Agent skill

GitHub Actions Workflows

by Hack23 in Hack23/cia

Create secure CI/CD workflows with GitHub Actions for Java 26/Maven/PostgreSQL builds, security scans, and deployments

Apache-2.0Auto-check passedDevOps & Cloud

Install GitHub Actions Workflows

skills CLI
$ npx skills add Hack23/cia --skill github-actions-workflows -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia github-actions-workflows --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/github-actions-workflows .claude/skills/github-actions-workflows && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
github-actions-workflows
GitHub stars
239
Token cost
~1.9k tokens
SKILL.md length
341 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Create secure CI/CD workflows with GitHub Actions for Java 26/Maven/PostgreSQL builds, security scans, and deployments

  • Tasks that involve CI/CD
  • SKILL.md covers Purpose, When to Use, Current CIA Build Environment and CI/CD Pipeline Template, plus 5 more sections
  • Needs SONAR_TOKEN and POSTGRES_PASSWORD
  • Tasks that involve Security review

What it does

GitHub Actions Workflows is an agent skill from Hack23/cia. Create secure CI/CD workflows with GitHub Actions for Java 26/Maven/PostgreSQL builds, security scans, and deployments

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering CI/CD and Security review. It works with GitHub Actions, PostgreSQL and Java. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve CI/CD
  • Tasks that involve Security review

Example prompts

  • “/github-actions-workflows”

Requirements

  • Node.js
  • A credential in SONAR_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.github.com
    • slsa.dev
    • securityscorecards.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SONAR_TOKEN
    • POSTGRES_PASSWORD
    • DB_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GitHub Actions Workflows loads about 1.9k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 341 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 341 words, ~1,942 tokens.

Download SKILL.mdSave it as .claude/skills/github-actions-workflows/SKILL.md (or your agent's skills folder).
name
github-actions-workflows
description
Create secure CI/CD workflows with GitHub Actions for Java 26/Maven/PostgreSQL builds, security scans, and deployments
license
Apache-2.0

GitHub Actions Workflows Skill

Purpose

Create and maintain secure, efficient CI/CD pipelines using GitHub Actions for the CIA platform. Covers build, test, security scanning, deployment, and agentic workflow integration.

When to Use

  • ✅ Setting up or modifying CI/CD pipelines
  • ✅ Automating security scans (CodeQL, OWASP, SonarCloud)
  • ✅ Implementing deployment pipelines
  • ✅ Scheduling periodic tasks
  • ✅ Integrating with GitHub Agentic Workflows (gh-aw)

Current CIA Build Environment

ComponentVersionNotes
Java JDK26 (Temurin)Source level 21
Maven3.9.15Multi-module reactor build
PostgreSQL18Extensions: pgaudit, pgcrypto, pg_stat_statements
Node.js24MCP servers, Playwright
Runnerubuntu-latestGitHub Actions hosted

CI/CD Pipeline Template

yaml
name: CI/CD Pipeline

on:
  push:
    branches: [master]
  pull_request:
    branches: [master]

permissions:
  contents: read
  security-events: write
  actions: read

jobs:
  build:
    permissions:
      contents: read
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

      - name: Set up JDK 26
        uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4.7.1
        with:
          java-version: '26'
          distribution: 'temurin'
          cache: 'maven'

      - name: Build with Maven
        run: mvn clean install -DskipTests

      - name: Run Tests
        run: mvn test -Dtest='!**ITest*,!**/XmlDateTypeAdapterTest,!**/XmlTimeTypeAdapterTest,!**/XmlDateTimeTypeAdapterTest'

      - name: Upload Coverage
        uses: codecov/codecov-action@18283e04ce6e62d37312384ff67231eb8fd56d24 # v5.4.3
        with:
          files: '**/target/site/jacoco/jacoco.xml'

  security:
    runs-on: ubuntu-latest
    needs: build
    steps:
      - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

      - name: Initialize CodeQL
        uses: github/codeql-action/init@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3.28.18
        with:
          languages: java

      - name: Autobuild
        uses: github/codeql-action/autobuild@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3.28.18
        # Note: The actual codeql-analysis.yml uses a custom Maven build instead of autobuild.
        # Replace this step with a manual build if autobuild fails for your project.

      - name: CodeQL Analysis
        uses: github/codeql-action/analyze@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3.28.18

      - name: OWASP Dependency Check
        run: mvn org.owasp:dependency-check-maven:check

  deploy:
    runs-on: ubuntu-latest
    needs: [build, security]
    if: github.ref == 'refs/heads/master'
    permissions:
      id-token: write   # Required for OIDC
      contents: read
    steps:
      - name: Deploy to AWS
        uses: aws-actions/configure-aws-credentials@ececac1a45f3b08a01d2dd070d28d111c5fe6722 # v4.1.0
        with:
          role-to-assume: ${{ secrets.AWS_ROLE_ARN }}
          aws-region: eu-north-1

Security Best Practices

Action Pinning

Always pin actions to full SHA commit hashes, never tags:

yaml
# ✅ Correct - pinned to SHA
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

# ❌ Wrong - mutable tag
- uses: actions/checkout@v4
Permissions

Always declare minimal permissions at workflow and job level:

yaml
permissions:
  contents: read      # Default for most jobs
  security-events: write  # Only for security scan uploads
  issues: write       # Only for issue management jobs
Secrets Management
yaml
# ✅ Use GitHub secrets
env:
  SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}

# ✅ Use OIDC for cloud access (no long-lived keys)
- uses: aws-actions/configure-aws-credentials@ececac1a45f3b08a01d2dd070d28d111c5fe6722 # v4.1.0
  with:
    role-to-assume: ${{ secrets.AWS_ROLE_ARN }}

# ❌ Never hardcode credentials
Supply Chain Security
yaml
# SLSA 3 build provenance (pin to a specific commit SHA)
- uses: slsa-framework/slsa-github-generator/.github/workflows/builder_maven.yml@3c58c41cab36161dc53f223132d1f59f1df67cf9 # v2
  with:
    rekor-log-public: true

CIA-Specific Workflows

Existing Workflows
WorkflowPurposeTrigger
codeql-analysis.ymlSecurity vulnerability scanningPush/PR to master + scheduled
dependency-review.ymlDependency security checksPR only
scorecards.ymlOpenSSF Scorecard assessmentScheduled
release.ymlBuild artifacts + SLSA attestationsManual (workflow_dispatch)
copilot-setup-steps.ymlCopilot agent build environmentCopilot sessions
javadoc-generation.ymlJavaDoc generationPush/scheduled
site-generation.ymlMaven site generationPush/scheduled
zap-scan.ymlOWASP ZAP security scanScheduled
generate-intelligence-changelog.ymlIntelligence changelog generationManual (workflow_dispatch)
labeler.ymlPull request auto-labelingpull_request_target
validate-field-completeness.ymlJSON export field completenessPush (path-filtered)
validate-json-schemas.ymlJSON schema validationPush/PR (path-filtered) + scheduled
validate-view-documentation.ymlView documentation validationScheduled (monthly) + PR (path-filtered)
PostgreSQL Setup Pattern
yaml
services:
  postgres:
    image: postgres:18
    env:
      POSTGRES_USER: eris
      POSTGRES_PASSWORD: ${{ secrets.DB_PASSWORD }}
      POSTGRES_DB: cia_dev
    options: >-
      --health-cmd pg_isready
      --health-interval 10s
      --health-timeout 5s
      --health-retries 5
    ports:
      - 5432:5432
Maven Build Optimization
yaml
# Multi-level caching for resilience
- name: Cache Maven repository
  uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
  with:
    path: ~/.m2/repository
    key: ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }}
    restore-keys: |
      ${{ runner.os }}-maven-

# Parallel builds for multi-module projects
- name: Build
  run: mvn -T 1C clean install -DskipTests

Integration with Agentic Workflows

GitHub Agentic Workflows (gh-aw) complement traditional Actions:

AspectTraditional ActionsAgentic Workflows
LogicDeterministic YAMLNatural language AI
DecisionsPre-programmed conditionalsContext-aware reasoning
Format.yml files.md files → compiled to .lock.yml
SecurityManual permission managementBuilt-in 5-layer security
Best forBuild, test, deployTriage, review, docs, analysis

Use both together: traditional Actions for deterministic build/test/deploy, agentic workflows for intelligent automation.

ISMS Control Mapping

ControlImplementation
ISO 27001 A.8.8Change management via PR-gated workflow changes
ISO 27001 A.8.15Audit logging via Actions run logs
NIST CSF PR.IP-1Baseline configuration via pinned action versions
CIS Control 16Application security via CodeQL + OWASP in pipeline

References

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/github-actions-workflows of Hack23/cia.

Open the folder on GitHubat commit 6a9797b

Compare with similar skills

GitHub Actions Workflows next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitHub Actions Workflows compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitHub Actions Workflows this skillHack23/cia239—~1.9kAutomated safety check: PassApache-2.0
Secure GitHub Actionsvechain/x-app-template450—~1.2kAutomated safety check: PassMIT
Code PatternsAedelon/claude-code-blueprint120—~1.2kAutomated safety check: PassCustom licence
Cicd Pipelinerevfactory/harness-1001.3k—~1.8kAutomated safety check: PassApache-2.0
Agentic GitHub Actions Auditortrailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0
GitHub Actions Hardeninggithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT

Similar skills

  • Secure GitHub Actions

    vechain/x-app-template

    Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.

    450 GitHub stars~1.2k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Code Patterns

    Aedelon/claude-code-blueprint

    Reference patterns for REST APIs, pytest/vitest testing, Docker multi-stage builds, GitHub Actions CI/CD, PostgreSQL, TypeScript generics, Python async, and React Server Components.

    120 GitHub stars~1.2k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed
  • Cicd Pipeline

    revfactory/harness-100

    Full pipeline for CI/CD pipeline design, build, monitoring, and optimization.

    1.3k GitHub stars~1.8k tokensUpdated 6 mo ago
    DevOps & CloudAuto-check passed
  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.4k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • GitHub Actions Hardening

    github/awesome-copilot

    Official

    Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).

    40k GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • Managing Pipelines

    rileyhilliard/claude-essentials

    Guides GitHub Actions CI/CD architecture, security hardening, and deployment strategies.

    130 GitHub stars~1.5k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about GitHub Actions Workflows

What does GitHub Actions Workflows do?

Create secure CI/CD workflows with GitHub Actions for Java 26/Maven/PostgreSQL builds, security scans, and deployments. GitHub Actions Workflows is an agent skill from Hack23/cia.

When should I use GitHub Actions Workflows?

GitHub Actions Workflows fits situations like: tasks that involve CI/CD; tasks that involve Security review.

How do I install GitHub Actions Workflows in Claude Code?

Run `npx skills add Hack23/cia --skill github-actions-workflows -a claude-code`. Or copy the skill folder (.github/skills/github-actions-workflows in Hack23/cia) into .claude/skills/github-actions-workflows in your project. Claude Code loads it when a task matches its description.

How do I install GitHub Actions Workflows in Codex?

Run `npx skills add Hack23/cia --skill github-actions-workflows -a codex`. Or copy the skill folder (.github/skills/github-actions-workflows in Hack23/cia) into .agents/skills/github-actions-workflows in your project. Codex loads it when a task matches its description.

Can I use GitHub Actions Workflows in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill github-actions-workflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-actions-workflows, .gemini/skills/github-actions-workflows, .github/skills/github-actions-workflows and .opencode/skills/github-actions-workflows in your project.

What does GitHub Actions Workflows need to run?

Going by SKILL.md and its folder, GitHub Actions Workflows needs credentials named SONAR_TOKEN, POSTGRES_PASSWORD and DB_PASSWORD. Our summary lists: Node.js; A credential in SONAR_TOKEN.

Does GitHub Actions Workflows access the network?

SKILL.md names 3 domains. As links in the text: docs.github.com, slsa.dev and securityscorecards.dev. This is read from the text; nothing was executed.

Is GitHub Actions Workflows safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does GitHub Actions Workflows use?

GitHub Actions Workflows is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitHub Actions Workflows use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to GitHub Actions Workflows?

Skills that share tags, products or a category with GitHub Actions Workflows: Secure GitHub Actions (vechain/x-app-template, 450 stars), Code Patterns (Aedelon/claude-code-blueprint, 120 stars), Cicd Pipeline (revfactory/harness-100, 1.3k stars) and Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitHub Actions Workflows?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.