Official agent skill

Vibe CI Supply Chain

by mistralai in mistralai/mistral-vibe

Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Vibe CI Supply Chain

skills CLI
$ npx skills add mistralai/mistral-vibe --skill vibe-ci-supply-chain -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mistralai/mistral-vibe vibe-ci-supply-chain --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mistralai/mistral-vibe.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/vibe-ci-supply-chain .claude/skills/vibe-ci-supply-chain && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vibe-ci-supply-chain
GitHub stars
5.1k
Token cost
~1k tokens
SKILL.md length
484 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
Apache-2.0

At a glance

Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe.

  • Changing CI pipelines
  • SKILL.md covers Startup import cost, Git, CI / GitHub Actions and Supply-chain pinning
  • Calls git, uv and gh
  • Dependency pinning

What it does

Vibe CI Supply Chain is an agent skill from mistralai/mistral-vibe, published by the product's own GitHub organization. Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe. Use when changing CI pipelines, GitHub Actions, dependency pinning, container images, pre-commit hooks, git workflow, or external binary downloads.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Supply chain security, CI/CD and Git workflow. It works with Mistral AI, GitHub Actions and Git. The repository describes itself as: Minimal CLI coding agent by Mistral. The licence is Apache-2.0.

When your agent uses it

  • Changing CI pipelines
  • Dependency pinning
  • Container images
  • Pre-commit hooks

Example prompts

  • “/vibe-ci-supply-chain”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 4ae5c59. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • uv
    • gh
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, uv, gh and curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vibe CI Supply Chain loads about 1k tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 484 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mistralai/mistral-vibe at commit 4ae5c59, republished under its Apache-2.0 licence (© mistralai). 484 words, ~1,010 tokens.

Download SKILL.mdSave it as .claude/skills/vibe-ci-supply-chain/SKILL.md (or your agent's skills folder).
name
vibe-ci-supply-chain
description
Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe. Use when changing CI pipelines, GitHub Actions, dependency pinning, container images, pre-commit hooks, git workflow, or external binary downloads.
metadata.display-name
Vibe CI & Supply Chain
metadata.short-description
Git, CI, and supply-chain pinning for Vibe
metadata.default-prompt
Use $vibe-ci-supply-chain to follow Vibe git, CI, and supply-chain conventions.

Vibe CI & Supply Chain

Conventions for git workflow, CI configuration, and supply-chain security in Vibe.

Startup import cost

CI gates cold-start module count via vibe/scripts/check_startup_import_cost.py (budgets in vibe/scripts/startup_import_cost.vibe.toml).

  • When a change touches imports or module structure on the path of import vibe or from vibe.cli.textual_ui.app import VibeApp, run cd vibe && uv run scripts/check_startup_import_cost.py and confirm the count stays within budget.
  • Verify, do not bump. An overshoot is a regression to investigate (lazy import, drop the dependency, defer the import) — not a reason to raise the budget. Only widen for a deliberate, PR-justified increase, and set to observed count + ~10% headroom, never the exact count.

Git

  • Never use git commit --amend, git push --force, or git push --force-with-lease.
  • Always create new commits and push with a plain git push.
  • Reconciling with the upstream of the current branch (e.g. push rejected because origin/<current-branch> advanced): rebase the current branch onto its upstream — do not merge the upstream branch into the current one, never force-push.
  • Reconciling with the base branch (e.g. origin/main) once the PR is open: merge the base branch into the current branch — do not rebase, since rebasing rewrites already-pushed history and would require a force-push.
  • Run git commands through uv run (e.g. uv run git commit, uv run git push) so pre-commit hooks resolve the project's venv — bare git commit fails pre-commit with reportMissingImports because pyright can't find third-party packages.

CI / GitHub Actions

  • Pin every uses: to a full commit SHA with an exact version comment: uses: owner/action@<commit-sha> # vX.Y.Z.
  • Resolve to the commit, not the annotated-tag object: take the refs/tags/vX^{} line from git ls-remote --tags, or gh api repos/<owner>/<repo>/git/refs/tags/<tag> --jq .object peeled to a commit. Check with git cat-file -t <sha> → commit, not tag. Never pin a moving major tag (v9).
Show full SKILL.md (194 more words)Show less

Supply-chain pinning

Every external input to the build, CI, or install path must be pinned to an immutable identifier — never a mutable tag or an unverified download. Add a human-readable comment next to each pin.

  • Container images: reference by @sha256:<digest>, never a bare tag (:latest, :8). Resolve the digest via the registry's Docker-Content-Digest header (curl -sI -H 'Accept: application/vnd.oci.image.index.v1+json' <registry>/v2/<repo>/manifests/<tag>). When the image lives inside a JSON matrix string, document the tag→digest mapping in an adjacent comment.
  • pre-commit hooks (.pre-commit-config.yaml): pin every rev: to a full commit SHA with a # vX.Y.Z comment. Run pre-commit autoupdate --freeze to refresh, and resolve to the peeled commit ref (refs/tags/vX^{}), not the annotated-tag object — same rule as uses: above.
  • Build-system deps (pyproject.toml [build-system] requires): pin hatchling, hatch-vcs, editables (and any addition) to exact == versions. These execute during source builds and are not covered by uv.lock.
  • External binary downloads (e.g. patchelf in scripts/ci/): never pipe an unverified download straight into tar/sh. Download to a temp file, verify sha256sum -c against a known-good hash keyed by version (and arch when relevant), then extract. Hard-fail when no hash is registered for the requested version/arch so a bump forces updating the hash.

© mistralai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/vibe-ci-supply-chain of mistralai/mistral-vibe.

Open the folder on GitHubat commit 4ae5c59

Compare with similar skills

Vibe CI Supply Chain next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vibe CI Supply Chain compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vibe CI Supply Chain this skillmistralai/mistral-vibe5.1k—~1kAutomated safety check: PassApache-2.0
CI/CD Pipeline Principlesirahardianto/awesome-agv156—~2.7kAutomated safety check: NotesMIT
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Devops Automationrohitg00/awesome-claude-code-toolkit2.7k—~1.6kAutomated safety check: PassApache-2.0
Update Depsstella/stella258—~2.7kAutomated safety check: PassApache-2.0
Pypi ReleasealchemiststudiosDOTai/tunacode125—~2.2kAutomated safety check: PassMIT

Similar skills

  • CI/CD Pipeline Principles

    irahardianto/awesome-agv

    Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

    156 GitHub stars~2.7k tokensUpdated 6 days ago
    DevOps & CloudAuto-check: notes
  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Devops Automation

    rohitg00/awesome-claude-code-toolkit

    CI/CD pipeline design with GitHub Actions, Docker, Kubernetes, Helm, and GitOps patterns

    2.7k GitHub stars~1.6k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check passed
  • Update Deps

    stella/stella

    Inventory, assess, update, and validate third-party dependencies across Bun, Python/uv, Cargo, Docker, and GitHub Actions without hiding ecosystem or supply-chain risk.

    258 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Pypi Release

    alchemiststudiosDOTai/tunacode

    This skill should be used when releasing tunacode-cli to PyPI.

    125 GitHub stars~2.2k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • npm Package Publisher

    klaudworks/universal-skills

    Releases an npm package by committing changes, bumping the version with npm version, pushing the tag and checking the GitHub Actions publish.

    181 GitHub stars~923 tokensUpdated 9 mo ago
    DevelopmentAuto-check passed

More from mistralai/mistral-vibe

All 15 skills in this repo
  • Mistral Vibe Plugin Creator

    mistralai/mistral-vibe

    Official

    Shows how to build a Vibe plugin package in the Agent Plugins 1.0 format, with a plugin.json manifest and optional skills, MCP servers, hooks and other components.

    5.1k GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • Create Vibe Feature

    mistralai/mistral-vibe

    Official

    Guides feature work in the Mistral Vibe Python CLI so each change lands in the right module and matches the project's architecture decision records.

    5.1k GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Official

    Plans which analytics events and properties a new feature needs, checks them against the existing event registry, and verifies them per environment.

    5.1k GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Vibe Worktree Manager

    mistralai/mistral-vibe

    Official

    Creates, reuses and cleans up git worktrees under a shared vibe home directory, with per-repo buckets, claim records and dirty-state checks before removal.

    5.1k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Write Vibe ADR

    mistralai/mistral-vibe

    Official

    Creates or updates concise Architecture Decision Records for the Mistral Vibe CLI and registers each one in the AGENTS.md decisions table.

    5.1k GitHub stars~942 tokensUpdated yesterday
    Auto-check passed
  • Write Vibe Tests

    mistralai/mistral-vibe

    Official

    Guides writing or refactoring tests for the Mistral Vibe CLI agent so they check behavior through stable boundaries, like tool invocation or saved session shape, instead of internal calls.

    5.1k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Questions about Vibe CI Supply Chain

What does Vibe CI Supply Chain do?

Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe. Vibe CI Supply Chain is an agent skill from mistralai/mistral-vibe, published by the product's own GitHub organization. Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe.

When should I use Vibe CI Supply Chain?

Vibe CI Supply Chain fits situations like: changing CI pipelines; dependency pinning; container images; pre-commit hooks.

How do I install Vibe CI Supply Chain in Claude Code?

Run `npx skills add mistralai/mistral-vibe --skill vibe-ci-supply-chain -a claude-code`. Or copy the skill folder (.agents/skills/vibe-ci-supply-chain in mistralai/mistral-vibe) into .claude/skills/vibe-ci-supply-chain in your project. Claude Code loads it when a task matches its description.

How do I install Vibe CI Supply Chain in Codex?

Run `npx skills add mistralai/mistral-vibe --skill vibe-ci-supply-chain -a codex`. Or copy the skill folder (.agents/skills/vibe-ci-supply-chain in mistralai/mistral-vibe) into .agents/skills/vibe-ci-supply-chain in your project. Codex loads it when a task matches its description.

Can I use Vibe CI Supply Chain in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mistralai/mistral-vibe --skill vibe-ci-supply-chain -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vibe-ci-supply-chain, .gemini/skills/vibe-ci-supply-chain, .github/skills/vibe-ci-supply-chain and .opencode/skills/vibe-ci-supply-chain in your project.

What does Vibe CI Supply Chain need to run?

Going by SKILL.md and its folder, Vibe CI Supply Chain needs the command-line tools its instructions call (git, uv, gh and curl). Our summary lists: Docker.

Does Vibe CI Supply Chain access the network?

SKILL.md contains no URLs. Its commands use git, uv, gh and curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Vibe CI Supply Chain safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vibe CI Supply Chain use?

Vibe CI Supply Chain is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vibe CI Supply Chain use?

About 1k tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vibe CI Supply Chain?

Skills that share tags, products or a category with Vibe CI Supply Chain: CI/CD Pipeline Principles (irahardianto/awesome-agv, 156 stars), Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Devops Automation (rohitg00/awesome-claude-code-toolkit, 2.7k stars) and Update Deps (stella/stella, 258 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vibe CI Supply Chain?

mistralai (a GitHub organization, an official publisher) maintains it in mistralai/mistral-vibe, which has 5,087 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 9, 2026.

Source: mistralai/mistral-vibe on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.