Sicurezza GitHub
ccplugins/awesome-claude-code-plugins
Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot.
Master GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support
$ npx skills add Hack23/cia --skill github-agentic-workflows -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Hack23/cia github-agentic-workflows --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/github-agentic-workflows .claude/skills/github-agentic-workflows && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "github-agentic-workflows" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/github-agentic-workflows into .claude/skills/github-agentic-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-agentic-workflows", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Hack23/cia/tree/master/.github/skills/github-agentic-workflowsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Hack23/cia --skill github-agentic-workflows -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Hack23/cia github-agentic-workflows --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/github-agentic-workflows .agents/skills/github-agentic-workflows && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "github-agentic-workflows" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/github-agentic-workflows into .agents/skills/github-agentic-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-agentic-workflows", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Hack23/cia --skill github-agentic-workflows -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Hack23/cia github-agentic-workflows --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/github-agentic-workflows .cursor/skills/github-agentic-workflows && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "github-agentic-workflows" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/github-agentic-workflows into .cursor/skills/github-agentic-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-agentic-workflows", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Hack23/cia.git --path .github/skills/github-agentic-workflows--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Hack23/cia --skill github-agentic-workflows -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Hack23/cia github-agentic-workflows --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/github-agentic-workflows .gemini/skills/github-agentic-workflows && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "github-agentic-workflows" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/github-agentic-workflows into .gemini/skills/github-agentic-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-agentic-workflows", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Hack23/cia github-agentic-workflowsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Hack23/cia --skill github-agentic-workflows -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/github-agentic-workflows .github/skills/github-agentic-workflows && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "github-agentic-workflows" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/github-agentic-workflows into .github/skills/github-agentic-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-agentic-workflows", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Hack23/cia --skill github-agentic-workflows -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Hack23/cia github-agentic-workflows --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/github-agentic-workflows .opencode/skills/github-agentic-workflows && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "github-agentic-workflows" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/github-agentic-workflows into .opencode/skills/github-agentic-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-agentic-workflows", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
github-agentic-workflowsMaster GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support
GitHub Agentic Workflows is an agent skill from Hack23/cia. Master GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud. It works with GitHub and GitHub Actions. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bbed538. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comAlso links to:
github.github.comgithubnext.comgithub.bloggenai.owasp.orgFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
BRAVE_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
GitHub Agentic Workflows loads about 3.8k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 1,051 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Hack23/cia at commit bbed538, republished under its Apache-2.0 licence (© Hack23). 1,051 words, ~3,763 tokens.
.claude/skills/github-agentic-workflows/SKILL.md (or your agent's skills folder).Guide creation, deployment, and governance of GitHub Agentic Workflows (gh-aw) — markdown-defined AI automations that run inside GitHub Actions with defense-in-depth security. Developed by GitHub Next and Microsoft Research, they augment deterministic CI/CD with Continuous AI capabilities.
GitHub Agentic Workflows enforce five security layers:
| Layer | Mechanism | Effect |
|---|---|---|
| Read-only tokens | Agent receives read-only GitHub token | Cannot push, create PRs, or delete files |
| Zero secrets | Write tokens never enter agent process | Compromised agent has nothing to steal |
| Container + Firewall | Agent Workflow Firewall (AWF) with Squid proxy allowlist | Blocks exfiltration to unapproved domains |
| Safe outputs | Structured artifact → gated write job | Agent proposes; separate job with scoped permissions executes |
| Threat detection | AI-powered scan before output is applied | Blocks prompt injection, leaked credentials, malicious code |
Event → [Sandboxed Agent (read-only, firewalled)] → Proposed Output (artifact)
→ Threat Detection (AI scan) → ✓ Safe → Write Job (scoped token) → GitHub API
→ ✗ Suspicious → BlockedEvery workflow is a markdown file with YAML frontmatter + natural language body:
---
on:
schedule: daily # or: issue, pull_request, discussion, workflow_dispatch, etc.
timeout-minutes: 10
permissions:
contents: read
issues: read
tools:
github:
toolsets: [issues, pull_requests, repos]
safe-outputs:
create-issue:
title-prefix: "[report] "
labels: [automated, daily]
max: 1
close-older-issues: true
---
# Daily Repository Status Report
Analyze recent activity and create a summary issue.
## Instructions
- Review open issues, merged PRs, and recent commits
- Highlight blockers and achievements
- Provide actionable next steps for maintainersThe gh aw compile CLI generates a .lock.yml GitHub Actions workflow from this markdown.
| Engine | Key | Notes |
|---|---|---|
| GitHub Copilot | copilot (default) | Best general-purpose agent |
| Claude (Anthropic) | claude | Strong for analysis and NLP tasks |
| OpenAI Codex | codex | Code-focused tasks |
| Google Gemini | gemini | Multi-modal capabilities |
Set engine in frontmatter: engine: claude
on:)| Trigger | Syntax | Use Case |
|---|---|---|
| Schedule | schedule: daily, schedule: "0 9 * * 1-5" | Periodic reports, scans |
| Issue events | issue: types: [opened, reopened] | Triage, auto-labeling |
| PR events | pull_request: types: [opened, synchronize] | Code review, checks |
| Discussion | discussion: types: [created] | Task mining, Q&A |
| Dispatch | workflow_dispatch: | Manual trigger |
| Comment | issue_comment: types: [created] | Slash commands (/plan, /review) |
tools:
github:
toolsets: [issues, pull_requests, repos, code_search, actions, security]
min-integrity: approved # or: none (for public repos processing external contributors)Available toolsets: issues, pull_requests, repos, code_search, actions, security, labels, discussions, projects, users, notifications, stars, gists
tools:
mcp:
brave-search:
command: npx -y @anthropic/mcp-brave-search
env:
BRAVE_API_KEY: ${{ secrets.BRAVE_API_KEY }}Controls which users' content the agent can see. Critical for public repositories:
| Level | Who Is Visible | Use When |
|---|---|---|
approved (default) | Owners, members, collaborators | Most workflows |
none | All contributors | Issue triage in public repos |
Safe outputs are the only way agents write to GitHub. Each type has hard constraints:
safe-outputs:
create-issue:
title-prefix: "[auto] " # Required prefix (prevents impersonation)
labels: [automated] # Allowed labels only
max: 3 # Hard limit per run
close-older-issues: true # Auto-close previous issues with same prefix
add-labels:
allowed: [bug, feature, enhancement, documentation, question]
add-comment: {} # Allow commenting on issuessafe-outputs:
create-pull-request:
title-prefix: "[auto] "
max: 1
branch-prefix: "auto/"
labels: [automated]
draft: true # Create as draft PR
add-review-comment: {}safe-outputs:
create-discussion:
category: "Reports"
title-prefix: "[daily] "
max: 1
close-older-discussions: truepermissions:
contents: read # Repository content (always read-only for agent)
issues: read # Issue data access
pull-requests: read # PR data access
discussions: read # Discussion access
actions: read # Workflow run data
security-events: read # Code scanning alertsWrite permissions are never granted to the agent — only to the safe output write job.
Control outbound access from the agent container:
network:
allowed-domains:
- "api.github.com"
- "*.githubusercontent.com"
- "pypi.org" # For Python package installsAll other domains are blocked by the AWF firewall.
# Install CLI
gh extension install github/gh-aw
# Add workflow from gallery
gh aw add-wizard https://github.com/github/gh-aw/blob/v0.45.5/.github/workflows/issue-triage-agent.md
# Compile markdown to lock file
gh aw compile
# Compile specific workflow
gh aw compile .github/workflows/my-workflow.md
# List workflows
gh aw list
# Validate without compiling
gh aw validate .github/workflows/my-workflow.mdThe .lock.yml file is the actual GitHub Actions workflow. Never edit it directly — always edit the .md source and recompile.
/plan) — Decompose issues into sub-tasks/security) — On-demand security analysis---
on:
issue:
types: [opened, reopened]
timeout-minutes: 5
permissions:
contents: read
issues: read
tools:
github:
toolsets: [issues, repos, code_search]
min-integrity: none
safe-outputs:
add-labels:
allowed: [bug, enhancement, documentation, security, performance, ui, data-integration]
add-comment: {}
---
# CIA Platform Issue Triage
Analyze new issues for the Citizen Intelligence Agency platform.
## Context
This is a Java/Spring/Vaadin political intelligence platform monitoring Swedish parliament data.
## Instructions
1. Read the issue title and body carefully
2. Search the codebase for related files and patterns
3. Apply the most appropriate label from the allowed set
4. Comment with:
- Brief analysis of the issue
- Relevant code areas (module, package, class)
- Suggested approach for resolution
- Related issues if any exist
## Label Criteria
- `bug` — Incorrect behavior, crashes, data errors
- `enhancement` — New features or improvements
- `security` — Security vulnerabilities or hardening
- `performance` — Speed, memory, query optimization
- `ui` — Vaadin UI/UX improvements
- `data-integration` — External API or data pipeline issues
- `documentation` — Docs updates needed---
on:
schedule: "0 8 * * 1-5"
timeout-minutes: 15
permissions:
contents: read
security-events: read
issues: read
tools:
github:
toolsets: [repos, security, issues, code_search]
safe-outputs:
create-issue:
title-prefix: "[security-scan] "
labels: [security, automated]
max: 1
close-older-issues: true
---
# Daily Security Scan Report
Analyze repository security posture and create a summary.
## Instructions
1. Check code scanning alerts (CodeQL, Dependabot)
2. Review dependency vulnerabilities
3. Assess OWASP Top 10 exposure
4. Create a prioritized issue with findings and remediation steps
5. Reference ISO 27001, NIST CSF controls where applicableOne workflow, one task. Best for focused automation.
Agent A completes work, creates artifact → Agent B picks up and continues.
Agent produces output → same or different agent reviews it → iterates until quality threshold met.
/plan command decomposes issue into sub-taskssafe-outputs:
add-labels:
allowed: [agentic-workflow, automated, needs-review]Use consistent label prefixes to track agentic work across the repository.
| Command | Description |
|---|---|
gh aw compile | Compile all .md workflows to .lock.yml |
gh aw compile <file> | Compile specific workflow |
gh aw list | List all workflows and their status |
gh aw validate | Validate workflow syntax |
gh aw add-wizard <url> | Add workflow from gallery |
gh aw run <workflow> | Trigger workflow manually |
gh aw logs <run-id> | View workflow run logs |
gh aw validate .github/workflows/my-workflow.mdgh aw compile .github/workflows/my-workflow.mdworkflow_dispatch on a test branch| Control | Implementation |
|---|---|
| ISO 27001 A.8.8 | Change management via PR review of workflow changes |
| ISO 27001 A.8.15 | Logging via GitHub Actions audit logs |
| ISO 27001 A.9.4.1 | Access restriction via permissions and safe outputs |
| NIST CSF PR.AC-4 | Least privilege via read-only agent permissions |
| CIS Control 2.7 | Privileged access management via safe output jobs |
| NIST CSF DE.CM | Continuous monitoring via scheduled security workflows |
WORKFLOWS.md when adding/modifying agentic workflowsSECURITY_ARCHITECTURE.md if workflows access security dataTHREAT_MODEL.md for new attack surfaces from agentic automation| Risk | Mitigation in gh-aw |
|---|---|
| AG01 - Prompt Injection | Read-only tokens + threat detection scan |
| AG02 - Tool Misuse | Scoped toolsets, no write permissions in agent |
| AG03 - Insecure Output | Safe outputs with hard limits and prefix constraints |
| AG04 - Data Exfiltration | AWF firewall with domain allowlist |
| AG05 - Excessive Permissions | Least-privilege permissions model |
| AG06 - Memory Poisoning | Stateless per-run execution, no persistent memory |
| AG07 - Supply Chain | Pinned action versions, locked dependencies |
| AG08 - Credential Theft | Zero secrets in agent process |
| AG09 - Denial of Service | Timeout limits, max output constraints |
| AG10 - Insufficient Monitoring | Actions audit logs, workflow health monitoring |
© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/github-agentic-workflows of Hack23/cia.
Open the folder on GitHubat commit bbed538
GitHub Agentic Workflows next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| GitHub Agentic Workflows this skillHack23/cia | 239 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | |
| Sicurezza GitHubccplugins/awesome-claude-code-plugins | 968 | — | ~486 | Automated safety check: Notes | Apache-2.0 | |
| Released-kimuson/claude-code-viewer | 1.3k | — | ~1.2k | Automated safety check: Pass | MIT | |
| GitHub Actions Supply Chain Pinningasyncapi/generator | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| npm Release Via GitHub Actionsjmfederico/pi-web | 866 | — | ~2.9k | Automated safety check: Pass | MIT | |
| CI/CD Failure Troubleshootingruby-git/ruby-git | 1.8k | — | ~1.9k | Automated safety check: Pass | MIT |
ccplugins/awesome-claude-code-plugins
Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot.
d-kimuson/claude-code-viewer
Run the claude-code-viewer release flow end-to-end. An agent skill from d-kimuson/claude-code-viewer.
asyncapi/generator
A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).
jmfederico/pi-web
A skill your agent uses whenever the user asks for a new npm version, npm release, package release, new release, version bump, publishing to npm, cutting a GitHub release, tagging a release, or…
ruby-git/ruby-git
Diagnoses and fixes failing GitHub Actions runs by identifying the failure, fetching only the relevant logs, finding the root cause and reproducing it locally.
vechain/x-app-template
Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.
Hack23/cia
WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms
Hack23/cia
Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis
Hack23/cia
AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents
Hack23/cia
External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs
Hack23/cia
AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform
Hack23/cia
AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment
Works with
Categories
Master GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support. GitHub Agentic Workflows is an agent skill from Hack23/cia.
GitHub Agentic Workflows fits situations like: devOps & Cloud work in your project.
Run `npx skills add Hack23/cia --skill github-agentic-workflows -a claude-code`. Or copy the skill folder (.github/skills/github-agentic-workflows in Hack23/cia) into .claude/skills/github-agentic-workflows in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Hack23/cia --skill github-agentic-workflows -a codex`. Or copy the skill folder (.github/skills/github-agentic-workflows in Hack23/cia) into .agents/skills/github-agentic-workflows in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill github-agentic-workflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-agentic-workflows, .gemini/skills/github-agentic-workflows, .github/skills/github-agentic-workflows and .opencode/skills/github-agentic-workflows in your project.
Going by SKILL.md and its folder, GitHub Agentic Workflows needs the command-line tools its instructions call (gh) and credentials named BRAVE_API_KEY. Our summary lists: Python 3; Node.js; A credential in BRAVE_API_KEY.
SKILL.md names 5 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: github.github.com, githubnext.com, github.blog and genai.owasp.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
GitHub Agentic Workflows is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with GitHub Agentic Workflows: Sicurezza GitHub (ccplugins/awesome-claude-code-plugins, 968 stars), Release (d-kimuson/claude-code-viewer, 1.3k stars), GitHub Actions Supply Chain Pinning (asyncapi/generator, 1.1k stars) and npm Release Via GitHub Actions (jmfederico/pi-web, 866 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 7, 2026.
Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.