Agent skill

Probe Workflow

by kdeldycke in kdeldycke/dotfiles

Validate a claim about real-host behavior with a temporary GitHub Actions workflow.

BSD-2-ClauseAuto-check: notesDevOps & Cloud

Install Probe Workflow

skills CLI
$ npx skills add kdeldycke/dotfiles --skill probe-workflow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kdeldycke/dotfiles probe-workflow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kdeldycke/dotfiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/dotfiles/.agents/skills/probe-workflow .claude/skills/probe-workflow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
probe-workflow
GitHub stars
173
Token cost
~2k tokens
SKILL.md length
1,172 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
BSD-2-Clause

At a glance

Validate a claim about real-host behavior with a temporary GitHub Actions workflow.

  • Works in 5 steps: Push. The paths: trigger starts the run. → Watch with a single-pipeline poll: until… → Read gh run view --log-failed first, the… → …
  • Local tests and mocks cannot answer how a tool
  • SKILL.md covers Invocation, Ground rules, Measure before asserting and Runner facts that cost a…, plus 2 more sections
  • Calls gh, git and bash

What it does

Probe Workflow is an agent skill from kdeldycke/dotfiles. Validate a claim about real-host behavior with a temporary GitHub Actions workflow. Measure the environment, iterate on hard assertion gates, then move each finding where it belongs and retire the workflow. Use when local tests and mocks cannot answer how a tool, platform, container or privilege boundary actually behaves.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code. Recommended model: Opus.

It sits in DevOps & Cloud, covering CI/CD. It works with GitHub Actions. The repository describes itself as: 🍎 macOS dotfiles for Python developers. The licence is BSD-2-Clause.

When your agent uses it

  • Local tests and mocks cannot answer how a tool
  • Privilege boundary actually behaves

Example prompts

  • “/probe-workflow”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code. Recommended model: Opus.

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Push. The paths: trigger starts the run.
  2. Watch with a single-pipeline poll: until gh api "repos///actions/workflows//runs?head_sha=" --jq '.workflow_runs[] | select(.status ==…
  3. Read gh run view --log-failed first, the full --log when the failed step's cause sits in an earlier step's output.
  4. Diagnose from measurement, fix exactly one thing, commit with a subject naming the lesson, push again.
  5. A failing gate can indict the probe's staging or the code under test. When raw commands succeed where the code fails, the probe has found…

What it can do on your machine

Read from SKILL.md and the folder at commit 7947d0f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git
    • bash
    • uv
    • python
    • apk

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, git and uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code. Recommended model: Opus.

    From compatibility in the SKILL.md frontmatter.

Context cost

Probe Workflow loads about 2k tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 1,172 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:44
    permissive ACL that children inherit: a `sudo mkdir` there is world-writable until `chmod 0755` plus `setfacl -b`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kdeldycke/dotfiles at commit 7947d0f, republished under its BSD-2-Clause licence (© kdeldycke). 1,172 words, ~1,976 tokens.

Download SKILL.mdSave it as .claude/skills/probe-workflow/SKILL.md (or your agent's skills folder).
name
probe-workflow
description
Validate a claim about real-host behavior with a temporary GitHub Actions workflow. Measure the environment, iterate on hard assertion gates, then move each finding where it belongs and retire the workflow. Use when local tests and mocks cannot answer how a tool, platform, container or privilege boundary actually behaves.
compatibility
Designed for Claude Code. Recommended model: Opus.

Probe real-host behavior with a temporary workflow

A probe is a throwaway GitHub Actions workflow that answers one question about the real world: what a third-party CLI actually prints, how a privilege boundary actually behaves, what a container or another OS actually ships. It exists because a unit test asserts what you believe, while a probe measures what is true. The lifecycle is fixed: write, push, read, iterate, then move each finding where it belongs and delete the probe. A probe that lingers becomes CI cost with no question left to answer.

Reach for one when:

  • Code must match a tool's real output or error wordings, and the tool does not run on the development machine (another OS, another distro, a musl container, a privileged path).
  • A feature's flagship scenario has only ever run against mocks or a stand-in host.
  • A CI failure depends on runner-image state that local reproduction cannot fake (preinstalled tools, filesystem ACLs, service accounts).

Do not reach for one when a local test, a container run on the development machine, or reading the tool's source answers the question faster.

Invocation

The loop commits and pushes on every iteration. Get the user's explicit go-ahead for autonomous commit/push/run/cancel cycles before starting, or run under --dangerously-skip-permissions in a trusted checkout. Confirm which branch to push to: these repositories key workflow concurrency on the ref, so pushing to the default branch supersedes cleanly while a side branch queues alongside it. A probe living on a side branch cannot be started with gh workflow run, which only dispatches a workflow file present on the default branch (HTTP 404: workflow ... not found on the default branch): give it a push trigger on its own branch instead, and let each push start it.

Ground rules

  • Mark it temporary in line one. The workflow's first comment says TEMPORARY probe workflow, to be deleted once <question> is answered. Name the file <subject>-probe.yaml.
  • Trigger on push with a paths: filter covering the workflow file AND the code under test. A probe validating mymodule.py must re-run when mymodule.py changes, or code iterations silently test nothing.
  • Cooldown rules apply. Installs from live registries carry the repository's cooldown (UV_EXCLUDE_NEWER, NPM_CONFIG_MIN_RELEASE_AGE in the workflow env:); distro archives (apt-get, apk) are out of scope by design. Pin actions by SHA and tools by version, copied from an existing workflow.
  • Hard gates, not eyeballs. Every claim becomes a grep -q (or test -e, exit-code check) against captured output: command > out.txt 2>&1 || true then grep. A step that only prints is a diagnostic, not a validation, and belongs in the run only while a question is open.
  • Negative gates too. Assert the behavior does NOT fire where it must not (if grep -q ...; then exit 1; fi), or the probe proves half the contract.

Measure before asserting

When an assertion fails and more than one theory explains it, do not fix the theory: add a measurement step and push again. Print the state the theories disagree about (ls -la the directory, run the raw command as each user, cat the config), read the numbers, then write the fix. Guessing costs a full runner round-trip per guess; measuring costs one round-trip total. Record each lesson as a comment beside the step that hit it, so retirement can route every one to its lasting home.

Two shell traps recur in measurement steps:

  • GitHub's default shell is bash -e: a step written to capture a failure dies at the failing command instead. Set shell: bash {0} on diagnostic steps, or suffix || true on every command whose non-zero exit is the datum.
  • Steps run as root in container jobs. Behavior gated on privilege (escalation, ownership, per-user config) needs a created unprivileged user, with scripts handed over via su <user> -s /bin/sh /path/script.sh and HOME set explicitly inside the script.
Show full SKILL.md (540 more words)Show less

Runner facts that cost a round-trip each

Measured on hosted ubuntu-26.04 runners and alpine:edge containers, 2026-08. Re-verify before relying on them: runner images churn.

  • /opt carries setgid, sticky and a permissive ACL that children inherit: a sudo mkdir there is world-writable until chmod 0755 plus setfacl -b.
  • sudo resets HOME, so an escalated tool reads root's own configuration, not the invoking user's: a per-user config set before escalating silently does not apply.
  • uv sync venvs ship no pip: the venv python shadowing PATH breaks anything probing python -m pip.
  • JavaScript actions (actions/checkout, astral-sh/setup-uv) are glibc-linked and die in musl containers: inside Alpine, fetch the exact SHA with git clone + git fetch origin "$GITHUB_SHA" and install tooling with apk add.
  • Container base images ship no package index: run the package manager's index refresh before any search or install can see the catalog.
  • Hosted macos-26, measured 2026-09-17: tell application X to quit launches an app that is not running, so a probe relaunching an app quits it only if application X is running and polls pgrep -x X before the next open. The screen comes up 1024 wide, and macOS hides the status items that do not fit beside the front app's menus, so raise the display (CGConfigureDisplayWithDisplayMode) before measuring the menu bar.

The iteration loop

  1. Push. The paths: trigger starts the run.
  2. Watch with a single-pipeline poll: until gh api "repos/<OWNER>/<REPO>/actions/workflows/<file>/runs?head_sha=<FULL_SHA>" --jq '.workflow_runs[] | select(.status == "completed") | "DONE " + .conclusion' | grep DONE; do sleep 20; done. Multi-step shell in background watchers (variables, set --, paste) fails silently; one pipeline per tick is the shape that survives. Read runs through the API, never gh run list: both its forms have put runs weeks old at the top of the list. Give head_sha the full 40-character SHA, since an abbreviated one matches nothing and returns an empty list that looks identical to "nothing ran", and quote the whole path, since zsh expands the ? as a glob.
  3. Read gh run view <id> --log-failed first, the full --log when the failed step's cause sits in an earlier step's output.
  4. Diagnose from measurement, fix exactly one thing, commit with a subject naming the lesson, push again.
  5. A failing gate can indict the probe's staging or the code under test. When raw commands succeed where the code fails, the probe has found a real bug: fix it in the codebase with its own tests and changelog entry, and let the probe re-validate.

Retirement

Delete the workflow the moment every gate is green:

  • Route each finding to its lasting home before the delete, and treat that placement as the durable record: a real-output fixture into the test corpus, an environment quirk into a comment beside the code that works around it, a measured number into the docstring whose claim rests on it, a user-facing fix into the changelog. The probe itself must hold nothing that still matters.
  • The retirement commit is then a subject line naming the question it answered, not a write-up. A finding that reaches only git log is lost to every reader who never runs it.
  • If a scenario deserves permanent coverage, that is a new decision with a cost: propose a schedule-only job to the user rather than quietly keeping the probe alive.

© kdeldycke, BSD-2-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in dotfiles/.agents/skills/probe-workflow of kdeldycke/dotfiles.

Open the folder on GitHubat commit 7947d0f

Compare with similar skills

Probe Workflow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Probe Workflow compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Probe Workflow this skillkdeldycke/dotfiles173—~2kAutomated safety check: NotesBSD-2-Clause
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
GitHub Actions Templatesbartstc/vite-ts-react-template12214 repos~1.9kAutomated safety check: PassMIT
Nushellccusage/ccusage19k—~938Automated safety check: PassCustom licence
Repo Hygiene Scan and FixQwenLM/qwen-code28k—~1.7kAutomated safety check: PassApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence

Similar skills

  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • GitHub Actions Templates

    bartstc/vite-ts-react-template

    Create production-ready GitHub Actions workflows for automated testing, building, and deploying applications.

    122 GitHub starsUsed in 14 repos~1.9k tokens
    DevOps & CloudAuto-check passed
  • Nushell

    ccusage/ccusage

    Guides ccusage Nushell scripts. An agent skill from ccusage/ccusage.

    19k GitHub stars~938 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Scheduled CI skill that scans a repository for small, certain docs, test and code hygiene issues and fixes them on one branch with a commit per finding.

    28k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • CI Failure Triage and Repair

    Chachamaru127/claude-code-harness

    Diagnoses failing CI pipelines and tests, deciding first whether the test or the implementation is at fault, and hands hard cases to a dedicated fixer subagent.

    3.2k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check: notes

More from kdeldycke/dotfiles

All 25 skills in this repo
  • Agent Config Self Tune

    kdeldycke/dotfiles

    Audit and tune the configuration of coding agents across Claude Code and pi - settings files (settings.json, settings.local.json), permission rules, instruction files (CLAUDE.md, AGENTS.md), skill…

    173 GitHub stars~3.4k tokensUpdated 4 days ago
    Auto-check: notes
  • Audit Repo Issues

    kdeldycke/dotfiles

    Analyze a GitHub repository's issues and PRs to find unaddressed feature requests, dismissed ideas, maintenance signals, and opportunities relevant to the current project.

    173 GitHub stars~2.5k tokensUpdated 4 days ago
    Auto-check passed
  • Brand Assets

    kdeldycke/dotfiles

    Create project logo and banner SVGs, then export them to light and dark PNG variants.

    173 GitHub stars~4.7k tokensUpdated 4 days ago
    Auto-check passed
  • Fill Web Form

    kdeldycke/dotfiles

    Fill a web form using data extracted from local documents (PDFs, images, spreadsheets).

    173 GitHub stars~2.3k tokensUpdated 4 days ago
    Auto-check passed
  • Rename With Dates

    kdeldycke/dotfiles

    Rename documents and files (PDFs, images, screenshots, etc.) by reading their content to extract the effective/publication date, then renaming them with a "YYYY-MM-DD - Clear descriptive title.ext"…

    173 GitHub stars~3.5k tokensUpdated 4 days ago
    Auto-check passed
  • Repomatic Test Matrix

    kdeldycke/dotfiles

    Choose what a repository's CI test matrix covers. An agent skill from kdeldycke/dotfiles.

    173 GitHub stars~2.2k tokensUpdated 4 days ago
    Auto-check: notes

Works with

Categories

Questions about Probe Workflow

What does Probe Workflow do?

Validate a claim about real-host behavior with a temporary GitHub Actions workflow. Probe Workflow is an agent skill from kdeldycke/dotfiles. Validate a claim about real-host behavior with a temporary GitHub Actions workflow.

When should I use Probe Workflow?

Probe Workflow fits situations like: local tests and mocks cannot answer how a tool; privilege boundary actually behaves.

How do I install Probe Workflow in Claude Code?

Run `npx skills add kdeldycke/dotfiles --skill probe-workflow -a claude-code`. Or copy the skill folder (dotfiles/.agents/skills/probe-workflow in kdeldycke/dotfiles) into .claude/skills/probe-workflow in your project. Claude Code loads it when a task matches its description.

How do I install Probe Workflow in Codex?

Run `npx skills add kdeldycke/dotfiles --skill probe-workflow -a codex`. Or copy the skill folder (dotfiles/.agents/skills/probe-workflow in kdeldycke/dotfiles) into .agents/skills/probe-workflow in your project. Codex loads it when a task matches its description.

Can I use Probe Workflow in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kdeldycke/dotfiles --skill probe-workflow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/probe-workflow, .gemini/skills/probe-workflow, .github/skills/probe-workflow and .opencode/skills/probe-workflow in your project.

What does Probe Workflow need to run?

Going by SKILL.md and its folder, Probe Workflow needs the command-line tools its instructions call (gh, git, bash, uv, python and apk). Our summary lists: Python 3. Compatibility (from SKILL.md): Designed for Claude Code. Recommended model: Opus..

Does Probe Workflow access the network?

SKILL.md contains no URLs. Its commands use gh, git and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Probe Workflow safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Probe Workflow use?

Probe Workflow is published under the BSD-2-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Probe Workflow use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Probe Workflow?

Skills that share tags, products or a category with Probe Workflow: Analyze GitHub Action Logs (withastro/astro, 63k stars), GitHub Actions Templates (bartstc/vite-ts-react-template, 122 stars), Nushell (ccusage/ccusage, 19k stars) and Repo Hygiene Scan and Fix (QwenLM/qwen-code, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Probe Workflow?

kdeldycke (a GitHub user) maintains it in kdeldycke/dotfiles, which has 173 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on October 4, 2026.

Source: kdeldycke/dotfiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.