Agent skill

CI GitHub Actions

by gnomeria in gnomeria/usbtree

GitHub Actions CI pipeline conventions — job shape, caching, permissions, and action pinning.

MITAuto-check passedDevOps & Cloud

Install CI GitHub Actions

skills CLI
$ npx skills add gnomeria/usbtree --skill ci-github-actions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install gnomeria/usbtree ci-github-actions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/gnomeria/usbtree.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ci-github-actions .claude/skills/ci-github-actions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ci-github-actions
GitHub stars
690
Token cost
~1.4k tokens
SKILL.md length
619 words
Files
2 (incl. references)
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

GitHub Actions CI pipeline conventions — job shape, caching, permissions, and action pinning.

  • Asked to set up CI
  • SKILL.md covers Pipeline shape, Concurrency — cancel…, Permissions — least privilege and Pin third-party actions to SHA, plus 6 more sections
  • Calls pnpm, bun and npm
  • Add a GitHub Actions workflow

What it does

CI GitHub Actions is an agent skill from gnomeria/usbtree. GitHub Actions CI pipeline conventions — job shape, caching, permissions, and action pinning. Use when asked to "set up CI", "add a GitHub Actions workflow", "fix the pipeline", or when creating/reviewing files under .github/workflows/ for Go or Node/TS projects.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/workflows.md`).

It sits in DevOps & Cloud, covering CI/CD and Caching. It works with GitHub Actions and pnpm. The repository describes itself as: Live USB device tree in your terminal. Rust TUI, no root, no libusb. Full activity metrics on Linux; device tree on macOS/Windows. The licence is MIT.

When your agent uses it

  • Asked to set up CI
  • Add a GitHub Actions workflow
  • Fix the pipeline
  • Creating/reviewing files under .github/workflows/ for Go

Example prompts

  • “set up CI”
  • “add a GitHub Actions workflow”
  • “fix the pipeline”
  • “/ci-github-actions”

What it can do on your machine

Read from SKILL.md and the folder at commit 8ba6a5e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • bun
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

CI GitHub Actions loads about 1.4k tokens when it runs, and up to ~2.8k if it reads all its reference files. Until then it costs about 70 tokens; SKILL.md has 619 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from gnomeria/usbtree at commit 8ba6a5e, republished under its MIT licence (© gnomeria). 619 words, ~1,363 tokens.

Download SKILL.mdSave it as .claude/skills/ci-github-actions/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
ci-github-actions
description
GitHub Actions CI pipeline conventions — job shape, caching, permissions, and action pinning. Use when asked to "set up CI", "add a GitHub Actions workflow", "fix the pipeline", or when creating/reviewing files under .github/workflows/ for Go or Node/TS projects.

CI with GitHub Actions

Complete copy-paste workflows for Go and Node/TS live in references/workflows.md — read it when writing an actual workflow file. This file is the rules.

Pipeline shape

Default pipeline: lint → typecheck → test → build, as parallel jobs (they don't depend on each other's outputs) with build optionally needs: the rest if you want fail-fast economics. Trigger:

yaml
on:
  push:
    branches: [main]
  pull_request:

Don't run push on every branch and pull_request — that double-builds PR branches.

Concurrency — cancel superseded runs

Every CI workflow gets this; without it, ten pushes to a PR queue ten full runs:

yaml
concurrency:
  group: ${{ github.workflow }}-${{ github.ref }}
  cancel-in-progress: true

For deploy workflows, keep the group but set cancel-in-progress: false (queue, don't kill mid-deploy).

Permissions — least privilege

Top of every workflow:

yaml
permissions:
  contents: read

Grant more only per-job, only what that job proves it needs (pull-requests: write for a comment bot, id-token: write for OIDC cloud auth, packages: write for pushing images). Never leave the org/repo default write-all doing the work implicitly.

Pin third-party actions to SHA

  • Official actions/* and other heavily-trusted orgs: major tag is acceptable (actions/checkout@v5).

  • Everything else: pin to a full commit SHA with a version comment:

    yaml
    uses: some-org/some-action@3d1a2b... # v2.1.0

    Tags are mutable; a compromised action re-tagged at v2 runs in your CI with your secrets. Dependabot/Renovate can bump SHAs for you — enable it.

Caching

  • Go: actions/setup-go@v6 with cache: true (default when a go.sum exists) — caches module and build cache. Don't hand-roll actions/cache for Go.
  • Node/npm or yarn: actions/setup-node@v5 with cache: npm — caches the package cache (correct; don't cache node_modules).
  • pnpm: setup-node's cache: pnpm caches the pnpm store. Install pnpm first (pnpm/action-setup, SHA-pinned), then setup-node with cache: pnpm, then pnpm install --frozen-lockfile.
  • bun: oven-sh/setup-bun (SHA-pinned) has no built-in caching — pair with actions/cache on ~/.bun/install/cache, key bun-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('**/bun.lock') }}, then bun install --frozen-lockfile.
  • Cache keys must include the lockfile hash — built-in caching does this for you.
  • Never cache build outputs between CI runs as a correctness shortcut; only as a measured optimization (Next.js .next/cache is the common legitimate case).

Matrix — only when genuinely needed

A matrix multiplies CI cost. Use one when you actually support multiple targets (a library testing Node 20/22, or linux+windows CLIs). An app deployed to one runtime tests on that one runtime version — pin it to the version production runs.

Show full SKILL.md (259 more words)Show less

Secrets

  • Secrets come from GitHub Environments (environment: production on the job), which gate them behind protection rules and reviewers — not from repo-wide secrets sprayed into every job.
  • CI jobs (lint/test/build) should need zero secrets. If a test needs a secret, question the test.
  • Never echo secrets, never pass them as CLI args (visible in process lists/logs). Prefer OIDC (id-token: write + cloud role assumption) over long-lived cloud keys.
  • pull_request_target + checkout of PR head = classic secret-exfiltration hole. Don't use pull_request_target unless you know exactly why.

Monorepo path filters

Scope workflows to what changed:

yaml
on:
  pull_request:
    paths:
      - "services/api/**"
      - ".github/workflows/api.yml"

Include the workflow file itself in its own paths. If a filtered check is a required status check, add a no-op fallback workflow with the inverse paths-ignore so PRs that don't touch the service aren't blocked forever.

Artifacts

Upload build outputs when a later job or a human needs them:

yaml
- uses: actions/upload-artifact@v5
  with:
    name: server-dist
    path: dist/
    retention-days: 7

Set retention-days deliberately (default 90 wastes storage). Pass files between jobs via artifacts, not by rebuilding. Test reports/coverage: upload with if: always() so failures still produce the report.

Checklist for a new workflow

  • Triggers: push to main + pull_request, no double-trigger
  • concurrency with cancel-in-progress: true
  • permissions: contents: read at top; extras per-job only
  • Third-party actions SHA-pinned with version comment
  • setup-go / setup-node built-in caching, keyed off lockfile
  • Installs use lockfile-strict mode (npm ci, pnpm install --frozen-lockfile, bun install --frozen-lockfile)
  • No matrix unless multiple targets are truly supported
  • Secrets via environments; none in lint/test/build jobs
  • Monorepo: paths filters incl. the workflow file
  • Artifacts have retention-days; reports uploaded if: always()
  • Runtime versions read from the repo (go.mod, .nvmrc/package.json engines), not hardcoded twice

© gnomeria, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .agents/skills/ci-github-actions of gnomeria/usbtree.

  • SKILL.md
  • references/workflows.md

Open the folder on GitHubat commit 8ba6a5e

Compare with similar skills

CI GitHub Actions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

CI GitHub Actions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
CI GitHub Actions this skillgnomeria/usbtree690—~1.4kAutomated safety check: PassMIT
CI Pipeline Synthesizerkajisho5/ffmpeg-skill1.9k1 repos~1.1kAutomated safety check: PassMIT
Deploy Release Testvercel/next.js143k—~1.2kAutomated safety check: PassMIT
Devops SpecialistCaoMeiYouRen/caomei-auth220—~446Automated safety check: NotesMIT
CI Checkadam-s/intercept189—~612Automated safety check: PassMIT
Atmos Cachecloudposse/atmos1.4k—~793Automated safety check: PassApache-2.0

Similar skills

  • CI Pipeline Synthesizer

    kajisho5/ffmpeg-skill

    Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.

    1.9k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check passed
  • Deploy Release Test

    vercel/next.js

    Official

    Validate a commit-specific Next.js preview package and manually trigger the entire Next.js deployment test suite through the teste2edeployrelease.yml GitHub Actions workflow.

    143k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Devops Specialist

    CaoMeiYouRen/caomei-auth

    修改 Docker、CI/CD、部署配置、环境变量、运行时参数、构建脚本和发布流程时使用。优先覆盖 Docker、Vercel、Cloudflare 与 GitHub Actions 场景。用户提到 deploy、Dockerfile、workflow、CI、CD、environment variables、build pipeline、release config 时都应触发。

    220 GitHub stars~446 tokensUpdated 7 days ago
    DevOps & CloudAuto-check: notes
  • CI Check

    adam-s/intercept

    Run local CI checks and verify GitHub Actions status. An agent skill from adam-s/intercept.

    189 GitHub stars~612 tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Atmos Cache

    cloudposse/atmos

    Atmos caching: CI cache configuration and commands, GitHub Actions cache integration, Terraform registry cache mirror/list/prune/stats/trust, and cache modernization guidance

    1.4k GitHub stars~793 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Ship Now

    BuilderIO/agent-native

    Fast-path the current branch through local pnpm prep:urgent, targeted recovery, feedback resolution, whole-branch push, immediate admin merge, and fresh-branch rotation.

    7.1k GitHub stars~3.4k tokensUpdated today
    DevOps & CloudAuto-check passed

More from gnomeria/usbtree

  • Knowledge Graph

    gnomeria/usbtree

    Set up and maintain a lightweight, file-based knowledge graph of the repo — entities, typed relations, decisions, gotchas — so agents load context fast instead of re-exploring the codebase every…

    690 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Debug

    gnomeria/usbtree

    Systematic root-cause debugging — reproduce, isolate, fix at the source, prove the fix.

    690 GitHub stars~715 tokensUpdated 1 mo ago
    Auto-check passed
  • Refactor

    gnomeria/usbtree

    Behavior-preserving restructuring done safely — test net first, small verified steps, no mixed-in feature changes.

    690 GitHub stars~669 tokensUpdated 1 mo ago
    Auto-check passed
  • Write Tests

    gnomeria/usbtree

    Author tests that match the repo's stack and existing test style, at the cheapest level that catches the regression.

    690 GitHub stars~622 tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about CI GitHub Actions

What does CI GitHub Actions do?

GitHub Actions CI pipeline conventions — job shape, caching, permissions, and action pinning. CI GitHub Actions is an agent skill from gnomeria/usbtree. GitHub Actions CI pipeline conventions — job shape, caching, permissions, and action pinning.

When should I use CI GitHub Actions?

CI GitHub Actions fits situations like: asked to set up CI; add a GitHub Actions workflow; fix the pipeline; creating/reviewing files under .github/workflows/ for Go.

How do I install CI GitHub Actions in Claude Code?

Run `npx skills add gnomeria/usbtree --skill ci-github-actions -a claude-code`. Or copy the skill folder (.agents/skills/ci-github-actions in gnomeria/usbtree) into .claude/skills/ci-github-actions in your project. Claude Code loads it when a task matches its description.

How do I install CI GitHub Actions in Codex?

Run `npx skills add gnomeria/usbtree --skill ci-github-actions -a codex`. Or copy the skill folder (.agents/skills/ci-github-actions in gnomeria/usbtree) into .agents/skills/ci-github-actions in your project. Codex loads it when a task matches its description.

Can I use CI GitHub Actions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gnomeria/usbtree --skill ci-github-actions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ci-github-actions, .gemini/skills/ci-github-actions, .github/skills/ci-github-actions and .opencode/skills/ci-github-actions in your project.

What does CI GitHub Actions need to run?

Going by SKILL.md and its folder, CI GitHub Actions needs the command-line tools its instructions call (pnpm, bun and npm).

Does CI GitHub Actions access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is CI GitHub Actions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does CI GitHub Actions use?

CI GitHub Actions is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does CI GitHub Actions use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to CI GitHub Actions?

Skills that share tags, products or a category with CI GitHub Actions: CI Pipeline Synthesizer (kajisho5/ffmpeg-skill, 1.9k stars), Deploy Release Test (vercel/next.js, 143k stars), Devops Specialist (CaoMeiYouRen/caomei-auth, 220 stars) and CI Check (adam-s/intercept, 189 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains CI GitHub Actions?

gnomeria (a GitHub user) maintains it in gnomeria/usbtree, which has 690 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on August 20, 2026.

Source: gnomeria/usbtree on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.