Agent skill

GitHub Agentic Workflows

by Hack23 in Hack23/cia

Master GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support

Apache-2.0Auto-check passedDevOps & Cloud

Install GitHub Agentic Workflows

skills CLI
$ npx skills add Hack23/cia --skill github-agentic-workflows -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia github-agentic-workflows --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/github-agentic-workflows .claude/skills/github-agentic-workflows && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
github-agentic-workflows
GitHub stars
239
Token cost
~3.8k tokens
SKILL.md length
1,051 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Master GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support

  • Works in 4 steps: Plan: /plan command decomposes issue… → Execute: Copilot Coding Agent works on… → Review: PR review workflow validates… → …
  • DevOps & Cloud work in your project
  • SKILL.md covers Purpose, When to Use, Architecture & Security Layers and Workflow Structure, plus 11 more sections
  • Calls gh; reaches github.com; needs BRAVE_API_KEY

What it does

GitHub Agentic Workflows is an agent skill from Hack23/cia. Master GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with GitHub and GitHub Actions. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/github-agentic-workflows”

Requirements

  • Python 3
  • Node.js
  • A credential in BRAVE_API_KEY

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Plan: /plan command decomposes issue into sub-tasks
  2. Execute: Copilot Coding Agent works on each sub-task
  3. Review: PR review workflow validates changes
  4. Merge: Human approves and merges

What it can do on your machine

Read from SKILL.md and the folder at commit bbed538. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • github.github.com
    • githubnext.com
    • github.blog
    • genai.owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • BRAVE_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GitHub Agentic Workflows loads about 3.8k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 1,051 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit bbed538, republished under its Apache-2.0 licence (© Hack23). 1,051 words, ~3,763 tokens.

Download SKILL.mdSave it as .claude/skills/github-agentic-workflows/SKILL.md (or your agent's skills folder).
name
github-agentic-workflows
description
Master GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support
license
Apache-2.0

GitHub Agentic Workflows Skill

Purpose

Guide creation, deployment, and governance of GitHub Agentic Workflows (gh-aw) — markdown-defined AI automations that run inside GitHub Actions with defense-in-depth security. Developed by GitHub Next and Microsoft Research, they augment deterministic CI/CD with Continuous AI capabilities.

When to Use

  • ✅ AI-driven issue triage, PR review, documentation maintenance, code quality improvement
  • ✅ Multi-agent orchestration with specialized workers
  • ✅ Scheduled/event-driven repository analysis and reporting
  • ✅ Continuous improvement workflows (code simplification, security scanning, metrics)
  • ❌ Simple deterministic shell-script automation (use traditional GitHub Actions)
  • ❌ Operations requiring 100% predictable execution paths

Architecture & Security Layers

GitHub Agentic Workflows enforce five security layers:

LayerMechanismEffect
Read-only tokensAgent receives read-only GitHub tokenCannot push, create PRs, or delete files
Zero secretsWrite tokens never enter agent processCompromised agent has nothing to steal
Container + FirewallAgent Workflow Firewall (AWF) with Squid proxy allowlistBlocks exfiltration to unapproved domains
Safe outputsStructured artifact → gated write jobAgent proposes; separate job with scoped permissions executes
Threat detectionAI-powered scan before output is appliedBlocks prompt injection, leaked credentials, malicious code
Event → [Sandboxed Agent (read-only, firewalled)] → Proposed Output (artifact)
  → Threat Detection (AI scan) → ✓ Safe → Write Job (scoped token) → GitHub API
                                → ✗ Suspicious → Blocked

Workflow Structure

Every workflow is a markdown file with YAML frontmatter + natural language body:

markdown
---
on:
  schedule: daily          # or: issue, pull_request, discussion, workflow_dispatch, etc.
timeout-minutes: 10
permissions:
  contents: read
  issues: read
tools:
  github:
    toolsets: [issues, pull_requests, repos]
safe-outputs:
  create-issue:
    title-prefix: "[report] "
    labels: [automated, daily]
    max: 1
    close-older-issues: true
---

# Daily Repository Status Report

Analyze recent activity and create a summary issue.

## Instructions
- Review open issues, merged PRs, and recent commits
- Highlight blockers and achievements
- Provide actionable next steps for maintainers

The gh aw compile CLI generates a .lock.yml GitHub Actions workflow from this markdown.

AI Engines

EngineKeyNotes
GitHub Copilotcopilot (default)Best general-purpose agent
Claude (Anthropic)claudeStrong for analysis and NLP tasks
OpenAI CodexcodexCode-focused tasks
Google GeminigeminiMulti-modal capabilities

Set engine in frontmatter: engine: claude

Triggers (on:)

TriggerSyntaxUse Case
Scheduleschedule: daily, schedule: "0 9 * * 1-5"Periodic reports, scans
Issue eventsissue: types: [opened, reopened]Triage, auto-labeling
PR eventspull_request: types: [opened, synchronize]Code review, checks
Discussiondiscussion: types: [created]Task mining, Q&A
Dispatchworkflow_dispatch:Manual trigger
Commentissue_comment: types: [created]Slash commands (/plan, /review)

Tools Configuration

GitHub Tools (MCP-based)
yaml
tools:
  github:
    toolsets: [issues, pull_requests, repos, code_search, actions, security]
    min-integrity: approved   # or: none (for public repos processing external contributors)

Available toolsets: issues, pull_requests, repos, code_search, actions, security, labels, discussions, projects, users, notifications, stars, gists

Custom MCP Servers
yaml
tools:
  mcp:
    brave-search:
      command: npx -y @anthropic/mcp-brave-search
      env:
        BRAVE_API_KEY: ${{ secrets.BRAVE_API_KEY }}
Integrity Filtering

Controls which users' content the agent can see. Critical for public repositories:

LevelWho Is VisibleUse When
approved (default)Owners, members, collaboratorsMost workflows
noneAll contributorsIssue triage in public repos

Safe Outputs

Safe outputs are the only way agents write to GitHub. Each type has hard constraints:

Issue Operations
yaml
safe-outputs:
  create-issue:
    title-prefix: "[auto] "    # Required prefix (prevents impersonation)
    labels: [automated]         # Allowed labels only
    max: 3                      # Hard limit per run
    close-older-issues: true    # Auto-close previous issues with same prefix
  add-labels:
    allowed: [bug, feature, enhancement, documentation, question]
  add-comment: {}               # Allow commenting on issues
PR Operations
yaml
safe-outputs:
  create-pull-request:
    title-prefix: "[auto] "
    max: 1
    branch-prefix: "auto/"
    labels: [automated]
    draft: true                 # Create as draft PR
  add-review-comment: {}
Discussion Operations
yaml
safe-outputs:
  create-discussion:
    category: "Reports"
    title-prefix: "[daily] "
    max: 1
    close-older-discussions: true

Permissions (Least Privilege)

yaml
permissions:
  contents: read          # Repository content (always read-only for agent)
  issues: read            # Issue data access
  pull-requests: read     # PR data access
  discussions: read       # Discussion access
  actions: read           # Workflow run data
  security-events: read   # Code scanning alerts

Write permissions are never granted to the agent — only to the safe output write job.

Network Permissions

Control outbound access from the agent container:

yaml
network:
  allowed-domains:
    - "api.github.com"
    - "*.githubusercontent.com"
    - "pypi.org"           # For Python package installs

All other domains are blocked by the AWF firewall.

Compilation & Deployment

bash
# Install CLI
gh extension install github/gh-aw

# Add workflow from gallery
gh aw add-wizard https://github.com/github/gh-aw/blob/v0.45.5/.github/workflows/issue-triage-agent.md

# Compile markdown to lock file
gh aw compile

# Compile specific workflow
gh aw compile .github/workflows/my-workflow.md

# List workflows
gh aw list

# Validate without compiling
gh aw validate .github/workflows/my-workflow.md

The .lock.yml file is the actual GitHub Actions workflow. Never edit it directly — always edit the .md source and recompile.

Issue & PR Management
  • Issue Triage Agent — Auto-label and comment on new issues
  • PR Triage Agent — Categorize and assign PRs
  • Plan Command (/plan) — Decompose issues into sub-tasks
  • Auto-Assign Issue — Route issues to appropriate team members
Continuous Improvement
  • Code Simplifier — Daily complexity reduction
  • Repository Quality Improver — Holistic code quality analysis
  • Code Refiner — Systematic refactoring suggestions
  • Dead Code Removal Agent — Find and remove unused code
Documentation & Reporting
  • Daily Issues Report — Team status summaries
  • Documentation Healer — Fix stale docs and broken links
  • Architecture Diagram Generator — Auto-generate C4/Mermaid diagrams
  • Discussion Task Miner — Extract actionable tasks from discussions
Security & Quality
  • Code Scanning Fixer — Auto-fix CodeQL/SAST findings
  • Security Review Agent (/security) — On-demand security analysis
  • CI Failure Doctor — Diagnose and suggest fixes for CI failures
  • Malicious Code Scan — Daily security sweeps
  • Breaking Change Checker — Detect API breaking changes
Metrics & Analytics
  • Copilot Session Insights — ML analysis of agent behavior
  • Prompt Clustering Analysis — Categorize agent prompts using ML
  • Workflow Health Manager — Monitor agent success rates and costs
Multi-Repository
  • Organization Health Report — Cross-repo analysis
  • Feature Sync — Coordinate changes across repositories

Real-World Example: CIA Platform Issue Triage

markdown
---
on:
  issue:
    types: [opened, reopened]
timeout-minutes: 5
permissions:
  contents: read
  issues: read
tools:
  github:
    toolsets: [issues, repos, code_search]
    min-integrity: none
safe-outputs:
  add-labels:
    allowed: [bug, enhancement, documentation, security, performance, ui, data-integration]
  add-comment: {}
---

# CIA Platform Issue Triage

Analyze new issues for the Citizen Intelligence Agency platform.

## Context
This is a Java/Spring/Vaadin political intelligence platform monitoring Swedish parliament data.

## Instructions
1. Read the issue title and body carefully
2. Search the codebase for related files and patterns
3. Apply the most appropriate label from the allowed set
4. Comment with:
   - Brief analysis of the issue
   - Relevant code areas (module, package, class)
   - Suggested approach for resolution
   - Related issues if any exist

## Label Criteria
- `bug` — Incorrect behavior, crashes, data errors
- `enhancement` — New features or improvements
- `security` — Security vulnerabilities or hardening
- `performance` — Speed, memory, query optimization
- `ui` — Vaadin UI/UX improvements
- `data-integration` — External API or data pipeline issues
- `documentation` — Docs updates needed

Real-World Example: Daily Security Scan

markdown
---
on:
  schedule: "0 8 * * 1-5"
timeout-minutes: 15
permissions:
  contents: read
  security-events: read
  issues: read
tools:
  github:
    toolsets: [repos, security, issues, code_search]
safe-outputs:
  create-issue:
    title-prefix: "[security-scan] "
    labels: [security, automated]
    max: 1
    close-older-issues: true
---

# Daily Security Scan Report

Analyze repository security posture and create a summary.

## Instructions
1. Check code scanning alerts (CodeQL, Dependabot)
2. Review dependency vulnerabilities
3. Assess OWASP Top 10 exposure
4. Create a prioritized issue with findings and remediation steps
5. Reference ISO 27001, NIST CSF controls where applicable

Orchestration Patterns

Single Agent (Simple)

One workflow, one task. Best for focused automation.

Show full SKILL.md (426 more words)Show less
Handoff Pattern

Agent A completes work, creates artifact → Agent B picks up and continues.

Reflection Pattern

Agent produces output → same or different agent reviews it → iterates until quality threshold met.

Plan-Execute Pattern (Most Powerful)
  1. Plan: /plan command decomposes issue into sub-tasks
  2. Execute: Copilot Coding Agent works on each sub-task
  3. Review: PR review workflow validates changes
  4. Merge: Human approves and merges

Labels and Organization

yaml
safe-outputs:
  add-labels:
    allowed: [agentic-workflow, automated, needs-review]

Use consistent label prefixes to track agentic work across the repository.

CLI Quick Reference

CommandDescription
gh aw compileCompile all .md workflows to .lock.yml
gh aw compile <file>Compile specific workflow
gh aw listList all workflows and their status
gh aw validateValidate workflow syntax
gh aw add-wizard <url>Add workflow from gallery
gh aw run <workflow>Trigger workflow manually
gh aw logs <run-id>View workflow run logs

Testing Workflows

  1. Validate syntax: gh aw validate .github/workflows/my-workflow.md
  2. Compile: gh aw compile .github/workflows/my-workflow.md
  3. Dry run: Trigger with workflow_dispatch on a test branch
  4. Monitor: Check Actions tab for run status and logs
  5. Review outputs: Verify safe output constraints were respected
  6. Iterate: Refine instructions based on agent behavior

Integration with Hack23 ISMS

Applicable Controls
ControlImplementation
ISO 27001 A.8.8Change management via PR review of workflow changes
ISO 27001 A.8.15Logging via GitHub Actions audit logs
ISO 27001 A.9.4.1Access restriction via permissions and safe outputs
NIST CSF PR.AC-4Least privilege via read-only agent permissions
CIS Control 2.7Privileged access management via safe output jobs
NIST CSF DE.CMContinuous monitoring via scheduled security workflows
Documentation Requirements
  • Update WORKFLOWS.md when adding/modifying agentic workflows
  • Update SECURITY_ARCHITECTURE.md if workflows access security data
  • Update THREAT_MODEL.md for new attack surfaces from agentic automation
  • Track workflow costs and success rates in operational reviews

OWASP Agentic Security (Top 10 2026)

RiskMitigation in gh-aw
AG01 - Prompt InjectionRead-only tokens + threat detection scan
AG02 - Tool MisuseScoped toolsets, no write permissions in agent
AG03 - Insecure OutputSafe outputs with hard limits and prefix constraints
AG04 - Data ExfiltrationAWF firewall with domain allowlist
AG05 - Excessive PermissionsLeast-privilege permissions model
AG06 - Memory PoisoningStateless per-run execution, no persistent memory
AG07 - Supply ChainPinned action versions, locked dependencies
AG08 - Credential TheftZero secrets in agent process
AG09 - Denial of ServiceTimeout limits, max output constraints
AG10 - Insufficient MonitoringActions audit logs, workflow health monitoring

References

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/github-agentic-workflows of Hack23/cia.

Open the folder on GitHubat commit bbed538

Compare with similar skills

GitHub Agentic Workflows next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitHub Agentic Workflows compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitHub Agentic Workflows this skillHack23/cia239—~3.8kAutomated safety check: PassApache-2.0
Sicurezza GitHubccplugins/awesome-claude-code-plugins968—~486Automated safety check: NotesApache-2.0
Released-kimuson/claude-code-viewer1.3k—~1.2kAutomated safety check: PassMIT
GitHub Actions Supply Chain Pinningasyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.0
npm Release Via GitHub Actionsjmfederico/pi-web866—~2.9kAutomated safety check: PassMIT
CI/CD Failure Troubleshootingruby-git/ruby-git1.8k—~1.9kAutomated safety check: PassMIT

Similar skills

  • Sicurezza GitHub

    ccplugins/awesome-claude-code-plugins

    Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot.

    968 GitHub stars~486 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Release

    d-kimuson/claude-code-viewer

    Run the claude-code-viewer release flow end-to-end. An agent skill from d-kimuson/claude-code-viewer.

    1.3k GitHub stars~1.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

    1.1k GitHub stars~1.9k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • A skill your agent uses whenever the user asks for a new npm version, npm release, package release, new release, version bump, publishing to npm, cutting a GitHub release, tagging a release, or…

    866 GitHub stars~2.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Diagnoses and fixes failing GitHub Actions runs by identifying the failure, fetching only the relevant logs, finding the root cause and reproducing it locally.

    1.8k GitHub stars~1.9k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Secure GitHub Actions

    vechain/x-app-template

    Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.

    450 GitHub stars~1.2k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Questions about GitHub Agentic Workflows

What does GitHub Agentic Workflows do?

Master GitHub Agentic Workflows (gh-aw) - AI-powered repository automation with safe outputs, sandboxed execution, and multi-engine support. GitHub Agentic Workflows is an agent skill from Hack23/cia.

When should I use GitHub Agentic Workflows?

GitHub Agentic Workflows fits situations like: devOps & Cloud work in your project.

How do I install GitHub Agentic Workflows in Claude Code?

Run `npx skills add Hack23/cia --skill github-agentic-workflows -a claude-code`. Or copy the skill folder (.github/skills/github-agentic-workflows in Hack23/cia) into .claude/skills/github-agentic-workflows in your project. Claude Code loads it when a task matches its description.

How do I install GitHub Agentic Workflows in Codex?

Run `npx skills add Hack23/cia --skill github-agentic-workflows -a codex`. Or copy the skill folder (.github/skills/github-agentic-workflows in Hack23/cia) into .agents/skills/github-agentic-workflows in your project. Codex loads it when a task matches its description.

Can I use GitHub Agentic Workflows in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill github-agentic-workflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-agentic-workflows, .gemini/skills/github-agentic-workflows, .github/skills/github-agentic-workflows and .opencode/skills/github-agentic-workflows in your project.

What does GitHub Agentic Workflows need to run?

Going by SKILL.md and its folder, GitHub Agentic Workflows needs the command-line tools its instructions call (gh) and credentials named BRAVE_API_KEY. Our summary lists: Python 3; Node.js; A credential in BRAVE_API_KEY.

Does GitHub Agentic Workflows access the network?

SKILL.md names 5 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: github.github.com, githubnext.com, github.blog and genai.owasp.org. This is read from the text; nothing was executed.

Is GitHub Agentic Workflows safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does GitHub Agentic Workflows use?

GitHub Agentic Workflows is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitHub Agentic Workflows use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to GitHub Agentic Workflows?

Skills that share tags, products or a category with GitHub Agentic Workflows: Sicurezza GitHub (ccplugins/awesome-claude-code-plugins, 968 stars), Release (d-kimuson/claude-code-viewer, 1.3k stars), GitHub Actions Supply Chain Pinning (asyncapi/generator, 1.1k stars) and npm Release Via GitHub Actions (jmfederico/pi-web, 866 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitHub Agentic Workflows?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 7, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.