Official agent skill

Authoring GitHub Workflows

by dotnet in dotnet/skills

Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run.

OfficialMITAuto-check passedDevOps & Cloud

Install Authoring GitHub Workflows

skills CLI
$ npx skills add dotnet/skills --skill authoring-github-workflows -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dotnet/skills authoring-github-workflows --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/authoring-github-workflows .claude/skills/authoring-github-workflows && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
authoring-github-workflows
GitHub stars
5.6k
Used in
1 other repo
Token cost
~2.3k tokens
SKILL.md length
890 words
Files
1
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run.

  • Works in 5 steps: Identify the changed/authored workflow… → Quote risky expression scalars → Validate with actionlint (authoritative) → …
  • Reviewing any file under .github/workflows/
  • SKILL.md covers When to Use, When Not to Use, The #1 Trap: # inside an… and Other characters that force…, plus 4 more sections
  • Calls actionlint, git and curl; reaches github.com

What it does

Authoring GitHub Workflows is an agent skill from dotnet/skills, published by the product's own GitHub organization. Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run. USE FOR: editing, adding, or reviewing any file under .github/workflows/, writing run-name/name/if/env/run values that contain ${{ }} expressions, diagnosing a run that fails with 'This run likely failed because of a workflow file issue' and no jobs starting, deciding when a workflow scalar must be quoted, validating workflows with actionlint. DO NOT USE FOR: authoring…

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering CI/CD. It works with GitHub Actions, GitHub, Azure DevOps and GitLab. The repository describes itself as: Repository for skills to assist AI coding agents with .NET and C. The licence is MIT.

When your agent uses it

  • Reviewing any file under .github/workflows/
  • Writing run-name/name/if/env/run values that contain ${{ }} expressions
  • Diagnosing a run that fails with This run likely failed because of a workflow file issue and no jobs starting
  • Deciding when a workflow scalar must be quoted

Example prompts

  • “This run likely failed because of a workflow file issue”
  • “/authoring-github-workflows”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Identify the changed/authored workflow files
  2. Quote risky expression scalars
  3. Validate with actionlint (authoritative)
  4. Confirm a YAML-only check is not enough
  5. Keep the CI gate green

What it can do on your machine

Read from SKILL.md and the folder at commit 8d670fa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • actionlint
    • git
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • docs.github.com
    • yaml.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Authoring GitHub Workflows loads about 2.3k tokens when it runs. Until then it costs about 249 tokens; SKILL.md has 890 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~249
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dotnet/skills at commit 8d670fa, republished under its MIT licence (© dotnet). 890 words, ~2,258 tokens.

Download SKILL.mdSave it as .claude/skills/authoring-github-workflows/SKILL.md (or your agent's skills folder).
name
authoring-github-workflows
description
Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run. USE FOR: editing, adding, or reviewing any file under .github/workflows/, writing run-name/name/if/env/run values that contain ${{ }} expressions, diagnosing a run that fails with 'This run likely failed because of a workflow file issue' and no jobs starting, deciding when a workflow scalar must be quoted, validating workflows with actionlint. DO NOT USE FOR: authoring application YAML unrelated to GitHub Actions, Azure Pipelines, GitLab CI, or non-workflow YAML. SCOPE: this skill covers *syntactic/structural* correctness of workflow YAML (quoting, parsing, actionlint); for *semantic and functional* workflow design (what a workflow should do, agentic-workflow behavior), see .github/agents/agentic-workflows.agent.md — the two are complementary. INVOKES: actionlint (downloaded pinned binary) plus git/grep for inspection.
license
MIT

Authoring GitHub Actions Workflows Safely

GitHub Actions workflow files are YAML, but valid YAML is not the same as a valid workflow. A workflow can parse cleanly with yaml.safe_load (or a casual review) yet still be rejected by GitHub Actions at load time — producing the opaque failure "This run likely failed because of a workflow file issue" with zero jobs started. This skill teaches the YAML-vs-Actions traps (the #-as-comment trap above all), how to quote expression scalars correctly, and how to validate with actionlint before merge.

Scope: syntactic vs. semantic. This skill is about the syntactic and structural correctness of workflow YAML — quoting, parsing, and actionlint-level validity that determines whether GitHub Actions will load and run a file at all. It is not about what a workflow should do or how an agentic workflow should behave. For semantic and functional guidance (designing workflow logic, agentic-workflow patterns, gh-aw authoring), use .github/agents/agentic-workflows.agent.md. The two are complementary: get the behavior right with the agent, get the YAML right with this skill.

When to Use

  • Editing, adding, or reviewing any file under .github/workflows/.
  • Writing a run-name, name, if, env, with, or run value that embeds a ${{ }} expression.
  • A workflow run failed with "This run likely failed because of a workflow file issue" and no jobs ran.
  • Eval/CI on main suddenly breaks for every run after a workflow edit merged, even though the change "looked fine."
  • Deciding whether a YAML scalar needs quoting.

When Not to Use

  • Authoring non-Actions YAML (app config, Kubernetes, Compose, Azure Pipelines, GitLab CI).
  • Pure shell/script logic inside an already-valid run: block (that is a scripting task, not a workflow-syntax task).

The #1 Trap: # inside an unquoted expression becomes a YAML comment

In YAML, a space followed by # starts a comment. In an unquoted (plain) scalar, everything from that space-then-# to end-of-line is silently discarded:

yaml
# BAD — the run-name is silently truncated at " #"
run-name: ${{ inputs.pr_number != '' && format('Evaluate PR #{0} @ {1}', inputs.pr_number, inputs.head_sha) || '' }}

YAML parses this as run-name: ${{ inputs.pr_number != '' && format('Evaluate PR — an unterminated ${{ expression. yaml.safe_load succeeds (it just sees a truncated string with a trailing comment), so the bug passes naive validation, but GitHub Actions rejects the malformed expression and refuses to start any run.

yaml
# GOOD — wrap the whole value in double quotes so '#' stays inside the scalar
run-name: "${{ inputs.pr_number != '' && format('Evaluate PR #{0} @ {1}', inputs.pr_number, inputs.head_sha) || '' }}"

The inner expression already uses single quotes, so double-quoting the scalar is safe. This is exactly the bug that broke dotnet/skills evaluation on main (PR #746 → fixed by quoting).

Other characters that force quoting in a plain scalar

Character / patternWhy it breaksFix
space then # (space-hash)Starts a YAML comment; truncates the valueQuote the whole value
Leading *, &, !, ?, |, >, @, `YAML anchors/aliases/tags/block scalarsQuote the value
Leading { or [Parsed as flow mapping/sequence (a bare ${{ }} starts with $, which is safe, but {{ after a leading char is risky)Quote the value
: then space (colon-space) inside the valueParsed as a nested mapping keyQuote the value
Leading/trailing spaces that matterPlain scalars strip themQuote the value
Values that are true/false/yes/no/on/off/numbers but must stay stringsYAML type coercionQuote the value

Rule of thumb: if a name, run-name, if, env, or with value contains a ${{ }} expression and any literal #, :, or leading special character, wrap the entire scalar in double quotes.

Workflow

Step 1: Identify the changed/authored workflow files
bash
git diff --name-only origin/main... -- .github/workflows/

For each file, scan every line that contains ${{ together with a #, a colon-space, or a leading special character.

Show full SKILL.md (361 more words)Show less
Step 2: Quote risky expression scalars

Wrap the full value in double quotes when the value embeds an expression and contains a # or other special character (see the table above). Prefer double quotes when the inner expression uses single quotes, and vice-versa. Do not escape the ${{ }} braces — quoting the scalar is enough.

Step 3: Validate with actionlint (authoritative)

actionlint understands the GitHub Actions schema and the expression grammar, so it catches exactly this class of bug that plain YAML linters miss. Download a pinned release and run it:

bash
ACTIONLINT_VERSION=1.7.7
ACTIONLINT_SHA256=023070a287cd8cccd71515fedc843f1985bf96c436b7effaecce67290e7e0757
curl -fsSLo actionlint.tar.gz \
  "https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz"
# Verify the download against the pinned checksum before extracting/executing it:
echo "${ACTIONLINT_SHA256}  actionlint.tar.gz" | sha256sum -c -
tar -xzf actionlint.tar.gz actionlint
# Focus on workflow/expression correctness; silence shell/py style noise:
./actionlint -shellcheck= -pyflakes= -color .github/workflows/*.yml

On Windows PowerShell, use the actionlint_<ver>_windows_amd64.zip asset and Expand-Archive.

The truncated-expression bug surfaces as:

got unexpected EOF while lexing end of string literal, expecting ''' [expression]

A clean exit code 0 means the workflows are structurally valid.

Step 4: Confirm a YAML-only check is not enough

Do not rely on yaml.safe_load, yamllint, or "it parses" as proof. They accept the truncated-comment form. Only actionlint (or pushing and watching GitHub Actions parse it) validates the Actions layer.

Step 5: Keep the CI gate green

This repository runs actionlint automatically (see .github/workflows/actionlint.yml) on any PR that touches .github/workflows/. Ensure your change passes that check before requesting review. If you add a new workflow, the gate covers it automatically.

Validation

  • Every ${{ }} value containing #, a colon-space, or a leading special character is wrapped in quotes.
  • actionlint -shellcheck= -pyflakes= .github/workflows/*.yml exits 0.
  • No workflow run reports "This run likely failed because of a workflow file issue".
  • The actionlint CI check is green on the PR.

Common Pitfalls

PitfallSolution
Unquoted run-name/name with # inside the expressionWrap the whole value in double quotes
Trusting yaml.safe_load/yamllint/a code review to catch itRun actionlint; YAML-only checks accept the truncated form
Escaping ${{ braces to "fix" itDon't — quote the scalar instead; escaping breaks the expression
Using single quotes around a value that contains single quotesUse double quotes for the outer scalar
Adding actionlint with shellcheck enabled and drowning in pre-existing shell-style warningsRun with -shellcheck= -pyflakes= to focus on workflow/expression errors
Assuming a green YAML lint means the workflow will runPush and confirm jobs actually start, or rely on the actionlint gate

References

© dotnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/authoring-github-workflows of dotnet/skills.

Open the folder on GitHubat commit 8d670fa

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in dotnet/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Authoring GitHub Workflows next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Authoring GitHub Workflows compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Authoring GitHub Workflows this skilldotnet/skills5.6k1 repos~2.3kAutomated safety check: PassMIT
Migrate To TeamcityJetBrains/teamcity-cli125—~1.3kAutomated safety check: PassApache-2.0
Appbuilder Cicd PipelineNeverSight/learn-skills.dev2161 repos~1.8kAutomated safety check: NotesApache-2.0
ONNX Runtime CI Managementmicrosoft/onnxruntime22k—~4.1kAutomated safety check: PassMIT
Megalinter Checknvuillam/npm-groovy-lint2481 repos~3.9kAutomated safety check: NotesMIT
CI CDEliasOulkadi/shokunin114—~3.4kAutomated safety check: NotesMIT

Similar skills

  • Migrate To Teamcity

    JetBrains/teamcity-cli

    Official

    Migrating CI/CD pipelines to TeamCity. An agent skill from JetBrains/teamcity-cli.

    125 GitHub stars~1.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Appbuilder Cicd Pipeline

    NeverSight/learn-skills.dev

    Set up CI/CD pipelines for Adobe App Builder projects. An agent skill from NeverSight/learn-skills.dev.

    216 GitHub starsUsed in 1 repo~1.8k tokens
    DevOps & CloudAuto-check: notes
  • ONNX Runtime CI Management

    microsoft/onnxruntime

    Official

    Triggers, re-runs and unblocks the CI checks on an ONNX Runtime pull request, after diagnosing whether a failure is transient or needs a code change.

    22k GitHub stars~4.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Megalinter Check

    nvuillam/npm-groovy-lint

    Collect MegaLinter lint errors for the current repository. An agent skill from nvuillam/npm-groovy-lint.

    248 GitHub starsUsed in 1 repo~3.9k tokens
    DevOps & CloudAuto-check: notes
  • CI CD

    EliasOulkadi/shokunin

    Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary)…

    114 GitHub stars~3.4k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Tirith Policies

    StackGuardian/tirith

    Write, validate, run and debug Tirith IaC governance policies, install Tirith, and add it to a CI pipeline (GitHub Actions, GitLab CI, Bitbucket Pipelines, Jenkins, Azure DevOps, CircleCI or any…

    167 GitHub stars~1.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from dotnet/skills

All 91 skills in this repo
  • Official

    Resolves .NET runtime frames in Apple .ips crash logs to function names, source files and line numbers using dSYM symbols, atos and the Microsoft symbol server.

    5.6k GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed
  • Official

    Resolves native crash frames from .NET Android tombstones to function names, source files and line numbers using BuildIds, Microsoft's symbol server and llvm-symbolizer.

    5.6k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Official

    Scans C# and .NET code for about 50 performance anti-patterns and reports prioritized findings with concrete fixes, at a scan depth you choose.

    5.6k GitHub starsUsed in 3 repos~3.1k tokens
    Auto-check passed
  • Official

    Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build.

    5.6k GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Microbenchmarking

    dotnet/skills

    Official

    Activate this skill when BenchmarkDotNet (BDN) is involved in the task — creating, running, configuring, or reviewing BDN benchmarks.

    5.6k GitHub starsUsed in 3 repos~3.3k tokens
    Auto-check passed
  • Official

    Makes .NET projects compatible with Native AOT and trimming by resolving IL trim and AOT analyzer warnings through annotations rather than suppressions.

    5.6k GitHub starsUsed in 2 repos~4.2k tokens
    Auto-check passed

Categories

Questions about Authoring GitHub Workflows

What does Authoring GitHub Workflows do?

Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run. Authoring GitHub Workflows is an agent skill from dotnet/skills, published by the product's own GitHub organization. Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run.

When should I use Authoring GitHub Workflows?

Authoring GitHub Workflows fits situations like: reviewing any file under .github/workflows/; writing run-name/name/if/env/run values that contain ${{ }} expressions; diagnosing a run that fails with This run likely failed because of a workflow file issue and no jobs starting; deciding when a workflow scalar must be quoted.

How do I install Authoring GitHub Workflows in Claude Code?

Run `npx skills add dotnet/skills --skill authoring-github-workflows -a claude-code`. Or copy the skill folder (.agents/skills/authoring-github-workflows in dotnet/skills) into .claude/skills/authoring-github-workflows in your project. Claude Code loads it when a task matches its description.

How do I install Authoring GitHub Workflows in Codex?

Run `npx skills add dotnet/skills --skill authoring-github-workflows -a codex`. Or copy the skill folder (.agents/skills/authoring-github-workflows in dotnet/skills) into .agents/skills/authoring-github-workflows in your project. Codex loads it when a task matches its description.

Can I use Authoring GitHub Workflows in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dotnet/skills --skill authoring-github-workflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/authoring-github-workflows, .gemini/skills/authoring-github-workflows, .github/skills/authoring-github-workflows and .opencode/skills/authoring-github-workflows in your project.

What does Authoring GitHub Workflows need to run?

Going by SKILL.md and its folder, Authoring GitHub Workflows needs the command-line tools its instructions call (actionlint, git and curl).

Does Authoring GitHub Workflows access the network?

SKILL.md names 3 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: docs.github.com and yaml.org. This is read from the text; nothing was executed.

Is Authoring GitHub Workflows safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Authoring GitHub Workflows use?

Authoring GitHub Workflows is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Authoring GitHub Workflows use?

About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Authoring GitHub Workflows?

Skills that share tags, products or a category with Authoring GitHub Workflows: Migrate To Teamcity (JetBrains/teamcity-cli, 125 stars), Appbuilder Cicd Pipeline (NeverSight/learn-skills.dev, 216 stars), ONNX Runtime CI Management (microsoft/onnxruntime, 22k stars) and Megalinter Check (nvuillam/npm-groovy-lint, 248 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Authoring GitHub Workflows?

dotnet (a GitHub organization, an official publisher) maintains it in dotnet/skills, which has 5,568 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 7, 2026.

Source: dotnet/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.