Megalinter Check
nvuillam/npm-groovy-lint
Collect MegaLinter lint errors for the current repository. An agent skill from nvuillam/npm-groovy-lint.
Generate CI pipeline files and check scripts (GitHub Actions, GitLab, CircleCI, Bitbucket) that automate design system checks: token validation, hardcoded values, a11y scans, visual regression…
$ npx skills add murphytrueman/design-system-ops --skill cicd-integration -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install murphytrueman/design-system-ops cicd-integration --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/murphytrueman/design-system-ops.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cicd-integration .claude/skills/cicd-integration && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cicd-integration" agent skill from https://github.com/murphytrueman/design-system-ops/tree/main/skills/cicd-integration into .claude/skills/cicd-integration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cicd-integration", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/murphytrueman/design-system-ops/tree/main/skills/cicd-integrationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add murphytrueman/design-system-ops --skill cicd-integration -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install murphytrueman/design-system-ops cicd-integration --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/murphytrueman/design-system-ops.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cicd-integration .agents/skills/cicd-integration && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cicd-integration" agent skill from https://github.com/murphytrueman/design-system-ops/tree/main/skills/cicd-integration into .agents/skills/cicd-integration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cicd-integration", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add murphytrueman/design-system-ops --skill cicd-integration -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install murphytrueman/design-system-ops cicd-integration --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/murphytrueman/design-system-ops.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cicd-integration .cursor/skills/cicd-integration && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cicd-integration" agent skill from https://github.com/murphytrueman/design-system-ops/tree/main/skills/cicd-integration into .cursor/skills/cicd-integration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cicd-integration", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/murphytrueman/design-system-ops.git --path skills/cicd-integration--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add murphytrueman/design-system-ops --skill cicd-integration -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install murphytrueman/design-system-ops cicd-integration --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/murphytrueman/design-system-ops.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cicd-integration .gemini/skills/cicd-integration && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cicd-integration" agent skill from https://github.com/murphytrueman/design-system-ops/tree/main/skills/cicd-integration into .gemini/skills/cicd-integration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cicd-integration", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install murphytrueman/design-system-ops cicd-integrationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add murphytrueman/design-system-ops --skill cicd-integration -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/murphytrueman/design-system-ops.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cicd-integration .github/skills/cicd-integration && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cicd-integration" agent skill from https://github.com/murphytrueman/design-system-ops/tree/main/skills/cicd-integration into .github/skills/cicd-integration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cicd-integration", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add murphytrueman/design-system-ops --skill cicd-integration -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install murphytrueman/design-system-ops cicd-integration --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/murphytrueman/design-system-ops.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cicd-integration .opencode/skills/cicd-integration && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cicd-integration" agent skill from https://github.com/murphytrueman/design-system-ops/tree/main/skills/cicd-integration into .opencode/skills/cicd-integration/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cicd-integration", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cicd-integrationGenerate CI pipeline files and check scripts (GitHub Actions, GitLab, CircleCI, Bitbucket) that automate design system checks: token validation, hardcoded values, a11y scans, visual regression…
Cicd Integration is an agent skill from murphytrueman/design-system-ops. Generate CI pipeline files and check scripts (GitHub Actions, GitLab, CircleCI, Bitbucket) that automate design system checks: token validation, hardcoded values, a11y scans, visual regression, bundle size. Trigger: set up CI, quality gates, automate these checks. Not for running an audit.
Its SKILL.md is about 5.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering CI/CD. It works with GitHub Actions, Bitbucket and GitLab. The repository describes itself as: Claude Code skills for the work that keeps a design system alive. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit f167898. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteGrepGlobBash(cat:*)Bash(find:*)Bash(head:*)Bash(ls:*)Bash(sort:*)Bash(tail:*)…and 4 more on the same allowed-tools line.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxnpmtscgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx, npm and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
CHROMATIC_PROJECT_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cicd Integration loads about 5.4k tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 1,916 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from murphytrueman/design-system-ops at commit f167898, republished under its MIT licence (© murphytrueman). 1,916 words, ~5,419 tokens.
.claude/skills/cicd-integration/SKILL.md (or your agent's skills folder).A skill for generating pipeline configurations that automate the quality checks Design System Ops skills perform manually. This bridges the gap between "here are the problems the audit found" and "these problems can never recur because the pipeline catches them."
Output type: File creation. This skill produces pipeline configuration files (YAML), scripts, and documentation. It does not execute pipelines — it generates the configuration that teams add to their repository.
Confirm that every path in this skill's frontmatter references: exists relative to this SKILL.md. If any is missing, stop: the install is incomplete, usually because a flattening installer (for example npx skills install) dropped the repo-root knowledge-notes/ directory. Tell the user to reinstall by a method in 1-INSTALL.md and run verify-install.sh from the install root. Proceed without the references only if the user explicitly says to, and then say in the output that it was produced without the pack's reference material.
Every audit skill in Design System Ops finds problems. Some of those problems should never have reached a human reviewer because they are mechanically detectable: a hardcoded hex value in a component file, a token alias that references a non-existent token, a component export missing from the barrel file, an accessibility violation that an automated scanner would catch.
CI/CD Integration converts audit findings into automated pipeline checks. The goal is not to replace the audit skills — those handle nuance, context, and cross-skill synthesis that pipelines cannot. The goal is to automate the mechanical subset so that audits focus on the problems only humans can evaluate.
If .ds-ops-config.yml exists, follow the configuration-and-recurring knowledge note (../../knowledge-notes/configuration-and-recurring.md). This skill reads:
cicd:
platform: "github-actions" # github-actions, gitlab-ci, circleci, bitbucket
package_manager: "npm" # npm, yarn, pnpm
node_version: "22" # Node.js version (22 or 24; both LTS)
test_framework: "jest" # jest, vitest, playwright
component_library_path: "packages/components"
token_path: "packages/tokens"
monorepo: true # Whether the project uses a monorepo structure
triggers:
- "push to main"
- "pull request to main"If no configuration exists, ask for:
Before generating any pipeline configuration, determine which checks are worth automating. Not everything should be in CI.
| Check type | Automate in CI? | Why |
|---|---|---|
| Token naming violations | Yes | Mechanical — regex patterns, no judgment needed |
| Token circular references | Yes | Graph traversal — computers are better at this |
| Hardcoded colour values | Yes | grep/AST — exact match detection |
| Component prop type checking | Yes | TypeScript/Flow already does this |
| Accessibility (automated subset) | Yes | axe-core catches the machine-detectable subset of WCAG issues; keyboard and screen reader checks stay manual |
| Visual regression | Yes | Pixel comparison catches unintended changes |
| Component export completeness | Yes | AST/barrel file check |
| Bundle size tracking | Yes | Byte comparison — pure measurement |
| Token coverage gaps | Partial | Can check primitive→semantic mapping exists, cannot judge if mappings are correct |
| Component API consistency | Partial | Can lint prop naming patterns, cannot judge API design quality |
| Documentation completeness | Partial | Can check if docs exist, cannot judge if they are good |
| Cross-component pattern compliance | No | Requires too much context and judgment |
| Naming convention quality | No | Conventions need human validation first, then automation |
| Usage guideline adherence | No | Requires consuming-app context that CI rarely has |
If the skill's finding includes a specific, unambiguous rule (e.g., "tokens must use kebab-case", "no hex values outside token files"), it can be automated. If the finding requires judgment (e.g., "this token naming could be clearer"), it cannot.
For each audit finding category, determine the automated check:
| Finding category | Pipeline check | Tool |
|---|---|---|
| Naming violations | Lint token names against convention regex | Custom script or Style Dictionary validator |
| Circular references | Build-time alias resolution check | Style Dictionary build (fails on circular refs) |
| Orphaned tokens | Cross-reference token definitions with usage in component files | Custom script: grep token names across component source. Warn only — it can't see tokens consumed outside the repo (product apps, native platforms, Figma), so an "orphan" may be in use |
| Missing semantic tier | Check that every component token reference resolves through a semantic alias | Custom script or Style Dictionary referencing |
| DTCG format compliance | Validate token files against the 2025.10 format | npx terrazzo lint (DTCG-native), or a Style Dictionary 4 or 5 build with usesDtcg, which fails on broken references and bad shapes. There is no official DTCG JSON Schema to validate against |
| Hardcoded values in styles | Stylelint on colour, spacing and type properties; ESLint for Tailwind arbitrary values | stylelint-declaration-strict-value with the token pattern as ignoreValues; eslint-plugin-tailwindcss no-arbitrary-value. If governance-encoder has written this config, the step is npm run lint |
| Finding category | Pipeline check | Tool |
|---|---|---|
| Export completeness | Verify barrel file exports match component directories | Custom script: compare fs listing with exports |
| Prop type safety | TypeScript strict mode compilation | tsc --noEmit |
| Accessibility | Run axe-core on rendered components | @axe-core/cli, jest-axe, or Playwright + axe |
| Visual regression | Screenshot comparison against baselines | Chromatic, Percy, Playwright visual comparisons |
| Bundle size | Track and gate on component bundle sizes | size-limit, bundlesize, or custom webpack analysis |
| Finding category | Pipeline check | Tool |
|---|---|---|
| Existence | Check that each component directory has a README or docs file | Custom script: file existence check |
| Prop documentation | Check that JSDoc/TSDoc exists for all exported props | eslint-plugin-jsdoc or custom TSDoc validator |
| Storybook stories | Check that each component has at least one story file | Custom script: file pattern match |
Produce a workflow file: .github/workflows/design-system-checks.yml
Structure:
name: Design System Quality Checks
# No `paths:` filter here: if these jobs are required checks, a PR that
# doesn't touch the paths would leave them pending forever. The `changes`
# job decides what to run instead; skipped jobs count as passing.
on:
push:
branches: [main]
pull_request:
branches: [main]
permissions:
contents: read
pull-requests: read # lets the path filter list PR files
concurrency:
group: ds-checks-${{ github.ref }}
cancel-in-progress: true
jobs:
changes:
runs-on: ubuntu-latest
outputs:
tokens: ${{ steps.filter.outputs.tokens }}
components: ${{ steps.filter.outputs.components }}
steps:
- uses: actions/checkout@v7
- uses: dorny/paths-filter@v4
id: filter
with:
filters: |
tokens:
- 'packages/tokens/**'
components:
- 'packages/components/**'
- 'packages/tokens/**'
token-validation:
name: Token Validation
needs: changes
if: needs.changes.outputs.tokens == 'true'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version: '22'
cache: 'npm'
- run: npm ci
- name: Validate token naming
run: node scripts/ds-checks/validate-token-names.js
- name: Validate DTCG format and references
run: npx terrazzo lint # or: npx style-dictionary build --config tokens.config.js
- name: Detect orphaned tokens (warn only)
run: node scripts/ds-checks/find-orphaned-tokens.js
component-validation:
name: Component Validation
needs: [changes, token-validation]
if: ${{ !failure() && !cancelled() && needs.changes.outputs.components == 'true' }}
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version: '22'
cache: 'npm'
- run: npm ci
- name: TypeScript compilation
run: npx tsc --noEmit
- name: Hardcoded values in styles
run: npx stylelint "**/*.{css,scss}" --ignore-path .gitignore # declaration-strict-value config from governance-encoder
- name: Check export completeness
run: node scripts/ds-checks/verify-exports.js
- name: Accessibility scan
run: npm run test:a11y # prerequisite — see Step 3
- name: Bundle size check
run: npx size-limit # prerequisite — see Step 3
documentation-validation:
name: Documentation Validation
needs: changes
if: needs.changes.outputs.components == 'true'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version: '22'
cache: 'npm'
- run: npm ci
- name: Check component docs exist
run: node scripts/ds-checks/check-docs-exist.js
- name: Verify Storybook stories exist
run: node scripts/ds-checks/check-stories-exist.js
visual-regression:
name: Visual Regression
needs: changes
if: github.event_name == 'pull_request' && needs.changes.outputs.components == 'true'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0 # Chromatic needs git history for baselines
- uses: actions/setup-node@v7
with:
node-version: '22'
cache: 'npm'
- run: npm ci
- name: Build Storybook
run: npx storybook build --output-dir storybook-static
- name: Run visual regression
# Reuse the build above rather than letting Chromatic build Storybook again
run: npx chromatic --project-token=${{ secrets.CHROMATIC_PROJECT_TOKEN }} --storybook-build-dir=storybook-staticPin each action to its current major when you generate the file; the majors above were current when this skill was written. Use the Node version from cicd.node_version (22 or 24). dorny/paths-filter is a third-party action; if the team's policy disallows those, replace the changes job with a git diff --name-only step that sets the same outputs.
Blocking merges needs branch protection. A failing job only blocks a merge if the repository requires it. Tell the user to add the job names as required status checks under branch protection or a ruleset on main; the pipeline can't enforce this itself.
Generate the same job list as the GitHub workflow (token validation, component validation with the Stylelint step, documentation validation, visual regression on pull requests) in the platform's syntax; don't reduce the check list to fit a shorter template. Platform notes:
.gitlab-ci.yml): default.image: node:22, an npm cache keyed on package-lock.json, stages: [validate, visual], and rules with changes: on the token and component paths for merge-request pipelines. Set CHROMATIC_PROJECT_TOKEN as a masked variable. To block merges, enable "Pipelines must succeed" in the merge request settings..circleci/config.yml): a node executor on cimg/node:22.x, an install command with restore_cache/save_cache on package-lock.json, component-validation requiring token-validation. CircleCI has no built-in path filtering; add the path-filtering orb only if run time matters. Block merges with required status checks in the git host.bitbucket-pipelines.yml): image: node:22, step definitions reused under pipelines.pull-requests and pipelines.branches.main, condition: changesets: includePaths: to scope by path. Blocking merges needs a merge check requiring passing builds (a Premium feature on Bitbucket Cloud).Each pipeline check references a script. Generate the scripts in scripts/ds-checks/:
validate-token-names.js/**
* Validates token names against the configured naming convention.
* Exits with code 1 if violations are found.
*
* Generated by Design System Ops — cicd-integration
*/
const fs = require('fs');
const path = require('path');
// Configuration — adjust these to match your conventions
// A segment is lowercase letters and digits, optionally hyphenated:
// spacing.4, font-size.base, color.blue.500, color.action.primary-hover,
// button.background.hover all pass. 2–5 segments.
const SEGMENT = '[a-z0-9]+(?:-[a-z0-9]+)*';
const TOKEN_NAME = new RegExp(`^${SEGMENT}(?:\\.${SEGMENT}){1,4}$`);
// Tier comes from where a token is defined (file or set), not from how many
// segments its name has — spacing.4 and button.background.default can't be
// told apart by shape alone.
const TIER_BY_PATH = {
primitive: 'primitives/',
semantic: 'semantic/',
component: 'component/',
};
// Token file path — adjust to your project
const TOKEN_DIR = process.env.TOKEN_DIR || 'packages/tokens/src';
// [Full implementation: recursively read token files, assign each token
// a tier from TIER_BY_PATH, validate its name against TOKEN_NAME and any
// tier-specific rules, collect violations, read the threshold for
// `token-naming` from .ds-ops/quality-gates.yml, output violations, and
// exit 1 only if the count exceeds the threshold and block_merge is true]The block above is the header and configuration only; the generated file contains the implementation its comment describes. Provide complete, working implementations for each script. Include:
.ds-ops/quality-gates.yml (Step 4) via a shared helper, not hardcodedblock_merge: true is exceeded; otherwise 0, printing warnings (on GitHub, as ::warning:: lines so they show on the PR)validate-token-names.js — Regex-based token name validation (Style Dictionary doesn't validate names; Terrazzo's lint rules can, if the team is on Terrazzo, in which case skip this script)find-orphaned-tokens.js — Cross-reference token definitions with component usageverify-exports.js — Compare directory listing with barrel file exportscheck-docs-exist.js — Verify documentation files exist for each componentcheck-stories-exist.js — Verify Storybook story files exist for each componentread-gates.js — Shared helper that loads .ds-ops/quality-gates.yml and returns the threshold and block_merge flag for a gateDTCG validation and the hardcoded-value check are not scripts: they run Terrazzo or Style Dictionary, and Stylelint or ESLint, with the config the team has (or governance-encoder writes). Don't reimplement a linter in scripts/ds-checks/.
Two steps call tools the scripts above don't create. Generate them, or list them as prerequisites the team must add before the pipeline goes green:
stylelint-declaration-strict-value on the token-backed properties (and eslint-plugin-tailwindcss for Tailwind). Run governance-encoder to write it from the team's rules, or generate a minimal one here and say it's a starting point.test:a11y script in package.json — for example "test:a11y": "vitest run --project a11y" with jest-axe/vitest-axe tests, or "test:a11y": "test-storybook" with the Storybook test-runner and axe. Generate one example test per component type found.size-limit config — a .size-limit.json listing each entry point with a limit, plus size-limit and its preset (e.g. @size-limit/preset-small-lib) as dev dependencies.Produce a quality gate definition that the pipeline enforces on pull requests:
The scripts/ds-checks/ scripts read this file through read-gates.js. Checks run by other tools (Style Dictionary, axe, size-limit, Chromatic) are gated by their own exit codes and config — set their thresholds there, and say so in PIPELINE.md.
# .ds-ops/quality-gates.yml
# Quality gates for design system pull requests, read by scripts/ds-checks/
# Adjust thresholds based on your system's maturity
gates:
token-naming:
threshold: 0 # Zero tolerance for naming violations
block_merge: true
message: "Token naming violations must be fixed before merge"
orphaned-tokens:
threshold: 5 # Allow some orphans during migration periods
block_merge: false # Warn only: tokens consumed outside this repo look orphaned
message: "Possibly orphaned tokens — check external consumers before removing"
exports:
threshold: 0
block_merge: true
message: "Every component directory must be exported from the package entry point"
docs-and-stories:
threshold: 0
block_merge: false
message: "Components without docs or stories detected"Produce a PIPELINE.md file that explains:
Add a step that auto-pulls Figma variable values and compares them against token file definitions. This catches design-code drift at the CI level.
Style Dictionary's build catches broken and circular references and, with usesDtcg, bad value shapes; it does not validate names, so validate-token-names.js stays. Terrazzo's lint covers DTCG validation and has configurable lint rules that can replace the naming script. Use the tool the repo has; don't add a second token toolchain for CI.
Integrate the visual regression step with Storybook's built-in visual testing or Chromatic. Generate test-runner configuration for accessibility checks within stories.
Scope jobs by changed paths inside the pipeline (the changes job above), not with workflow-level paths: filters, so required checks never sit pending. Token changes run token checks; component changes run component checks. Use job dependencies so that token validation runs before component validation (since components depend on tokens).
test:a11y, size-limit) is either generated or listed as a prerequisite.ds-ops/quality-gates.yml, and the user is told to enable branch protection for blocking checks© murphytrueman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/cicd-integration of murphytrueman/design-system-ops.
Open the folder on GitHubat commit f167898
Cicd Integration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cicd Integration this skillmurphytrueman/design-system-ops | 203 | — | ~5.4k | Automated safety check: Pass | MIT | |
| Megalinter Checknvuillam/npm-groovy-lint | 248 | 1 repos | ~3.9k | Automated safety check: Notes | MIT | |
| Migrate To TeamcityJetBrains/teamcity-cli | 125 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Tirith PoliciesStackGuardian/tirith | 170 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Tsh Implementing CI CDTheSoftwareHouse/copilot-collections | 284 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Playwright CIzebbern/claude-code-guide | 4.7k | 2 repos | ~675 | Automated safety check: Pass | MIT |
nvuillam/npm-groovy-lint
Collect MegaLinter lint errors for the current repository. An agent skill from nvuillam/npm-groovy-lint.
JetBrains/teamcity-cli
Migrating CI/CD pipelines to TeamCity. An agent skill from JetBrains/teamcity-cli.
StackGuardian/tirith
Write, validate, run and debug Tirith IaC governance policies, install Tirith, and add it to a CI pipeline (GitHub Actions, GitLab CI, Bitbucket Pipelines, Jenkins, Azure DevOps, CircleCI or any…
TheSoftwareHouse/copilot-collections
CI/CD pipeline design patterns and deployment strategies. An agent skill from TheSoftwareHouse/copilot-collections.
zebbern/claude-code-guide
Production-ready CI/CD configurations for Playwright — GitHub Actions, GitLab CI, CircleCI, Azure DevOps, Jenkins, Docker, parallel sharding, reporting, code coverage, and global setup/teardown.
liarjsdev/liarjs-skills
Gate a build on browser fingerprint regressions with liarjs - save a baseline scan as JSON, diff later runs against it, and fail the job when the consistency score falls below a floor.
murphytrueman/design-system-ops
Write the AGENTS.md that tells coding agents how to use this design system: where things live, sourced rules, how to check work, what not to do; Claude, Cursor or Copilot pointers on request.
murphytrueman/design-system-ops
Write a six-section prose description (purpose, props, anti-patterns, composition, accessibility, examples) for a Figma component's description field so LLMs read it via MCP.
murphytrueman/design-system-ops
Write release notes, a migration guide and a team announcement for a design system change that is already decided, scaled to its impact.
murphytrueman/design-system-ops
Generate machine-readable index files in .ai/index/ (component inventory, uses/usedBy graph, stats) for AI agents.
murphytrueman/design-system-ops
Generate tested jscodeshift/postcss codemods for design system migrations: token renames, prop renames or removals, import paths, component swaps.
murphytrueman/design-system-ops
Audit prop APIs across a component library: naming consistency, boolean/default patterns, type coverage, exported types, breaking changes between versions.
Works with
Generate CI pipeline files and check scripts (GitHub Actions, GitLab, CircleCI, Bitbucket) that automate design system checks: token validation, hardcoded values, a11y scans, visual regression…. Cicd Integration is an agent skill from murphytrueman/design-system-ops. Generate CI pipeline files and check scripts (GitHub Actions, GitLab, CircleCI, Bitbucket) that automate design system checks: token validation, hardcoded values, a11y scans, visual regression, bundle size.
Cicd Integration fits situations like: tasks that involve CI/CD.
Run `npx skills add murphytrueman/design-system-ops --skill cicd-integration -a claude-code`. Or copy the skill folder (skills/cicd-integration in murphytrueman/design-system-ops) into .claude/skills/cicd-integration in your project. Claude Code loads it when a task matches its description.
Run `npx skills add murphytrueman/design-system-ops --skill cicd-integration -a codex`. Or copy the skill folder (skills/cicd-integration in murphytrueman/design-system-ops) into .agents/skills/cicd-integration in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add murphytrueman/design-system-ops --skill cicd-integration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cicd-integration, .gemini/skills/cicd-integration, .github/skills/cicd-integration and .opencode/skills/cicd-integration in your project.
Going by SKILL.md and its folder, Cicd Integration needs the command-line tools its instructions call (npx, npm, tsc and git) and credentials named CHROMATIC_PROJECT_TOKEN. Our summary lists: Node.js; A credential in CHROMATIC_PROJECT_TOKEN. Its frontmatter pre-approves these tools: Read, Write, Grep, Glob, Bash(cat:*), Bash(find:*), Bash(head:*), Bash(ls:*), Bash(sort:*), Bash(tail:*), Bash(wc:*), Bash(git diff:*), Bash(npx terrazzo:*), Bash(npx stylelint:*).
SKILL.md contains no URLs. Its commands use npx, npm and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cicd Integration is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.4k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Cicd Integration: Megalinter Check (nvuillam/npm-groovy-lint, 248 stars), Migrate To Teamcity (JetBrains/teamcity-cli, 125 stars), Tirith Policies (StackGuardian/tirith, 170 stars) and Tsh Implementing CI CD (TheSoftwareHouse/copilot-collections, 284 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
murphytrueman (a GitHub user) maintains it in murphytrueman/design-system-ops, which has 203 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on September 24, 2026.
Source: murphytrueman/design-system-ops on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.