CI/CD Pipeline Principles
irahardianto/awesome-agv
Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.
Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe.
$ npx skills add mistralai/mistral-vibe --skill vibe-ci-supply-chain -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mistralai/mistral-vibe vibe-ci-supply-chain --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mistralai/mistral-vibe.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/vibe-ci-supply-chain .claude/skills/vibe-ci-supply-chain && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vibe-ci-supply-chain" agent skill from https://github.com/mistralai/mistral-vibe/tree/main/.agents/skills/vibe-ci-supply-chain into .claude/skills/vibe-ci-supply-chain/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vibe-ci-supply-chain", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mistralai/mistral-vibe/tree/main/.agents/skills/vibe-ci-supply-chainType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mistralai/mistral-vibe --skill vibe-ci-supply-chain -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mistralai/mistral-vibe vibe-ci-supply-chain --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mistralai/mistral-vibe.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/vibe-ci-supply-chain .agents/skills/vibe-ci-supply-chain && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vibe-ci-supply-chain" agent skill from https://github.com/mistralai/mistral-vibe/tree/main/.agents/skills/vibe-ci-supply-chain into .agents/skills/vibe-ci-supply-chain/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vibe-ci-supply-chain", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mistralai/mistral-vibe --skill vibe-ci-supply-chain -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mistralai/mistral-vibe vibe-ci-supply-chain --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mistralai/mistral-vibe.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/vibe-ci-supply-chain .cursor/skills/vibe-ci-supply-chain && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vibe-ci-supply-chain" agent skill from https://github.com/mistralai/mistral-vibe/tree/main/.agents/skills/vibe-ci-supply-chain into .cursor/skills/vibe-ci-supply-chain/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vibe-ci-supply-chain", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mistralai/mistral-vibe.git --path .agents/skills/vibe-ci-supply-chain--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mistralai/mistral-vibe --skill vibe-ci-supply-chain -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mistralai/mistral-vibe vibe-ci-supply-chain --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mistralai/mistral-vibe.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/vibe-ci-supply-chain .gemini/skills/vibe-ci-supply-chain && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vibe-ci-supply-chain" agent skill from https://github.com/mistralai/mistral-vibe/tree/main/.agents/skills/vibe-ci-supply-chain into .gemini/skills/vibe-ci-supply-chain/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vibe-ci-supply-chain", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mistralai/mistral-vibe vibe-ci-supply-chainInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mistralai/mistral-vibe --skill vibe-ci-supply-chain -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mistralai/mistral-vibe.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/vibe-ci-supply-chain .github/skills/vibe-ci-supply-chain && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vibe-ci-supply-chain" agent skill from https://github.com/mistralai/mistral-vibe/tree/main/.agents/skills/vibe-ci-supply-chain into .github/skills/vibe-ci-supply-chain/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vibe-ci-supply-chain", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mistralai/mistral-vibe --skill vibe-ci-supply-chain -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mistralai/mistral-vibe vibe-ci-supply-chain --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mistralai/mistral-vibe.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/vibe-ci-supply-chain .opencode/skills/vibe-ci-supply-chain && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vibe-ci-supply-chain" agent skill from https://github.com/mistralai/mistral-vibe/tree/main/.agents/skills/vibe-ci-supply-chain into .opencode/skills/vibe-ci-supply-chain/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vibe-ci-supply-chain", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vibe-ci-supply-chainGit workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe.
Vibe CI Supply Chain is an agent skill from mistralai/mistral-vibe, published by the product's own GitHub organization. Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe. Use when changing CI pipelines, GitHub Actions, dependency pinning, container images, pre-commit hooks, git workflow, or external binary downloads.
Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Supply chain security, CI/CD and Git workflow. It works with Mistral AI, GitHub Actions and Git. The repository describes itself as: Minimal CLI coding agent by Mistral. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 4ae5c59. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gituvghcurlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, uv, gh and curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vibe CI Supply Chain loads about 1k tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 484 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from mistralai/mistral-vibe at commit 4ae5c59, republished under its Apache-2.0 licence (© mistralai). 484 words, ~1,010 tokens.
.claude/skills/vibe-ci-supply-chain/SKILL.md (or your agent's skills folder).Conventions for git workflow, CI configuration, and supply-chain security in Vibe.
CI gates cold-start module count via vibe/scripts/check_startup_import_cost.py (budgets in vibe/scripts/startup_import_cost.vibe.toml).
import vibe or from vibe.cli.textual_ui.app import VibeApp, run cd vibe && uv run scripts/check_startup_import_cost.py and confirm the count stays within budget.git commit --amend, git push --force, or git push --force-with-lease.git push.origin/<current-branch> advanced): rebase the current branch onto its upstream — do not merge the upstream branch into the current one, never force-push.origin/main) once the PR is open: merge the base branch into the current branch — do not rebase, since rebasing rewrites already-pushed history and would require a force-push.uv run (e.g. uv run git commit, uv run git push) so pre-commit hooks resolve the project's venv — bare git commit fails pre-commit with reportMissingImports because pyright can't find third-party packages.uses: to a full commit SHA with an exact version comment: uses: owner/action@<commit-sha> # vX.Y.Z.refs/tags/vX^{} line from git ls-remote --tags, or gh api repos/<owner>/<repo>/git/refs/tags/<tag> --jq .object peeled to a commit. Check with git cat-file -t <sha> → commit, not tag. Never pin a moving major tag (v9).Every external input to the build, CI, or install path must be pinned to an immutable identifier — never a mutable tag or an unverified download. Add a human-readable comment next to each pin.
@sha256:<digest>, never a bare tag (:latest, :8). Resolve the digest via the registry's Docker-Content-Digest header (curl -sI -H 'Accept: application/vnd.oci.image.index.v1+json' <registry>/v2/<repo>/manifests/<tag>). When the image lives inside a JSON matrix string, document the tag→digest mapping in an adjacent comment..pre-commit-config.yaml): pin every rev: to a full commit SHA with a # vX.Y.Z comment. Run pre-commit autoupdate --freeze to refresh, and resolve to the peeled commit ref (refs/tags/vX^{}), not the annotated-tag object — same rule as uses: above.pyproject.toml [build-system] requires): pin hatchling, hatch-vcs, editables (and any addition) to exact == versions. These execute during source builds and are not covered by uv.lock.patchelf in scripts/ci/): never pipe an unverified download straight into tar/sh. Download to a temp file, verify sha256sum -c against a known-good hash keyed by version (and arch when relevant), then extract. Hard-fail when no hash is registered for the requested version/arch so a bump forces updating the hash.© mistralai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/vibe-ci-supply-chain of mistralai/mistral-vibe.
Open the folder on GitHubat commit 4ae5c59
Vibe CI Supply Chain next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vibe CI Supply Chain this skillmistralai/mistral-vibe | 5.1k | — | ~1k | Automated safety check: Pass | Apache-2.0 | |
| CI/CD Pipeline Principlesirahardianto/awesome-agv | 156 | — | ~2.7k | Automated safety check: Notes | MIT | |
| Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~818 | Automated safety check: Pass | Apache-2.0 | |
| Devops Automationrohitg00/awesome-claude-code-toolkit | 2.7k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| Update Depsstella/stella | 258 | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Pypi ReleasealchemiststudiosDOTai/tunacode | 125 | — | ~2.2k | Automated safety check: Pass | MIT |
irahardianto/awesome-agv
Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.
mukul975/Anthropic-Cybersecurity-Skills
Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…
rohitg00/awesome-claude-code-toolkit
CI/CD pipeline design with GitHub Actions, Docker, Kubernetes, Helm, and GitOps patterns
stella/stella
Inventory, assess, update, and validate third-party dependencies across Bun, Python/uv, Cargo, Docker, and GitHub Actions without hiding ecosystem or supply-chain risk.
alchemiststudiosDOTai/tunacode
This skill should be used when releasing tunacode-cli to PyPI.
klaudworks/universal-skills
Releases an npm package by committing changes, bumping the version with npm version, pushing the tag and checking the GitHub Actions publish.
mistralai/mistral-vibe
Shows how to build a Vibe plugin package in the Agent Plugins 1.0 format, with a plugin.json manifest and optional skills, MCP servers, hooks and other components.
mistralai/mistral-vibe
Guides feature work in the Mistral Vibe Python CLI so each change lands in the right module and matches the project's architecture decision records.
mistralai/mistral-vibe
Plans which analytics events and properties a new feature needs, checks them against the existing event registry, and verifies them per environment.
mistralai/mistral-vibe
Creates, reuses and cleans up git worktrees under a shared vibe home directory, with per-repo buckets, claim records and dirty-state checks before removal.
mistralai/mistral-vibe
Creates or updates concise Architecture Decision Records for the Mistral Vibe CLI and registers each one in the AGENTS.md decisions table.
mistralai/mistral-vibe
Guides writing or refactoring tests for the Mistral Vibe CLI agent so they check behavior through stable boundaries, like tool invocation or saved session shape, instead of internal calls.
Works with
Categories
Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe. Vibe CI Supply Chain is an agent skill from mistralai/mistral-vibe, published by the product's own GitHub organization. Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe.
Vibe CI Supply Chain fits situations like: changing CI pipelines; dependency pinning; container images; pre-commit hooks.
Run `npx skills add mistralai/mistral-vibe --skill vibe-ci-supply-chain -a claude-code`. Or copy the skill folder (.agents/skills/vibe-ci-supply-chain in mistralai/mistral-vibe) into .claude/skills/vibe-ci-supply-chain in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mistralai/mistral-vibe --skill vibe-ci-supply-chain -a codex`. Or copy the skill folder (.agents/skills/vibe-ci-supply-chain in mistralai/mistral-vibe) into .agents/skills/vibe-ci-supply-chain in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mistralai/mistral-vibe --skill vibe-ci-supply-chain -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vibe-ci-supply-chain, .gemini/skills/vibe-ci-supply-chain, .github/skills/vibe-ci-supply-chain and .opencode/skills/vibe-ci-supply-chain in your project.
Going by SKILL.md and its folder, Vibe CI Supply Chain needs the command-line tools its instructions call (git, uv, gh and curl). Our summary lists: Docker.
SKILL.md contains no URLs. Its commands use git, uv, gh and curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Vibe CI Supply Chain is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1k tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Vibe CI Supply Chain: CI/CD Pipeline Principles (irahardianto/awesome-agv, 156 stars), Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Devops Automation (rohitg00/awesome-claude-code-toolkit, 2.7k stars) and Update Deps (stella/stella, 258 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mistralai (a GitHub organization, an official publisher) maintains it in mistralai/mistral-vibe, which has 5,087 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 9, 2026.
Source: mistralai/mistral-vibe on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.