Agent skill

CI Validation Gates

by bradygaster in bradygaster/squad

Defensive CI/CD patterns: semver validation, token checks, retry logic, and draft detection

MITAuto-check passedDevOps & Cloud

Install CI Validation Gates

skills CLI
$ npx skills add bradygaster/squad --skill ci-validation-gates -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bradygaster/squad ci-validation-gates --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bradygaster/squad.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.copilot/skills/ci-validation-gates .claude/skills/ci-validation-gates && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ci-validation-gates
GitHub stars
3.3k
Token cost
~1.1k tokens
SKILL.md length
458 words
Files
1
Skills in repo
31
Repo updated
First seen
Licence
MIT

At a glance

Defensive CI/CD patterns: semver validation, token checks, retry logic, and draft detection

  • Tasks that involve Error handling
  • SKILL.md covers Context, Patterns, Known Failure Modes and Anti-Patterns
  • Calls npm, curl and npx; needs NPM_TOKEN
  • Tasks that involve CI/CD

What it does

CI Validation Gates is an agent skill from bradygaster/squad. Defensive CI/CD patterns: semver validation, token checks, retry logic, and draft detection

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Error handling and CI/CD. It works with npm. The repository describes itself as: Squad: AI agent teams for any project. The licence is MIT.

When your agent uses it

  • Tasks that involve Error handling
  • Tasks that involve CI/CD

Example prompts

  • “/ci-validation-gates”

Requirements

  • Node.js
  • A credential in NPM_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit d2364df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • curl
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, curl and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NPM_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

CI Validation Gates loads about 1.1k tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 458 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from bradygaster/squad at commit d2364df, republished under its MIT licence (© bradygaster). 458 words, ~1,112 tokens.

Download SKILL.mdSave it as .claude/skills/ci-validation-gates/SKILL.md (or your agent's skills folder).
name
ci-validation-gates
description
Defensive CI/CD patterns: semver validation, token checks, retry logic, and draft detection
domain
ci-cd
confidence
high
source
extracted from release and CI incident lessons

Context

CI workflows must be defensive. These patterns capture lessons from prior release incidents; they are maintained as version-agnostic gates rather than claims about a particular repository release.

Patterns

Semver Validation Gate

Every publish workflow MUST validate version format before npm publish. 4-part versions (e.g., 0.8.21.4) are NOT valid semver — npm mangles them.

yaml
- name: Validate semver
  run: |
    VERSION="${{ github.event.release.tag_name }}"
    VERSION="${VERSION#v}"
    if ! npx semver "$VERSION" > /dev/null 2>&1; then
      echo "❌ Invalid semver: $VERSION"
      echo "Only 3-part versions (X.Y.Z) or prerelease (X.Y.Z-tag.N) are valid."
      exit 1
    fi
    echo "✅ Valid semver: $VERSION"
NPM Token Type Verification

NPM_TOKEN MUST be an Automation token, not a User token with 2FA:

  • User tokens require OTP — CI can't provide it → EOTP error
  • Create Automation tokens at npmjs.com → Settings → Access Tokens → Automation
  • Verify before first publish in any workflow
Retry Logic for npm Registry Propagation

npm registry uses eventual consistency. After npm publish succeeds, the package may not be immediately queryable.

  • Propagation: typically 5-30s, up to 2min in rare cases
  • All verify steps: 5 attempts, 15-second intervals
  • Log each attempt: "Attempt 1/5: Checking package..."
  • Exit loop on success, fail after max attempts
yaml
- name: Verify package (with retry)
  run: |
    MAX_ATTEMPTS=5
    WAIT_SECONDS=15
    for attempt in $(seq 1 $MAX_ATTEMPTS); do
      echo "Attempt $attempt/$MAX_ATTEMPTS: Checking $PACKAGE@$VERSION..."
      if npm view "$PACKAGE@$VERSION" version > /dev/null 2>&1; then
        echo "✅ Package verified"
        exit 0
      fi
      [ $attempt -lt $MAX_ATTEMPTS ] && sleep $WAIT_SECONDS
    done
    echo "❌ Failed to verify after $MAX_ATTEMPTS attempts"
    exit 1
Draft Release Detection

Draft releases don't emit release: published event. Workflows MUST:

  • Trigger on release: published (NOT created)
  • If using workflow_dispatch: verify release is published via GitHub API before proceeding
Installer and Generated-Artifact Gates
  • Pin downloaded scripts and binaries to an immutable release or commit; never execute a moving branch reference.
  • Use curl -f (normally curl -fsSL) so HTTP failures cannot be interpreted as scripts.
  • Download to a named file before execution when practical, then remove it after a successful install. This leaves a diagnosable artifact if the installer fails.
  • Use set -euo pipefail in Bash steps. When a download must feed an extractor, pipefail prevents the extractor from masking a failed download.
  • Lint and validate canonical workflow sources and every committed generated/template mirror. A successful source-only check does not prove the artifact that executes is valid.
  • Keep suppressions narrow: exact tool diagnostic plus exact affected path, and revalidate them when the pinned tool changes.
Show full SKILL.md (155 more words)Show less

The root build invokes scripts/bump-build.mjs, which can mutate package versions. Local validation MUST set SKIP_BUILD_BUMP=1 (or use an existing CI environment that guarantees no mutation) and MUST verify the package manifests and lockfile are unchanged afterward. Prefer an affected workspace build when it covers the check. Never let a validation build rewrite package versions or create a version-only diff.

Known Failure Modes

#What HappenedRoot CausePrevention
14-part version published, npm mangled itNo semver validation gatenpx semver check before every publish
2CI failed 5+ times with EOTPUser token with 2FAAutomation token only
3Verify returned false 404No retry logic for propagation5 attempts, 15s intervals
4Workflow never triggeredDraft release doesn't emit eventNever create draft releases

Anti-Patterns

  • ❌ Publishing without semver validation gate
  • ❌ Single-shot verification without retry
  • ❌ Hard-coded secrets in workflows
  • ❌ Silent CI failures — every error needs actionable output with remediation
  • ❌ Assuming npm publish is instantly queryable

© bradygaster, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .copilot/skills/ci-validation-gates of bradygaster/squad.

Open the folder on GitHubat commit d2364df

Compare with similar skills

CI Validation Gates next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

CI Validation Gates compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
CI Validation Gates this skillbradygaster/squad3.3k—~1.1kAutomated safety check: PassMIT
CI Validation GatesFritzAndFriends/SharpSite1451 repos~911Automated safety check: PassMIT
Repo Hygiene Scan and FixQwenLM/qwen-code28k—~1.7kAutomated safety check: PassApache-2.0
Check Deps SyncHyk260/PureChat546—~594Automated safety check: PassMIT
npm Release Via GitHub Actionsjmfederico/pi-web861—~2.9kAutomated safety check: PassMIT
Publishcode-yeongyu/oh-my-openagent70k—~5.5kAutomated safety check: WarnCustom licence

Similar skills

  • CI Validation Gates

    FritzAndFriends/SharpSite

    Defensive CI/CD patterns: semver validation, token checks, retry logic, draft detection — earned from v0.8.22

    145 GitHub starsUsed in 1 repo~911 tokens
    DevOps & CloudAuto-check passed
  • Scheduled CI skill that scans a repository for small, certain docs, test and code hygiene issues and fixes them on one branch with a commit per finding.

    28k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Check Deps Sync

    Hyk260/PureChat

    Check if package.json files are in sync with pnpm-lock.yaml.

    546 GitHub stars~594 tokensUpdated 20 days ago
    DevOps & CloudAuto-check passed
  • A skill your agent uses whenever the user asks for a new npm version, npm release, package release, new release, version bump, publishing to npm, cutting a GitHub release, tagging a release, or…

    861 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Publish

    code-yeongyu/oh-my-openagent

    Publish oh-my-opencode to npm by triggering the GitHub Actions publish workflow and verifying its artifacts.

    70k GitHub stars~5.5k tokensUpdated today
    DevOps & CloudAuto-check: warnings
  • Release And CI

    eser/stack

    Releases and CI for eserstack: the shared version of all packages, the release command, the tag-driven build.yml run, JSR and npm publishing, changelog and breaking changes, release recovery, GitHub…

    128 GitHub stars~665 tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed

More from bradygaster/squad

All 31 skills in this repo
  • Fact Checking

    bradygaster/squad

    Review and validate claims using counter-hypothesis testing.

    3.3k GitHub stars~503 tokensUpdated yesterday
    Auto-check passed
  • Architectural Review

    bradygaster/squad

    How to review PRs for architectural quality — module boundaries, dependency direction, export surface, pattern consistency

    3.3k GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Archival Integrity

    bradygaster/squad

    Preserve content when moving entries between tracked Squad state files

    3.3k GitHub stars~735 tokensUpdated yesterday
    Auto-check passed
  • CLI Wiring

    bradygaster/squad

    Checklist and patterns for wiring new CLI commands into cli-entry.ts

    3.3k GitHub stars~501 tokensUpdated yesterday
    Auto-check passed
  • Enables squad agents on different machines to share work via git-based task queuing

    3.3k GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Gh Aw Reliability

    bradygaster/squad

    Validate GitHub Agentic Workflow contracts through compiled artifacts and realistic mutations

    3.3k GitHub stars~444 tokensUpdated yesterday
    Auto-check passed

Works with

Questions about CI Validation Gates

What does CI Validation Gates do?

Defensive CI/CD patterns: semver validation, token checks, retry logic, and draft detection. CI Validation Gates is an agent skill from bradygaster/squad.

When should I use CI Validation Gates?

CI Validation Gates fits situations like: tasks that involve Error handling; tasks that involve CI/CD.

How do I install CI Validation Gates in Claude Code?

Run `npx skills add bradygaster/squad --skill ci-validation-gates -a claude-code`. Or copy the skill folder (.copilot/skills/ci-validation-gates in bradygaster/squad) into .claude/skills/ci-validation-gates in your project. Claude Code loads it when a task matches its description.

How do I install CI Validation Gates in Codex?

Run `npx skills add bradygaster/squad --skill ci-validation-gates -a codex`. Or copy the skill folder (.copilot/skills/ci-validation-gates in bradygaster/squad) into .agents/skills/ci-validation-gates in your project. Codex loads it when a task matches its description.

Can I use CI Validation Gates in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bradygaster/squad --skill ci-validation-gates -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ci-validation-gates, .gemini/skills/ci-validation-gates, .github/skills/ci-validation-gates and .opencode/skills/ci-validation-gates in your project.

What does CI Validation Gates need to run?

Going by SKILL.md and its folder, CI Validation Gates needs the command-line tools its instructions call (npm, curl and npx) and credentials named NPM_TOKEN. Our summary lists: Node.js; A credential in NPM_TOKEN.

Does CI Validation Gates access the network?

SKILL.md contains no URLs. Its commands use npm, curl and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is CI Validation Gates safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does CI Validation Gates use?

CI Validation Gates is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does CI Validation Gates use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to CI Validation Gates?

Skills that share tags, products or a category with CI Validation Gates: CI Validation Gates (FritzAndFriends/SharpSite, 145 stars), Repo Hygiene Scan and Fix (QwenLM/qwen-code, 28k stars), Check Deps Sync (Hyk260/PureChat, 546 stars) and npm Release Via GitHub Actions (jmfederico/pi-web, 861 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains CI Validation Gates?

bradygaster (a GitHub user) maintains it in bradygaster/squad, which has 3,256 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 6, 2026.

Source: bradygaster/squad on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.