Agent skill

GitHub Actions Creator

by FNOSP in FNOSP/FlyNarwhal

A skill your agent uses when the user wants to create, generate, or set up a GitHub Actions workflow.

AGPL-3.0Auto-check passedDevOps & Cloud

Install GitHub Actions Creator

skills CLI
$ npx skills add FNOSP/FlyNarwhal --skill github-actions-creator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install FNOSP/FlyNarwhal github-actions-creator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/FNOSP/FlyNarwhal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/github-actions-creator .claude/skills/github-actions-creator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
github-actions-creator
GitHub stars
495
Used in
1 other repo
Token cost
~2.4k tokens
SKILL.md length
744 words
Files
2 (incl. references)
Skills in repo
8
Repo updated
First seen
Licence
AGPL-3.0

At a glance

A skill your agent uses when the user wants to create, generate, or set up a GitHub Actions workflow.

  • Works in 3 steps: Analyze the Project → Ask Clarifying Questions (if needed) → Generate the Workflow
  • The user wants to create
  • SKILL.md covers Workflow Creation Process, Core Patterns by Use Case, Essential Actions Reference and Security Best Practices…, plus 4 more sections
  • Needs GITHUB_TOKEN

What it does

GitHub Actions Creator is an agent skill from FNOSP/FlyNarwhal. Use when the user wants to create, generate, or set up a GitHub Actions workflow. Handles CI/CD pipelines, testing, deployment, linting, security scanning, release automation, Docker builds, scheduled tasks, and any custom workflow for any language or framework.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/workflow-templates.md`).

It sits in DevOps & Cloud, covering CI/CD, Linting and formatting and Scheduled and recurring tasks. It works with GitHub Actions, Docker, Rust and Node.js. The repository describes itself as: 基于 Flutter 框架开发的适用于飞牛影视的跨平台客户端. The licence is AGPL-3.0.

When your agent uses it

  • The user wants to create
  • Set up a GitHub Actions workflow

Example prompts

  • “/github-actions-creator”

Requirements

  • Python 3
  • Node.js
  • Docker
  • A credential in GITHUB_TOKEN

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Analyze the Project
  2. Ask Clarifying Questions (if needed)
  3. Generate the Workflow

What it can do on your machine

Read from SKILL.md and the folder at commit c94d847. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GitHub Actions Creator loads about 2.4k tokens when it runs, and up to ~6.9k if it reads all its reference files. Until then it costs about 71 tokens; SKILL.md has 744 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from FNOSP/FlyNarwhal at commit c94d847, republished under its AGPL-3.0 licence (© FNOSP). 744 words, ~2,382 tokens.

Download SKILL.mdSave it as .claude/skills/github-actions-creator/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
github-actions-creator
description
Use when the user wants to create, generate, or set up a GitHub Actions workflow. Handles CI/CD pipelines, testing, deployment, linting, security scanning, release automation, Docker builds, scheduled tasks, and any custom workflow for any language or framework.

GitHub Actions Creator

You are an expert at creating GitHub Actions workflows. When the user asks you to create a GitHub Action, follow this structured process to deliver a production-ready workflow file.

Workflow Creation Process

Step 1: Analyze the Project

Before writing any YAML, scan the project to understand the stack:

  1. Check for language/framework indicators:

    • package.json → Node.js (check for React, Next.js, Vue, Angular, Svelte, etc.)
    • requirements.txt / pyproject.toml / setup.py → Python
    • go.mod → Go
    • Cargo.toml → Rust
    • pom.xml / build.gradle → Java/Kotlin
    • Gemfile → Ruby
    • composer.json → PHP
    • pubspec.yaml → Dart/Flutter
    • Package.swift → Swift
    • *.csproj / *.sln → .NET
  2. Check for existing CI/CD:

    • .github/workflows/ → existing workflows (avoid conflicts)
    • Dockerfile → container builds available
    • docker-compose.yml → multi-service setup
    • vercel.json / netlify.toml → deployment targets
    • terraform/ / pulumi/ → infrastructure as code
  3. Check for tooling:

    • .eslintrc* / eslint.config.* → ESLint configured
    • prettier* → Prettier configured
    • jest.config* / vitest.config* / pytest.ini → test framework
    • .env.example → environment variables needed
    • Makefile → build commands available
Step 2: Ask Clarifying Questions (if needed)

If the user's request is ambiguous, ask ONE focused question. Common clarifications:

  • "Create a CI pipeline" → "Should it run tests only, or also lint and type-check?"
  • "Add deployment" → "Where does this deploy? (Vercel, AWS, GCP, Docker Hub, etc.)"
  • "Set up tests" → "Should tests run on PR only, or also on push to main?"

If the intent is clear, skip this step and proceed.

Step 3: Generate the Workflow

Create the .github/workflows/{name}.yml file following these rules:

File Naming
  • Use descriptive kebab-case names: ci.yml, deploy-production.yml, release.yml
  • For simple CI: ci.yml
  • For deployment: deploy.yml or deploy-{target}.yml
  • For scheduled tasks: scheduled-{task}.yml
YAML Structure Rules
yaml
name: Human-readable name        # Always include

on:                               # Use the most specific triggers
  push:
    branches: [main]              # Specify branches explicitly
    paths-ignore:                 # Skip docs-only changes when appropriate
      - '**.md'
      - 'docs/**'
  pull_request:
    branches: [main]

permissions:                      # Always set minimal permissions
  contents: read

concurrency:                      # Prevent duplicate runs on PRs
  group: ${{ github.workflow }}-${{ github.ref }}
  cancel-in-progress: true

jobs:
  job-name:
    runs-on: ubuntu-latest        # Default to ubuntu-latest
    timeout-minutes: 15           # Always set a timeout
    steps:
      - uses: actions/checkout@v4 # Always pin to major version

Core Patterns by Use Case

CI (Test + Lint)

Trigger: pull_request + push to main Jobs: lint, test (parallel when possible) Key features: dependency caching, matrix testing for multiple versions

Deployment

Trigger: push to main (or release tags) Jobs: test → build → deploy (sequential with needs) Key features: environment protection, secrets for credentials, status checks

Release / Publish

Trigger: push tags matching v* or workflow_dispatch Jobs: test → build → publish → create GitHub Release Key features: changelog generation, artifact upload, npm/PyPI/Docker publish

Scheduled Tasks

Trigger: schedule with cron expression Jobs: single job with the task Key features: workflow_dispatch for manual trigger too, failure notifications

Security Scanning

Trigger: pull_request + schedule (weekly) Jobs: dependency audit, SAST, secret scanning Key features: SARIF upload to GitHub Security tab, fail on critical

Docker Build & Push

Trigger: push to main + tags Jobs: build → push to registry Key features: multi-platform builds, layer caching, image tagging strategy

Essential Actions Reference

Setup Actions (always pin to major version)
ActionPurpose
actions/checkout@v4Clone repository
actions/setup-node@v4Node.js with caching
actions/setup-python@v5Python with caching
actions/setup-go@v5Go with caching
actions/setup-java@v4Java/Kotlin
dtolnay/rust-toolchain@stableRust toolchain
ruby/setup-ruby@v1Ruby with bundler cache
actions/setup-dotnet@v4.NET SDK
Build & Deploy Actions
ActionPurpose
docker/build-push-action@v6Docker multi-platform builds
docker/login-action@v3Docker registry authentication
aws-actions/configure-aws-credentials@v4AWS authentication
google-github-actions/auth@v2GCP authentication
azure/login@v2Azure authentication
cloudflare/wrangler-action@v3Cloudflare Workers deploy
amondnet/vercel-action@v25Vercel deployment
Show full SKILL.md (287 more words)Show less
Quality & Security Actions
ActionPurpose
github/codeql-action/analyze@v3CodeQL SAST scanning
aquasecurity/trivy-action@masterContainer vulnerability scan
codecov/codecov-action@v4Coverage upload
actions/dependency-review-action@v4Dependency audit on PRs
Utility Actions
ActionPurpose
actions/cache@v4Generic caching
actions/upload-artifact@v4Store build artifacts
actions/download-artifact@v4Retrieve artifacts between jobs
softprops/action-gh-release@v2Create GitHub Releases
slackapi/slack-github-action@v2Slack notifications
peter-evans/create-pull-request@v7Automated PR creation

Security Best Practices (ALWAYS follow)

  1. Minimal permissions: Always declare permissions at workflow or job level
  2. Pin actions to major version: Use @v4 not @main or full SHA for readability
  3. Never echo secrets: Secrets are masked but avoid echo ${{ secrets.X }}
  4. Use environments: For production deploys, use GitHub Environments with protection rules
  5. Validate inputs: For workflow_dispatch, validate input values
  6. Avoid script injection: Never use ${{ github.event.*.body }} directly in run: — pass via environment variables
  7. Use GITHUB_TOKEN: Prefer ${{ secrets.GITHUB_TOKEN }} over PATs when possible
  8. Concurrency controls: Use concurrency to prevent parallel deploys
yaml
# WRONG - script injection vulnerability
- run: echo "${{ github.event.issue.title }}"

# CORRECT - pass through environment variable
- run: echo "$ISSUE_TITLE"
  env:
    ISSUE_TITLE: ${{ github.event.issue.title }}

Caching Strategies

Node.js
yaml
- uses: actions/setup-node@v4
  with:
    node-version: 20
    cache: 'npm'  # or 'yarn' or 'pnpm'
Python
yaml
- uses: actions/setup-python@v5
  with:
    python-version: '3.12'
    cache: 'pip'  # or 'poetry' or 'pipenv'
Go
yaml
- uses: actions/setup-go@v5
  with:
    go-version: '1.22'
    cache: true
Rust
yaml
- uses: actions/cache@v4
  with:
    path: |
      ~/.cargo/bin/
      ~/.cargo/registry/index/
      ~/.cargo/registry/cache/
      target/
    key: ${{ runner.os }}-cargo-${{ hashFiles('**/Cargo.lock') }}
Docker
yaml
- uses: docker/build-push-action@v6
  with:
    cache-from: type=gha
    cache-to: type=gha,mode=max

Matrix Testing Patterns

Multiple Node.js versions
yaml
strategy:
  matrix:
    node-version: [18, 20, 22]
  fail-fast: false
Multiple OS
yaml
strategy:
  matrix:
    os: [ubuntu-latest, macos-latest, windows-latest]
runs-on: ${{ matrix.os }}
Complex matrix with exclusions
yaml
strategy:
  matrix:
    os: [ubuntu-latest, windows-latest]
    node-version: [18, 20]
    exclude:
      - os: windows-latest
        node-version: 18

Cron Syntax Quick Reference

ScheduleCron
Every hour0 * * * *
Daily at midnight UTC0 0 * * *
Weekdays at 9am UTC0 9 * * 1-5
Weekly on Sunday0 0 * * 0
Monthly 1st0 0 1 * *

Output Format

After creating the workflow file, provide:

  1. What the workflow does — one-paragraph summary
  2. Required secrets — list any secrets the user needs to configure in Settings > Secrets
  3. Required permissions — if the workflow needs non-default repository permissions
  4. How to test — how to trigger the workflow (push, create PR, manual dispatch)

Common Patterns to Combine

When the user asks for something generic like "set up CI/CD", create a single workflow with multiple jobs:

yaml
jobs:
  lint:        # Fast feedback
  test:        # Core validation
  build:       # Ensure it compiles/bundles
    needs: [lint, test]
  deploy:      # Only after everything passes
    needs: build
    if: github.ref == 'refs/heads/main'

Keep workflows focused. Prefer one workflow per concern over one massive workflow, unless the jobs are tightly coupled.

© FNOSP, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .agents/skills/github-actions-creator of FNOSP/FlyNarwhal.

  • SKILL.md
  • references/workflow-templates.md

Open the folder on GitHubat commit c94d847

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in FNOSP/FlyNarwhal, which our catalogue first saw on October 7, 2026.

Compare with similar skills

GitHub Actions Creator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitHub Actions Creator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitHub Actions Creator this skillFNOSP/FlyNarwhal4951 repos~2.4kAutomated safety check: PassAGPL-3.0
Deployment and CI/CD Patternsaffaan-m/ECC274k6 repos~2.8kAutomated safety check: PassMIT
CIsoftspark/ai-toolkit179—~1.1kAutomated safety check: NotesApache-2.0
Deploy To Tempsgotempsh/temps822—~1.3kAutomated safety check: NotesApache-2.0
Configuration GeneratorArabelaTso/Skills-4-SE253—~2.8kAutomated safety check: NotesApache-2.0
Project Referencesaiskillstore/marketplace430—~2.3kAutomated safety check: NotesNone

Similar skills

  • Covers rolling, blue-green and canary deployments, multi-stage Dockerfiles, a GitHub Actions pipeline, health checks and production readiness for web apps.

    274k GitHub starsUsed in 6 repos~2.8k tokens
    DevOps & CloudAuto-check passed
  • CI

    softspark/ai-toolkit

    Detect/generate/debug CI pipeline config (GitHub Actions, GitLab CI).

    179 GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Deploy To Temps

    gotempsh/temps

    Deploy applications to the Temps platform with automatic framework detection, Dockerfile generation, and container orchestration.

    822 GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Configuration Generator

    ArabelaTso/Skills-4-SE

    Generate configuration files for applications, services, and infrastructure.

    253 GitHub stars~2.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Project References

    aiskillstore/marketplace

    Look up conventions, patterns, and concrete implementations from your own GitHub repositories checked out locally under ~/projects/referenzen/.

    430 GitHub stars~2.3k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    259 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes

More from FNOSP/FlyNarwhal

All 8 skills in this repo
  • Automate GitHub workflows with AI assistance. An agent skill from FNOSP/FlyNarwhal.

    495 GitHub starsUsed in 7 repos~5.4k tokens
    Auto-check passed
  • Flutter Tester

    FNOSP/FlyNarwhal

    A skill your agent uses when creating, writing, fixing, or reviewing tests in a Flutter project.

    495 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Flutter Expert

    FNOSP/FlyNarwhal

    A skill your agent uses when building cross-platform applications with Flutter 3+ and Dart.

    495 GitHub starsUsed in 2 repos~758 tokens
    Auto-check passed
  • Release Publishing

    FNOSP/FlyNarwhal

    A skill your agent uses when publishing a new release of FlyNarwhal desktop.

    495 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Remote API Development

    FNOSP/FlyNarwhal

    A skill your agent uses when adding, modifying, or refactoring any remote/HTTP API call in this Flutter project.

    495 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Swift Expert

    FNOSP/FlyNarwhal

    A skill your agent uses when building iOS/macOS applications with Swift 5.9+, SwiftUI, or async/await concurrency.

    495 GitHub stars~813 tokensUpdated today
    Auto-check passed

Categories

Questions about GitHub Actions Creator

What does GitHub Actions Creator do?

A skill your agent uses when the user wants to create, generate, or set up a GitHub Actions workflow. GitHub Actions Creator is an agent skill from FNOSP/FlyNarwhal. Use when the user wants to create, generate, or set up a GitHub Actions workflow.

When should I use GitHub Actions Creator?

GitHub Actions Creator fits situations like: the user wants to create; set up a GitHub Actions workflow.

How do I install GitHub Actions Creator in Claude Code?

Run `npx skills add FNOSP/FlyNarwhal --skill github-actions-creator -a claude-code`. Or copy the skill folder (.agents/skills/github-actions-creator in FNOSP/FlyNarwhal) into .claude/skills/github-actions-creator in your project. Claude Code loads it when a task matches its description.

How do I install GitHub Actions Creator in Codex?

Run `npx skills add FNOSP/FlyNarwhal --skill github-actions-creator -a codex`. Or copy the skill folder (.agents/skills/github-actions-creator in FNOSP/FlyNarwhal) into .agents/skills/github-actions-creator in your project. Codex loads it when a task matches its description.

Can I use GitHub Actions Creator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FNOSP/FlyNarwhal --skill github-actions-creator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-actions-creator, .gemini/skills/github-actions-creator, .github/skills/github-actions-creator and .opencode/skills/github-actions-creator in your project.

What does GitHub Actions Creator need to run?

Going by SKILL.md and its folder, GitHub Actions Creator needs credentials named GITHUB_TOKEN. Our summary lists: Python 3; Node.js; Docker; A credential in GITHUB_TOKEN.

Does GitHub Actions Creator access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is GitHub Actions Creator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does GitHub Actions Creator use?

GitHub Actions Creator is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitHub Actions Creator use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.5k tokens, read only when the agent opens those files.

What are the alternatives to GitHub Actions Creator?

Skills that share tags, products or a category with GitHub Actions Creator: Deployment and CI/CD Patterns (affaan-m/ECC, 274k stars), CI (softspark/ai-toolkit, 179 stars), Deploy To Temps (gotempsh/temps, 822 stars) and Configuration Generator (ArabelaTso/Skills-4-SE, 253 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitHub Actions Creator?

FNOSP (a GitHub organization) maintains it in FNOSP/FlyNarwhal, which has 495 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 6, 2026.

Source: FNOSP/FlyNarwhal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.