflows — no push,
  2. Draft releases are invisible without push access. A job that reads a
  3. workflow_run and schedule only fire from the default branch's copy
  4. pull_request_target hands out a writable token. Never check out and
  5. Creating PRs with GITHUB_TOKEN requires the repo setting "Allow GitHub

What it can do on your machine

Read from SKILL.md and the folder at commit fc44f2e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make
    • gh
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • COPILOT_GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cb Automation loads about 2.4k tokens when it runs. Until then it costs about 171 tokens; SKILL.md has 1,167 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~171
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BlkLeg/CircuitBreaker at commit fc44f2e, republished under its MIT licence (© BlkLeg). 1,167 words, ~2,406 tokens.

Download SKILL.mdSave it as .claude/skills/cb-automation/SKILL.md (or your agent's skills folder).
name
cb-automation
description
The maintenance automation around Circuit Breaker — which bots and scheduled workflows exist (Discord notifications, ledger watch, branch cleanup, Dependabot lockfile sync, the required-checks dispatcher, the post-release follow-up), the GITHUB_TOKEN rules they are built around, how to add a new one safely, and the guardrails for AI agents (Copilot cloud agent, Agentic Workflows, Copilot CLI on the headless box). Use this whenever adding or changing a scheduled or bot workflow, anything under scripts/ci/, a Discord notification, a workflow that pushes commits or opens PRs, a self-hosted runner, or an AI/agent workflow, and when asked why a bot did or did not act.

Circuit Breaker — Automation

One maintainer, no budget: automation exists to remove toil, and must never become toil itself (a noisy alert, a red check nobody owns, a bot that needs babysitting). Everything that needs a human reaches them through Discord.

What runs on its own

WorkflowWhenDoesTalks to Discord
notify.ymlEvery watched workflow completesscripts/ci/workflow_alert.py decides; posts failures (with ping) and recoveriesYes — it is the pager
release.ymlmake release-candidateSee cb-release"draft staged, waiting for you" (ping), "vX is published"
release-followup.ymlDispatched by release post-publishNext-patch PR into dev, stale draft cleanupVia notify.yml on failure
ledger-watch.ymlNightly 06:23 UTCscripts/ci/ledger_watch.py: one release-control issue listing ledger rows expiring within 30 days and risks past next_review; closes it when clearWhen a new issue opens (ping)
branch-cleanup.ymlSundays 05:00 UTC; manual dispatch defaults to dry runscripts/ci/branch_cleanup.py: deletes branches fully contained in main/dev, idle > 14 days, not the head or base of an open PRVia notify.yml on failure
dependabot-lockfile-sync.ymlDependabot pip PR into dev/mainRegenerates requirements.txt from poetry.lock with the base branch's generator, pushes, then dispatches required checksVia notify.yml on failure
dependabot-automerge.ymlDependabot PR opened/updatedQueues gh pr merge --auto for patch/minor updates into dev (the ruleset's 21 checks still decide); labels majors major-update and comments; never touches PRs into main—
security.yml, codeql.ymlWeekly + push/PR + dispatchScannersVia notify.yml on failure
e2e.ymlRC tag, agent-path PR, nightlyCalls composed-e2e.yml, quarantined (quarantined: true, QUAR-001, issue #162) — reports the register row instead of runningVia notify.yml on failure

Squash-merged branches are never cleaned up (their commits are not contained in main), by design of the containment rule.

GITHUB_TOKEN rules everything here is built around

  1. Events caused by GITHUB_TOKEN start no workflows — no push, pull_request, release, or push: tags run follows a bot's commit, PR, release or tag. The one exception is workflow_dispatch (and repository_dispatch). So:
    • a bot that pushes a commit or opens a PR must then run bash scripts/ci/dispatch_required_checks.sh <branch> [dev|main], which dispatches dev-ci.yml/ci.yml, security.yml and codeql.yml so all 21 required checks land on the head SHA. Without it the PR can never merge. The list of 21 lives only in tests/build/required_checks.py.
    • follow-on work after a release is dispatched, never triggered.
  2. Draft releases are invisible without push access. A job that reads a draft needs contents: write even if it only reads.
  3. workflow_run and schedule only fire from the default branch's copy of the workflow file. A new watcher or cron does nothing until it reaches main. Scheduled workflows carry # scheduled-ref: default-branch-intentional or pin a ref (test_scheduled_workflows_pin_their_ref).
  4. pull_request_target hands out a writable token. Never check out and execute the PR head in it: restore scripts from the base SHA (see dependabot-lockfile-sync.yml) and guard on the actor.
  5. Creating PRs with GITHUB_TOKEN requires the repo setting "Allow GitHub Actions to create and approve pull requests".

Discord

  • Send only through scripts/ci/notify_discord.py (--level info|success|warning|failure --title … [--body|--body-file] [--url] [--field k=v] [--mention]). Never curl the webhook.
  • Secrets: DISCORD_WEBHOOK_URL (required for anything to send) and DISCORD_MENTION_USER_ID (the numeric user id — Developer Mode, right-click your name, Copy User ID — never the username; used only with --mention, and a bad value costs only the ping, not the message). Both must be repository secrets: environment secrets are invisible to every job without that environment:. Pass them through step env:, never interpolated into run: — a test enforces it.
  • Unset webhook or a Discord outage = logged no-op, exit 0. A notification is never a reason for a job to fail.
  • allowed_mentions is always explicit: text can never ping @everyone, whatever a branch or commit is named. Only --mention pings, and only the configured user.
  • Notify on state changes, not on every run. New failure on main/dev or a scheduled/dispatched run → ping. Green after red → recovery, no ping. PR runs, cancellations and green-after-green → silence. A nightly that rewrites an existing issue does not re-notify.
  • Adding a workflow that should page: add its exact name: to notify.yml's workflows: list. test_every_watched_name_is_a_workflow_that_exists fails if a listed name stops matching.
Show full SKILL.md (506 more words)Show less

Adding an automation — checklist

  • Logic in a typed, docstringed stdlib script under scripts/ci/ with unit tests in tests/build/ (fixtures, no network). Nothing to register: make lint and scripts/ci/tier0-static.sh both glob scripts/*.py scripts/ci/*.py, so a new script is linted and type-checked the moment it lands. The enumeration these replaced had quietly lost 14 files, and only make lint — never CI — ran it.
  • If the job that runs it has no actions/setup-python step, the script must run on Python 3.10 — ubuntu-22.04's system python3. The dev venv's 3.12 hides the difference, which is how datetime.UTC reached quarantine_notice.py. tests/build/test_ci_scripts_match_runner_python.py fails the build on a newer stdlib name (an ast scan plus vermin), and ruff.toml pins the lint target to py310 so ruff cannot ask for a 3.11+ alias back. Either stay portable, or add actions/setup-python.
  • Top-level permissions: {} or read-only; grant per job, minimum needed.
  • Every ${{ }} through env: and quoted; actions pinned by tag like the rest of the repo (actions/checkout@v5), persist-credentials: false unless the job pushes.
  • Dispatch inputs get # checkov:skip=CKV_GHA_7 with a reason; run checkov -f <file> --framework github_actions locally.
  • Anything it pushes or opens is followed by dispatch_required_checks.sh.
  • Idempotent: a re-run for the same input updates or exits cleanly.
  • Destructive actions (delete branch, delete draft, close issue) re-check their precondition immediately before acting, and log each decision.
  • Failures reach Discord (add to notify.yml); successes usually don't.
  • Never continue-on-error to make it green, never auto-merge to main.

AI agents

Issue and PR text on this public repo is untrusted input. An agent that reads it must not also hold write access.

  • Copilot cloud agent (assign an issue, or gh agent-task create): for bounded code changes that come back as a PR for review. Good first tasks: QUAR-001 (#162), major Dependabot migrations, a shared sanitiser for the py/log-injection alerts. It reads CLAUDE.md and these skills (.claude/skills/ is a supported skills path), so the verification rules apply to it too.
  • GitHub Agentic Workflows (gh aw, Copilot engine): for judgement over untrusted text — issue triage, CI failure analysis, release-note drafts, security digests. Keep them read-only; writes go through safe outputs.
  • Copilot CLI unattended (cron on the headless box): explicit --allow-tool lists, never --allow-all/--yolo; always --deny-tool 'shell(git push)', --secret-env-vars, --max-ai-credits, --no-ask-user. Auth via a fine-grained PAT with Copilot Requests in COPILOT_GITHUB_TOKEN (classic PATs are not supported). Report through notify_discord.py.
  • Nothing an agent produces reaches main without a PR, the 21 required checks and a human merge. No agent approves or promotes a release.

The headless box (Fedora Server, AMD, always on)

Runs only what hosted runners cannot: the release soak (install the draft tarball, boot, probe /readyz, uninstall), a nightly make e2e-local against main, the Tier 3 QEMU fleet runner (fleet.yml, [self-hosted, qemu], needs KVM) and Copilot CLI report jobs.

Self-hosted runners on a public repo will run fork code unless restricted: register the box in a runner group limited to named workflows (fleet.yml and the soak/nightly ones), make jobs ephemeral (fresh container or VM per job), and never attach it to a pull_request trigger. Installer journeys there use rootless podman with --security-opt label=disable.

© BlkLeg, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/cb-automation of BlkLeg/CircuitBreaker.

Open the folder on GitHubat commit fc44f2e

Compare with similar skills

Cb Automation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cb Automation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cb Automation this skillBlkLeg/CircuitBreaker201—~2.4kAutomated safety check: PassMIT
ONNX Opset Bump Checklistmicrosoft/onnxruntime22k—~12kAutomated safety check: PassMIT
Merge Dependabot PRsonyx-dot-app/onyx32k1 repos~2.2kAutomated safety check: PassMIT
Update .NET OS Packagesdotnet/core22k—~2.3kAutomated safety check: PassMIT
OBS Plugin Dependency Upgradesorayuki/obs-multi-rtmp5.1k—~609Automated safety check: PassGPL-2.0
Renovate Actions PR Reviewbacknotprop/plannotator9.2k—~640Automated safety check: PassApache-2.0

Similar skills

  • ONNX Opset Bump Checklist

    microsoft/onnxruntime

    Official

    A checklist for upgrading the pinned ONNX version and opset in ONNX Runtime, covering the files to change, archive hashes, patch rebasing and release-candidate handling.

    22k GitHub stars~12k tokensUpdated today
    DevelopmentAuto-check passed
  • Merge Dependabot PRs

    onyx-dot-app/onyx

    Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes…

    32k GitHub starsUsed in 1 repo~2.2k tokens
    DevelopmentAuto-check passed
  • Official

    Audits and updates os-packages.json files listing the Linux packages each .NET release needs per distro, then regenerates the Markdown from the JSON.

    22k GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check passed
  • OBS Plugin Dependency Upgrade

    sorayuki/obs-multi-rtmp

    Updates the obs-multi-rtmp plugin repo to the latest upstream plugin template and OBS Studio version, including dependency metadata, then rebuilds it with CMake.

    5.1k GitHub stars~609 tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Renovate Actions PR Review

    backnotprop/plannotator

    Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.

    9.2k GitHub stars~640 tokensUpdated today
    DevelopmentAuto-check passed
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings

More from BlkLeg/CircuitBreaker

  • Cb Build Test

    BlkLeg/CircuitBreaker

    How Circuit Breaker is built, tested, packaged, and kept secret-safe — the make dev/verify/test targets, the PostgreSQL integration test database and its fixtures, the mono Docker image and native…

    201 GitHub stars~1.9k tokensUpdated 4 days ago
    Auto-check passed
  • Cb Code Quality

    BlkLeg/CircuitBreaker

    Circuit Breaker code conventions and the quality gates that actually block a push — ruff, mypy, eslint, the pytest coverage ratchet, and the make verify tiers.

    201 GitHub stars~1.9k tokensUpdated 4 days ago
    Auto-check passed
  • Cb Realtime API

    BlkLeg/CircuitBreaker

    How Circuit Breaker moves data between backend and frontend — the NATS internal bus, Redis pub/sub, the WebSocket stream endpoints and their first-message JWT handshake, SSE log/event streams, and…

    201 GitHub stars~1.7k tokensUpdated 4 days ago
    Auto-check passed
  • Cb Release

    BlkLeg/CircuitBreaker

    How a Circuit Breaker release is cut, approved, published and followed up — the candidate→approval→promote flow in release.yml, the release environment gate, the make release- targets, the…

    201 GitHub stars~1.8k tokensUpdated 4 days ago
    Auto-check passed
  • Cb Security Hardening

    BlkLeg/CircuitBreaker

    Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.

    201 GitHub stars~2.1k tokensUpdated 4 days ago
    Auto-check passed

Works with

Questions about Cb Automation

What does Cb Automation do?

The maintenance automation around Circuit Breaker — which bots and scheduled workflows exist (Discord notifications, ledger watch, branch cleanup, Dependabot lockfile sync, the required-checks…. Cb Automation is an agent skill from BlkLeg/CircuitBreaker. The maintenance automation around Circuit Breaker — which bots and scheduled workflows exist (Discord notifications, ledger watch, branch cleanup, Dependabot lockfile sync, the required-checks dispatcher, the post-release follow-up), the GITHUBTOKEN rules they are built around, how to add a new one safely, and the guardrails for AI agents (Copilot cloud agent, Agentic Workflows, Copilot CLI on the headless box).

When should I use Cb Automation?

Cb Automation fits situations like: tasks that involve Dependency management.

How do I install Cb Automation in Claude Code?

Run `npx skills add BlkLeg/CircuitBreaker --skill cb-automation -a claude-code`. Or copy the skill folder (.claude/skills/cb-automation in BlkLeg/CircuitBreaker) into .claude/skills/cb-automation in your project. Claude Code loads it when a task matches its description.

How do I install Cb Automation in Codex?

Run `npx skills add BlkLeg/CircuitBreaker --skill cb-automation -a codex`. Or copy the skill folder (.claude/skills/cb-automation in BlkLeg/CircuitBreaker) into .agents/skills/cb-automation in your project. Codex loads it when a task matches its description.

Can I use Cb Automation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BlkLeg/CircuitBreaker --skill cb-automation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cb-automation, .gemini/skills/cb-automation, .github/skills/cb-automation and .opencode/skills/cb-automation in your project.

What does Cb Automation need to run?

Going by SKILL.md and its folder, Cb Automation needs the command-line tools its instructions call (make, gh and bash) and credentials named GITHUB_TOKEN and COPILOT_GITHUB_TOKEN. Our summary lists: Python 3; A credential in GITHUB_TOKEN; A credential in COPILOT_GITHUB_TOKEN.

Does Cb Automation access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Cb Automation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cb Automation use?

Cb Automation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cb Automation use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cb Automation?

Skills that share tags, products or a category with Cb Automation: ONNX Opset Bump Checklist (microsoft/onnxruntime, 22k stars), Merge Dependabot PRs (onyx-dot-app/onyx, 32k stars), Update .NET OS Packages (dotnet/core, 22k stars) and OBS Plugin Dependency Upgrade (sorayuki/obs-multi-rtmp, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cb Automation?

BlkLeg (a GitHub user) maintains it in BlkLeg/CircuitBreaker, which has 201 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 5, 2026.

Source: BlkLeg/CircuitBreaker on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.