Agent skill

CI CD

by EliasOulkadi in EliasOulkadi/shokunin

Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary)…

MITAuto-check: notesDevOps & Cloud

Install CI CD

skills CLI
$ npx skills add EliasOulkadi/shokunin --skill ci-cd -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install EliasOulkadi/shokunin ci-cd --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/EliasOulkadi/shokunin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.pack/skills/ci-cd .claude/skills/ci-cd && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ci-cd
GitHub stars
114
Token cost
~3.4k tokens
SKILL.md length
1,217 words
Files
6 (incl. scripts, references, assets)
Skills in repo
49
Repo updated
First seen
Licence
MIT

At a glance

Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary)…

  • Works in 6 steps: Choose platform → Generate pipeline → Configure caching → …
  • User asks to set up CI/CD
  • SKILL.md covers Decision Framework, Workflow, Error Handling and Production Checklist, plus 8 more sections
  • Runs Shell scripts from its folder; calls terraform, npx and playwright; needs GITHUB_TOKEN

What it does

CI CD is an agent skill from EliasOulkadi/shokunin. Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary), auto-rollback, self-hosted runners, and environment protection with manual approvals. Use when user asks to set up CI/CD, write a pipeline, configure GitHub Actions/GitLab CI/CircleCI, automate deployments, or set up build/test/deploy workflows. Do NOT use for Dockerfile authoring (use docker), K8s manifests (use…

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts, reference files and assets (for example `assets/github-actions.ci.yml`, `assets/gitlab-ci.yml` and `references/deployment-strategies.md`). Compatibility notes: opencode

It sits in DevOps & Cloud, covering CI/CD and Deployment. It works with Docker, Kubernetes, GitLab and GitHub Actions. The repository describes itself as: 職人 Shokunin 62 AI agent skills for OpenCode, Claude Code, Cursor, Windsurf. ChromaDB memory, MCP servers, declarative self-updates. Multi-model, open source, zero cost. The licence is MIT.

When your agent uses it

  • User asks to set up CI/CD
  • Write a pipeline
  • Configure GitHub Actions/GitLab CI/CircleCI
  • Automate deployments

Example prompts

  • “/ci-cd”

Requirements

  • Python 3
  • Node.js
  • A Bash shell
  • Docker
  • A credential in GITHUB_TOKEN
  • Compatibility (from SKILL.md): opencode
  • Pre-approved tools (allowed-tools): Read, Bash, Write, Grep

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Choose platform
  2. Generate pipeline
  3. Configure caching
  4. Set up OIDC (no static secrets)
  5. Configure deployment strategy
  6. Set up self-hosted runners (if needed)

What it can do on your machine

Read from SKILL.md and the folder at commit 4c68e5b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash
    • Write
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • terraform
    • npx
    • playwright
    • pip
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    opencode

    From compatibility in the SKILL.md frontmatter.

Context cost

CI CD loads about 3.4k tokens when it runs, and up to ~8.8k if it reads all its reference files. Until then it costs about 142 tokens; SKILL.md has 1,217 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~142
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Bash, Write, Grep

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from EliasOulkadi/shokunin at commit 4c68e5b, republished under its MIT licence (© EliasOulkadi). 1,217 words, ~3,406 tokens.

Download SKILL.mdSave it as .claude/skills/ci-cd/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
ci-cd
description
Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary), auto-rollback, self-hosted runners, and environment protection with manual approvals. Use when user asks to set up CI/CD, write a pipeline, configure GitHub Actions/GitLab CI/CircleCI, automate deployments, or set up build/test/deploy workflows. Do NOT use for Dockerfile authoring (use docker), K8s manifests (use kubernetes), or Terraform config (use terraform).
allowed-tools
Read, Bash, Write, Grep
compatibility
opencode
triggers
CI/CD pipeline, GitHub Actions, GitLab CI, CircleCI, continuous integration, continuous deployment, build pipeline, deploy pipeline, automate build, automate…
negatives
Dockerfile, Terraform, Kubernetes manifest, infrastructure provisioning
license
MIT
metadata.workflow
infrastructure
metadata.audience
devops
metadata.version
3.0.0
metadata.author
shokunin

CI/CD Architect

Design fast, reliable, and secure CI/CD pipelines across GitHub Actions, GitLab CI, and CircleCI. Follows Google's DevOps capabilities and DORA metrics.

Decision Framework

Before building a CI/CD pipeline, answer:

  • Where is the code hosted? → If GitHub, start with GitHub Actions. If GitLab, use GitLab CI. On-prem? Consider self-hosted.
  • What's the deployment target? → Cloud (use OIDC), on-prem (use self-hosted runner), multi-cloud (use environment-specific jobs)
  • Is the team size 1-3? → Simple single-workflow. 10+? → Separate build, test, deploy workflows with artifact passing.
  • Do you need matrix builds (multiple OS/versions)? → Yes for libraries, no for single-platform apps.
  • Is the deploy target production? → Require manual approval gates. Non-prod: automatic on merge.

Workflow

Step 1: Choose platform
PlatformBest forConfig location
GitHub ActionsOSS, GitHub ecosystem.github/workflows/*.yml
GitLab CISelf-hosted, monorepos.gitlab-ci.yml
CircleCIPerformance, Docker.circleci/config.yml

Decision: If the project is on GitHub.com, use GitHub Actions. If self-hosted GitLab, use GitLab CI. If maximum performance needed, use CircleCI.

Step 2: Generate pipeline

Use the scaffold script with your platform and stack:

bash
scripts/generate-pipeline.sh --platform github --language node --e2e --docker
scripts/generate-pipeline.sh --platform gitlab --language python --docker
scripts/generate-pipeline.sh --platform circle --language go --e2e

This generates a production-ready pipeline with:

  • Lint → typecheck → test (sharded) → build → docker → deploy
  • Caching (npm/pip/go, Docker layers)
  • OIDC auth (no static secrets)
  • Environment gates (staging → production)
Step 3: Configure caching
Cache typeGitHub ActionsGitLab CICircleCI
npm/pip/goactions/cache with lockfile hashcache:key: with lockfile hashsave_cache / restore_cache
Docker layersdocker/build-push-action GHA cacheDocker layer caching on self-hostedRemote Docker engine cache
Playwright browsersnpx playwright install chromiumbefore_script cacheCustom Docker image with browsers
Build artifactsupload-artifact / download-artifactartifacts: sectionpersist_to_workspace

If the build is consistently >15 min: add more shards or parallelize independent jobs.

Test sharding
yaml
# GitHub Actions: split tests across N parallel runners
strategy:
  matrix:
    shard: [1, 2, 3, 4]
steps:
  - run: npx vitest --shard=${{ matrix.shard }}/${{ strategy.job-total }}

In GitLab CI, use the parallel: key: parallel: 4 and CI_NODE_INDEX / CI_NODE_TOTAL env vars.

Decision: Use sharding when test suite >5 min. Start with 2 shards, increase until each shard runs in <3 min. For Playwright, shard by spec file weight with playwright test --shard=$CI_NODE_INDEX/$CI_NODE_TOTAL.

Monorepo strategies
PatternTrigger ruleCache key
Path-basedpaths: ['packages/web/**'] (GHA) / rules:changes: (GitLab)${{ hashFiles('packages/web/package-lock.json') }}
Label-basedif: contains(github.event.pull_request.labels.*.name, 'web')Per-package cache restore
Full rebuildMonorepo tools (Nx, Turborepo) use their own remote cachingN/A — tool-managed

For large monorepos, use Nx or Turborepo for task orchestration. Let the tool handle --since, affected projects, and remote cache. Reference the tool's CI recipe — don't hand-roll matrix logic when the tool already solves it.

Environment protection rules
yaml
# GitHub Actions — manual approval gate before production
deploy-prod:
  needs: [deploy-staging]
  environment:
    name: production
    # Enforces: required reviewers, wait timer, restricted branches, deployment history
  steps: [...]
  • Required reviewers: Minimum 2 for production, 1 for staging
  • Wait timer: Force 5-minute buffer before deploy (catch last-minute reverts)
  • Deployment branches: Only main or release/* can trigger production
  • Auto-inactive: Mark deployments inactive after 30 days, prevent stale environment clutter
  • GitLab equivalent: environment: production with deploy: free or protected environments
  • CircleCI equivalent: approval job type with restricted contexts
Secret rotation

Never store long-lived secrets in CI/CD. Prefer:

  1. OIDC (preferred): No secrets at all — federated identity with short-lived tokens
  2. Short-lived credentials: Clouds offer 1-hour max tokens via OIDC
  3. Secret rotation schedule: Rotate all static secrets every 90 days, documented in playbook
  4. CI/CD secret scanning: Enable GitHub secret scanning push protection or GitLab secret detection

For legacy systems requiring static secrets, store them only in the CI/CD platform's encrypted variables (not in repo), audit access via audit logs, and set expiration reminders via automation.

Step 4: Set up OIDC (no static secrets)
yaml
# GitHub Actions
permissions:
  id-token: write
  contents: read
steps:
  - uses: aws-actions/configure-aws-credentials@v4
    with:
      role-to-assume: arn:aws:iam::123456:role/github-actions
      aws-region: us-east-1
Step 5: Configure deployment strategy

See references/deployment-strategies.md for full details.

StrategyRollbackUse when
Rolling updateManual (undo)Stateless apps
Blue-greenInstant (LB switch)Zero-downtime required
CanaryGradual (traffic % adjust)High-risk, gradual rollout

Always implement healthcheck verification after deploy:

yaml
- name: Healthcheck
  run: |
    for i in {1..30}; do
      STATUS=$(curl -so /dev/null -w '%{http_code}' https://app.example.com/health)
      if [ "$STATUS" = "200" ]; then exit 0; fi
      sleep 2
    done
    echo "Healthcheck failed, rolling back..."
    kubectl rollout undo deployment/app
    exit 1
Step 6: Set up self-hosted runners (if needed)

See references/self-hosted-runners.md for K8s runners, autoscaling, caching, and security configurations.

Decision: Use GitHub-hosted runners for standard builds. Self-hosted if you need:

  • Custom hardware (GPU, large memory)
  • Docker-in-Docker performance
  • Private network access

Error Handling

ErrorCauseFix
Resource not accessible by integrationMissing permissions: block in GHA workflowAdd permissions: contents: read, id-token: write at job or workflow level
fatal: unable to access ... The requested URL returned error: 403Expired or missing git credentialsUse actions/checkout with token: ${{ secrets.GITHUB_TOKEN }} or deploy key
Error response from daemon: manifest for ... not foundDocker image tag doesn't exist in registryVerify tag was built and pushed; check registry path matches exactly
Job failed: runner disconnectedSelf-hosted runner crashed or network flakedAdd timeout-minutes per job, configure runner auto-restart, use spot instance rebalancing
No space left on deviceBuild artifacts filling runner diskAdd cleanup step: rm -rf /tmp/* or use actions/upload-artifact with retention; reduce Docker image size
deploy job requires a unique deployment_idConcurrent deploys to same environmentAdd concurrency: group: ${{ github.workflow }}-${{ github.ref }} to prevent race conditions
Cache not found (restore) / Cache already exists (save)Cache key mismatch or cache hit on locked keyUse restore-keys fallback for partial matches; include hashFiles('lockfile') in primary key
OIDC token fetch failedMissing id-token: write permission or IAM trust relationship misconfiguredVerify IAM trust policy allows token.actions.githubusercontent.com + correct repo/subject claim
Show full SKILL.md (411 more words)Show less

Production Checklist

  • Lint + typecheck before tests
  • Tests parallelized (matrix/sharding)
  • Build artifacts cached or uploaded
  • Docker build uses layer caching
  • Plan/apply separation for IaC
  • Production deployment requires manual approval
  • Concurrency prevents simultaneous deploys
  • OIDC auth (no static cloud keys)
  • Rollback tested and documented
  • Notifications on failure (Slack/Discord/email)
  • Build time under 15 min

Anti-Patterns

Anti-patternFix
terraform apply from laptopCI/CD with plan/apply separation
Deploying from latest tagUse commit SHA or semver
No cacheCache deps, Docker layers, artifacts
Sequential testsParallel matrix or sharding
Static cloud creds in secretsOIDC or short-lived tokens
Secrets in pipeline YAMLCI/CD secret variables
Monolithic jobSplit: lint → test → build → deploy
No healthcheck after deployAuto-rollback on failure
Deploy on every main pushGated approval + environment protection

Pipeline Review Format (Required)

When reviewing CI/CD pipelines, use Before | After | Why format:

BeforeAfterWhy
Static cloud credentials in secretsOIDC with id-token: write permissionStatic credentials never expire. OIDC issues short-lived tokens per workflow run.
Sequential test jobsMatrix build + test sharding (strategy: matrix: shard: [1/4, 2/4, 3/4, 4/4])Sequential tests bottleneck the pipeline. Sharding parallelizes across runners.
terraform apply from laptopCI plan → manual approval → CI applyLaptop applies bypass audit trail and state locking. CI enforces process.
No cache on dependenciesactions/cache for node_modules/, pip cache, go mod cacheUncached dependencies add 2-5 minutes per run. Caching cuts this to seconds.

Matrix Build Optimization

yaml
# GitHub Actions: parallel test shards
strategy:
  matrix:
    shard: [1, 2, 3, 4]
steps:
  - run: npx vitest --shard=${{ matrix.shard }}/${{ strategy.job-total }}

# Parallel OS/version testing
strategy:
  matrix:
    os: [ubuntu-latest, windows-latest]
    node: [18, 20, 22]

Canary Deployment with Flagger

yaml
# Canary resource (Flagger CRD)
apiVersion: flagger.app/v1beta1
kind: Canary
spec:
  service: myapp
  analysis:
    interval: 30s; threshold: 5; maxWeight: 50; stepWeight: 10
    metrics:
    - name: request-success-rate; threshold: 99
    - name: request-duration; threshold: 500

Flow: deploy canary (10% traffic) → analyze metrics → if healthy, increase to 20%, 30%, 50% → promote to 100%.

Pipeline Approval Gates

yaml
# GitHub Environments with protection rules
deploy-prod:
  needs: deploy-staging
  environment: production
  steps: [ - run: ./deploy.sh ]

# Environment settings (GitHub UI):
# - Required reviewers: 2
# - Wait timer: 0 minutes
# - Deployment branches: main only

Sources

  • GitHub Actions docs (docs.github.com/actions)
  • GitLab CI docs (docs.gitlab.com/ee/ci)
  • CircleCI docs (circleci.com/docs)
  • DORA metrics (Google Cloud DevOps)
  • Docker BuildKit cache type
  • AWS IAM OIDC identity providers
  • Flagger documentation (flagger.app)

Pre-Deploy Checklist

Before merging to production:

  • All tests pass (unit, integration, E2E)
  • Security scan passes (no HIGH/CRITICAL vulnerabilities)
  • Lint and type checks pass with zero errors
  • Build artifact produced and validated
  • Deploy plan reviewed (IaC plan output, migration plan)
  • Rollback plan documented and tested
  • Environment protection rules active (require approvals for production)
  • Concurrency control enabled (prevent simultaneous deploys)
  • Healthcheck endpoint verified post-deploy
  • Monitoring alerts configured for the new version
  • Database migrations tested with a copy of production data

Checklist

  • Skill loads without errors in the AI agent
  • YAML frontmatter is valid (description, compatibility, audience)
  • Workflow section provides clear step-by-step instructions
  • Error handling section covers common failure modes
  • All referenced files (references/, scripts/, assets/) exist
  • Skill triggers correctly for intended use cases
  • No broken links or missing resources

© EliasOulkadi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references, assets) in .pack/skills/ci-cd of EliasOulkadi/shokunin.

  • SKILL.md
  • assets/github-actions.ci.yml
  • assets/gitlab-ci.yml
  • references/deployment-strategies.md
  • references/self-hosted-runners.md
  • scripts/generate-pipeline.sh

Open the folder on GitHubat commit 4c68e5b

Compare with similar skills

CI CD next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

CI CD compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
CI CD this skillEliasOulkadi/shokunin114—~3.4kAutomated safety check: NotesMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
CI/CD Pipeline Principlesirahardianto/awesome-agv156—~2.7kAutomated safety check: NotesMIT
Devops Excellencemajiayu000/spellbook287—~2.4kAutomated safety check: NotesMIT
Devops Deploymentyonatangross/orchestkit292—~2.7kAutomated safety check: PassMIT
Devops EngineerYikai-Liao/symusic1891 repos~1.5kAutomated safety check: PassMIT

Similar skills

  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • CI/CD Pipeline Principles

    irahardianto/awesome-agv

    Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

    156 GitHub stars~2.7k tokensUpdated 6 days ago
    DevOps & CloudAuto-check: notes
  • Devops Excellence

    majiayu000/spellbook

    DevOps and CI/CD expert. An agent skill from majiayu000/spellbook.

    287 GitHub stars~2.4k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Devops Deployment

    yonatangross/orchestkit

    A skill your agent uses when setting up CI/CD pipelines, containerizing applications, deploying to Kubernetes, or writing infrastructure as code.

    292 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Devops Engineer

    Yikai-Liao/symusic

    Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates.

    189 GitHub starsUsed in 1 repo~1.5k tokens
    DevOps & CloudAuto-check passed
  • DevOps助手 - 专业的DevOps实践与自动化专家。适用场景: (1) CI/CD流水线设计与实现 (2) 部署策略与发布管理 (3) 基础设施即代码(IaC) (4) 容器化与Kubernetes部署 (5) 监控告警与可观测性 (6) DevOps工具链选型 (7) DevOps文化与实践推广 触发关键词:DevOps、CI/CD、持续集成、持续部署、Jenkins、GitLab…

    126 GitHub stars~1.4k tokensUpdated 8 mo ago
    DevOps & CloudAuto-check passed

More from EliasOulkadi/shokunin

All 49 skills in this repo
  • Component Forge

    EliasOulkadi/shokunin

    Build production-grade components for React, Vue 3, and Svelte 5 with all states (loading, empty, error, success, idle), TypeScript strict, WCAG 2.2 accessibility, server components (RSC), and…

    114 GitHub stars~3.6k tokensUpdated 6 days ago
    Auto-check: notes
  • DB Admin

    EliasOulkadi/shokunin

    PostgreSQL database administration — backup/restore (pgdump, PITR, WAL archiving), health monitoring (connections, bloat, cache hit ratio, dead tuples), connection pooling (PgBouncer), replication…

    114 GitHub stars~2k tokensUpdated 6 days ago
    Auto-check: notes
  • DB Sculptor

    EliasOulkadi/shokunin

    Design database schemas with Prisma/Drizzle, PostgreSQL index strategy (B-tree, GIN, GiST, BRIN, Hash), query optimization (EXPLAIN ANALYZE), migration safety (expand/contract, zero-downtime), and…

    114 GitHub stars~3.1k tokensUpdated 6 days ago
    Auto-check: notes
  • Docker

    EliasOulkadi/shokunin

    Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and…

    114 GitHub stars~3.8k tokensUpdated 6 days ago
    Auto-check: notes
  • Error Handler

    EliasOulkadi/shokunin

    Design error handling, structured logging, and observability with OpenTelemetry (traces, metrics, logs), error classification, recovery patterns (retry with jitter, circuit breaker, bulkhead…

    114 GitHub stars~3.6k tokensUpdated 6 days ago
    Auto-check: notes
  • Kubernetes

    EliasOulkadi/shokunin

    Deploy, manage, and debug Kubernetes in production — Deployments, Services, Gateway API, Service Mesh (Istio/Linkerd/Cilium), eBPF observability (Cilium Hubble), security hardening (Pod Security…

    114 GitHub stars~3.3k tokensUpdated 6 days ago
    Auto-check: notes

Categories

Questions about CI CD

What does CI CD do?

Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary)…. CI CD is an agent skill from EliasOulkadi/shokunin. Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary), auto-rollback, self-hosted runners, and environment protection with manual approvals.

When should I use CI CD?

CI CD fits situations like: user asks to set up CI/CD; write a pipeline; configure GitHub Actions/GitLab CI/CircleCI; automate deployments.

How do I install CI CD in Claude Code?

Run `npx skills add EliasOulkadi/shokunin --skill ci-cd -a claude-code`. Or copy the skill folder (.pack/skills/ci-cd in EliasOulkadi/shokunin) into .claude/skills/ci-cd in your project. Claude Code loads it when a task matches its description.

How do I install CI CD in Codex?

Run `npx skills add EliasOulkadi/shokunin --skill ci-cd -a codex`. Or copy the skill folder (.pack/skills/ci-cd in EliasOulkadi/shokunin) into .agents/skills/ci-cd in your project. Codex loads it when a task matches its description.

Can I use CI CD in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EliasOulkadi/shokunin --skill ci-cd -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ci-cd, .gemini/skills/ci-cd, .github/skills/ci-cd and .opencode/skills/ci-cd in your project.

What does CI CD need to run?

Going by SKILL.md and its folder, CI CD needs a shell for the scripts in its folder, the command-line tools its instructions call (terraform, npx, playwright, pip and go) and credentials named GITHUB_TOKEN. Our summary lists: Python 3; Node.js; A Bash shell; Docker; A credential in GITHUB_TOKEN. Its frontmatter pre-approves these tools: Read, Bash, Write, Grep. Compatibility (from SKILL.md): opencode.

Does CI CD access the network?

SKILL.md contains no URLs. Its commands use npx and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is CI CD safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does CI CD use?

CI CD is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does CI CD use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.4k tokens, read only when the agent opens those files.

What are the alternatives to CI CD?

Skills that share tags, products or a category with CI CD: Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), CI/CD Pipeline Principles (irahardianto/awesome-agv, 156 stars), Devops Excellence (majiayu000/spellbook, 287 stars) and Devops Deployment (yonatangross/orchestkit, 292 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains CI CD?

EliasOulkadi (a GitHub user) maintains it in EliasOulkadi/shokunin, which has 114 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 5, 2026.

Source: EliasOulkadi/shokunin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.