CI Pipeline Synthesizer
kajisho5/ffmpeg-skill
Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.
GitHub Actions CI pipeline conventions — job shape, caching, permissions, and action pinning.
$ npx skills add gnomeria/usbtree --skill ci-github-actions -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install gnomeria/usbtree ci-github-actions --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/gnomeria/usbtree.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ci-github-actions .claude/skills/ci-github-actions && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ci-github-actions" agent skill from https://github.com/gnomeria/usbtree/tree/main/.agents/skills/ci-github-actions into .claude/skills/ci-github-actions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-github-actions", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/gnomeria/usbtree/tree/main/.agents/skills/ci-github-actionsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add gnomeria/usbtree --skill ci-github-actions -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install gnomeria/usbtree ci-github-actions --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gnomeria/usbtree.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/ci-github-actions .agents/skills/ci-github-actions && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ci-github-actions" agent skill from https://github.com/gnomeria/usbtree/tree/main/.agents/skills/ci-github-actions into .agents/skills/ci-github-actions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-github-actions", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add gnomeria/usbtree --skill ci-github-actions -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install gnomeria/usbtree ci-github-actions --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gnomeria/usbtree.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/ci-github-actions .cursor/skills/ci-github-actions && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ci-github-actions" agent skill from https://github.com/gnomeria/usbtree/tree/main/.agents/skills/ci-github-actions into .cursor/skills/ci-github-actions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-github-actions", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/gnomeria/usbtree.git --path .agents/skills/ci-github-actions--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add gnomeria/usbtree --skill ci-github-actions -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install gnomeria/usbtree ci-github-actions --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gnomeria/usbtree.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/ci-github-actions .gemini/skills/ci-github-actions && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ci-github-actions" agent skill from https://github.com/gnomeria/usbtree/tree/main/.agents/skills/ci-github-actions into .gemini/skills/ci-github-actions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-github-actions", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install gnomeria/usbtree ci-github-actionsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add gnomeria/usbtree --skill ci-github-actions -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/gnomeria/usbtree.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/ci-github-actions .github/skills/ci-github-actions && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ci-github-actions" agent skill from https://github.com/gnomeria/usbtree/tree/main/.agents/skills/ci-github-actions into .github/skills/ci-github-actions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-github-actions", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add gnomeria/usbtree --skill ci-github-actions -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install gnomeria/usbtree ci-github-actions --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gnomeria/usbtree.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/ci-github-actions .opencode/skills/ci-github-actions && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ci-github-actions" agent skill from https://github.com/gnomeria/usbtree/tree/main/.agents/skills/ci-github-actions into .opencode/skills/ci-github-actions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-github-actions", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ci-github-actionsGitHub Actions CI pipeline conventions — job shape, caching, permissions, and action pinning.
CI GitHub Actions is an agent skill from gnomeria/usbtree. GitHub Actions CI pipeline conventions — job shape, caching, permissions, and action pinning. Use when asked to "set up CI", "add a GitHub Actions workflow", "fix the pipeline", or when creating/reviewing files under .github/workflows/ for Go or Node/TS projects.
Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/workflows.md`).
It sits in DevOps & Cloud, covering CI/CD and Caching. It works with GitHub Actions and pnpm. The repository describes itself as: Live USB device tree in your terminal. Rust TUI, no root, no libusb. Full activity metrics on Linux; device tree on macOS/Windows. The licence is MIT.
Read from SKILL.md and the folder at commit 8ba6a5e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmbunnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
CI GitHub Actions loads about 1.4k tokens when it runs, and up to ~2.8k if it reads all its reference files. Until then it costs about 70 tokens; SKILL.md has 619 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from gnomeria/usbtree at commit 8ba6a5e, republished under its MIT licence (© gnomeria). 619 words, ~1,363 tokens.
.claude/skills/ci-github-actions/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Complete copy-paste workflows for Go and Node/TS live in references/workflows.md —
read it when writing an actual workflow file. This file is the rules.
Default pipeline: lint → typecheck → test → build, as parallel jobs (they don't
depend on each other's outputs) with build optionally needs: the rest if you want
fail-fast economics. Trigger:
on:
push:
branches: [main]
pull_request:Don't run push on every branch and pull_request — that double-builds PR branches.
Every CI workflow gets this; without it, ten pushes to a PR queue ten full runs:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: trueFor deploy workflows, keep the group but set cancel-in-progress: false (queue, don't kill mid-deploy).
Top of every workflow:
permissions:
contents: readGrant more only per-job, only what that job proves it needs (pull-requests: write for a
comment bot, id-token: write for OIDC cloud auth, packages: write for pushing images).
Never leave the org/repo default write-all doing the work implicitly.
Official actions/* and other heavily-trusted orgs: major tag is acceptable (actions/checkout@v5).
Everything else: pin to a full commit SHA with a version comment:
uses: some-org/some-action@3d1a2b... # v2.1.0Tags are mutable; a compromised action re-tagged at v2 runs in your CI with your
secrets. Dependabot/Renovate can bump SHAs for you — enable it.
actions/setup-go@v6 with cache: true (default when a go.sum exists) — caches module and build cache. Don't hand-roll actions/cache for Go.actions/setup-node@v5 with cache: npm — caches the package cache (correct; don't cache node_modules).cache: pnpm caches the pnpm store. Install pnpm first (pnpm/action-setup, SHA-pinned), then setup-node with cache: pnpm, then pnpm install --frozen-lockfile.oven-sh/setup-bun (SHA-pinned) has no built-in caching — pair with actions/cache on ~/.bun/install/cache, key bun-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('**/bun.lock') }}, then bun install --frozen-lockfile..next/cache is the common legitimate case).A matrix multiplies CI cost. Use one when you actually support multiple targets (a library testing Node 20/22, or linux+windows CLIs). An app deployed to one runtime tests on that one runtime version — pin it to the version production runs.
environment: production on the job), which gate them behind protection rules and reviewers — not from repo-wide secrets sprayed into every job.echo secrets, never pass them as CLI args (visible in process lists/logs). Prefer OIDC (id-token: write + cloud role assumption) over long-lived cloud keys.pull_request_target + checkout of PR head = classic secret-exfiltration hole. Don't use pull_request_target unless you know exactly why.Scope workflows to what changed:
on:
pull_request:
paths:
- "services/api/**"
- ".github/workflows/api.yml"Include the workflow file itself in its own paths. If a filtered check is a required
status check, add a no-op fallback workflow with the inverse paths-ignore so PRs that
don't touch the service aren't blocked forever.
Upload build outputs when a later job or a human needs them:
- uses: actions/upload-artifact@v5
with:
name: server-dist
path: dist/
retention-days: 7Set retention-days deliberately (default 90 wastes storage). Pass files between jobs
via artifacts, not by rebuilding. Test reports/coverage: upload with
if: always() so failures still produce the report.
push to main + pull_request, no double-triggerconcurrency with cancel-in-progress: truepermissions: contents: read at top; extras per-job onlynpm ci, pnpm install --frozen-lockfile, bun install --frozen-lockfile)paths filters incl. the workflow fileretention-days; reports uploaded if: always()go.mod, .nvmrc/package.json engines), not hardcoded twice© gnomeria, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in .agents/skills/ci-github-actions of gnomeria/usbtree.
Open the folder on GitHubat commit 8ba6a5e
CI GitHub Actions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| CI GitHub Actions this skillgnomeria/usbtree | 690 | — | ~1.4k | Automated safety check: Pass | MIT | |
| CI Pipeline Synthesizerkajisho5/ffmpeg-skill | 1.9k | 1 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Deploy Release Testvercel/next.js | 143k | — | ~1.2k | Automated safety check: Pass | MIT | |
| Devops SpecialistCaoMeiYouRen/caomei-auth | 220 | — | ~446 | Automated safety check: Notes | MIT | |
| CI Checkadam-s/intercept | 189 | — | ~612 | Automated safety check: Pass | MIT | |
| Atmos Cachecloudposse/atmos | 1.4k | — | ~793 | Automated safety check: Pass | Apache-2.0 |
kajisho5/ffmpeg-skill
Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.
vercel/next.js
Validate a commit-specific Next.js preview package and manually trigger the entire Next.js deployment test suite through the teste2edeployrelease.yml GitHub Actions workflow.
CaoMeiYouRen/caomei-auth
修改 Docker、CI/CD、部署配置、环境变量、运行时参数、构建脚本和发布流程时使用。优先覆盖 Docker、Vercel、Cloudflare 与 GitHub Actions 场景。用户提到 deploy、Dockerfile、workflow、CI、CD、environment variables、build pipeline、release config 时都应触发。
adam-s/intercept
Run local CI checks and verify GitHub Actions status. An agent skill from adam-s/intercept.
cloudposse/atmos
Atmos caching: CI cache configuration and commands, GitHub Actions cache integration, Terraform registry cache mirror/list/prune/stats/trust, and cache modernization guidance
BuilderIO/agent-native
Fast-path the current branch through local pnpm prep:urgent, targeted recovery, feedback resolution, whole-branch push, immediate admin merge, and fresh-branch rotation.
gnomeria/usbtree
Set up and maintain a lightweight, file-based knowledge graph of the repo — entities, typed relations, decisions, gotchas — so agents load context fast instead of re-exploring the codebase every…
gnomeria/usbtree
Systematic root-cause debugging — reproduce, isolate, fix at the source, prove the fix.
gnomeria/usbtree
Behavior-preserving restructuring done safely — test net first, small verified steps, no mixed-in feature changes.
gnomeria/usbtree
Author tests that match the repo's stack and existing test style, at the cheapest level that catches the regression.
Works with
Categories
GitHub Actions CI pipeline conventions — job shape, caching, permissions, and action pinning. CI GitHub Actions is an agent skill from gnomeria/usbtree. GitHub Actions CI pipeline conventions — job shape, caching, permissions, and action pinning.
CI GitHub Actions fits situations like: asked to set up CI; add a GitHub Actions workflow; fix the pipeline; creating/reviewing files under .github/workflows/ for Go.
Run `npx skills add gnomeria/usbtree --skill ci-github-actions -a claude-code`. Or copy the skill folder (.agents/skills/ci-github-actions in gnomeria/usbtree) into .claude/skills/ci-github-actions in your project. Claude Code loads it when a task matches its description.
Run `npx skills add gnomeria/usbtree --skill ci-github-actions -a codex`. Or copy the skill folder (.agents/skills/ci-github-actions in gnomeria/usbtree) into .agents/skills/ci-github-actions in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gnomeria/usbtree --skill ci-github-actions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ci-github-actions, .gemini/skills/ci-github-actions, .github/skills/ci-github-actions and .opencode/skills/ci-github-actions in your project.
Going by SKILL.md and its folder, CI GitHub Actions needs the command-line tools its instructions call (pnpm, bun and npm).
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
CI GitHub Actions is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with CI GitHub Actions: CI Pipeline Synthesizer (kajisho5/ffmpeg-skill, 1.9k stars), Deploy Release Test (vercel/next.js, 143k stars), Devops Specialist (CaoMeiYouRen/caomei-auth, 220 stars) and CI Check (adam-s/intercept, 189 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
gnomeria (a GitHub user) maintains it in gnomeria/usbtree, which has 690 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on August 20, 2026.
Source: gnomeria/usbtree on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.