Secure GitHub Actions
vechain/x-app-template
Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.
A skill your agent uses when the user wants to build, create, or develop anything — websites, apps, APIs, services, platforms.
$ npx skills add nagisanzenin/production-grade --skill production-grade -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nagisanzenin/production-grade production-grade --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nagisanzenin/production-grade.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/production-grade .claude/skills/production-grade && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "production-grade" agent skill from https://github.com/nagisanzenin/production-grade/tree/main/skills/production-grade into .claude/skills/production-grade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "production-grade", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nagisanzenin/production-grade/tree/main/skills/production-gradeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nagisanzenin/production-grade --skill production-grade -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nagisanzenin/production-grade production-grade --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nagisanzenin/production-grade.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/production-grade .agents/skills/production-grade && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "production-grade" agent skill from https://github.com/nagisanzenin/production-grade/tree/main/skills/production-grade into .agents/skills/production-grade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "production-grade", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nagisanzenin/production-grade --skill production-grade -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nagisanzenin/production-grade production-grade --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nagisanzenin/production-grade.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/production-grade .cursor/skills/production-grade && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "production-grade" agent skill from https://github.com/nagisanzenin/production-grade/tree/main/skills/production-grade into .cursor/skills/production-grade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "production-grade", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nagisanzenin/production-grade.git --path skills/production-grade--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nagisanzenin/production-grade --skill production-grade -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nagisanzenin/production-grade production-grade --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nagisanzenin/production-grade.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/production-grade .gemini/skills/production-grade && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "production-grade" agent skill from https://github.com/nagisanzenin/production-grade/tree/main/skills/production-grade into .gemini/skills/production-grade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "production-grade", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nagisanzenin/production-grade production-gradeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nagisanzenin/production-grade --skill production-grade -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nagisanzenin/production-grade.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/production-grade .github/skills/production-grade && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "production-grade" agent skill from https://github.com/nagisanzenin/production-grade/tree/main/skills/production-grade into .github/skills/production-grade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "production-grade", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nagisanzenin/production-grade --skill production-grade -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nagisanzenin/production-grade production-grade --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nagisanzenin/production-grade.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/production-grade .opencode/skills/production-grade && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "production-grade" agent skill from https://github.com/nagisanzenin/production-grade/tree/main/skills/production-grade into .opencode/skills/production-grade/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "production-grade", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
production-gradeA skill your agent uses when the user wants to build, create, or develop anything — websites, apps, APIs, services, platforms.
Production Grade is an agent skill from nagisanzenin/production-grade. Use when the user wants to build, create, or develop anything — websites, apps, APIs, services, platforms. This skill enhances your coding agent from producing raw code into delivering production-ready systems: architecture docs, API contracts, tested backend/frontend, security audit, CI/CD pipelines, and documentation. Also activates for: adding features to existing code, hardening before launch, setting up deployment, writing tests, code review, architecture design, or any multi-step development work. 14…
Its SKILL.md is about 16k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `hooks/activation-rules.json`, `phases/build.md` and `phases/define.md`).
It sits in DevOps & Cloud, covering Security review, CI/CD and API design. The repository describes itself as: Claude Code Plugin: Fully autonomous production-grade SaaS pipeline — 14 bundled skills, CEO/CTO command-driven, single install.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4b2f13f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Production Grade loads about 16k tokens when it runs. Until then it costs about 219 tokens; SKILL.md has 5,485 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- Block `.env`, `.key`, `.pem`, `credentials.json` from gitAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Without a licence we can't republish the file, so here is its outline and opening line. It has 5,485 words (~16,479 tokens).
“!git status 2>/dev/null || echo "No git repo detected" !cat CLAUDE.md 2>/dev/null || echo "No CLAUDE.md found" !ls Claude-Production-Grade-Suite/ 2>/dev/null || echo "No existing workspace" !cat .production-grade.yaml 2>/dev/null || echo "No config file — defaults apply" !cat Claude-Production-Grade-Suite/.protocols/visual-identity.md 2>/dev/null ||…”
SKILL.md and 6 other files in skills/production-grade of nagisanzenin/production-grade.
Open the folder on GitHubat commit 4b2f13f
Production Grade next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Production Grade this skillnagisanzenin/production-grade | 181 | — | ~16k | Automated safety check: Notes | None | |
| Secure GitHub Actionsvechain/x-app-template | 450 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Agentic GitHub Actions Auditortrailofbits/skills | 7.5k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Code PatternsAedelon/claude-code-blueprint | 120 | — | ~1.2k | Automated safety check: Pass | Custom licence | |
| GitHub Actions Hardeninggithub/awesome-copilot | 40k | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| Managing Pipelinesrileyhilliard/claude-essentials | 130 | — | ~1.5k | Automated safety check: Pass | MIT |
vechain/x-app-template
Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
Aedelon/claude-code-blueprint
Reference patterns for REST APIs, pytest/vitest testing, Docker multi-stage builds, GitHub Actions CI/CD, PostgreSQL, TypeScript generics, Python async, and React Server Components.
github/awesome-copilot
Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).
rileyhilliard/claude-essentials
Guides GitHub Actions CI/CD architecture, security hardening, and deployment strategies.
c0x12c/ai-toolkit
Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response.
nagisanzenin/production-grade
[production-grade internal] Optimizes AI/ML/LLM usage when you need model selection, prompt engineering, cost reduction, or experiment design.
nagisanzenin/production-grade
[production-grade internal] Turns product ideas and business goals into formal requirements — BRD, user stories, acceptance criteria, prioritization.
nagisanzenin/production-grade
[production-grade internal] Creates reusable Claude Code skills and plugins when you want to automate repeatable workflows into shareable tools.
nagisanzenin/production-grade
[production-grade internal] Implements backend services, APIs, and business logic — builds features, fixes bugs, refactors code from specs.
nagisanzenin/production-grade
[production-grade internal] Makes systems reliable in production — SLOs, monitoring, alerting, chaos engineering, incident runbooks, capacity planning.
nagisanzenin/production-grade
[production-grade internal] Generates documentation when you need to explain code — API references, developer guides, READMEs, architecture overviews.
Categories
A skill your agent uses when the user wants to build, create, or develop anything — websites, apps, APIs, services, platforms. Production Grade is an agent skill from nagisanzenin/production-grade. Use when the user wants to build, create, or develop anything — websites, apps, APIs, services, platforms.
Production Grade fits situations like: the user wants to build; develop anything — websites.
Run `npx skills add nagisanzenin/production-grade --skill production-grade -a claude-code`. Or copy the skill folder (skills/production-grade in nagisanzenin/production-grade) into .claude/skills/production-grade in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nagisanzenin/production-grade --skill production-grade -a codex`. Or copy the skill folder (skills/production-grade in nagisanzenin/production-grade) into .agents/skills/production-grade in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nagisanzenin/production-grade --skill production-grade -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/production-grade, .gemini/skills/production-grade, .github/skills/production-grade and .opencode/skills/production-grade in your project.
Going by SKILL.md and its folder, Production Grade needs the command-line tools its instructions call (git). Our summary lists: Python 3; Docker.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
No licence was found for Production Grade or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.
About 16k tokens (SKILL.md is roughly 66k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Production Grade: Secure GitHub Actions (vechain/x-app-template, 450 stars), Agentic GitHub Actions Auditor (trailofbits/skills, 7.5k stars), Code Patterns (Aedelon/claude-code-blueprint, 120 stars) and GitHub Actions Hardening (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nagisanzenin (a GitHub user) maintains it in nagisanzenin/production-grade, which has 181 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on August 19, 2026.
Source: nagisanzenin/production-grade on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.