GitHub Workflow Automation
FNOSP/FlyNarwhal
Automate GitHub workflows with AI assistance. An agent skill from FNOSP/FlyNarwhal.
Watch GitHub Actions CI correctly with the gh CLI — block until a run / PR check rollup is TRULY terminal, then trust the exit code.
$ npx skills add nubjs/nub --skill ci-watch -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nubjs/nub ci-watch --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/ci-watch .claude/skills/ci-watch && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ci-watch" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/ci-watch into .claude/skills/ci-watch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-watch", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nubjs/nub/tree/main/.claude/skills/ci-watchType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nubjs/nub --skill ci-watch -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nubjs/nub ci-watch --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/ci-watch .agents/skills/ci-watch && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ci-watch" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/ci-watch into .agents/skills/ci-watch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-watch", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nubjs/nub --skill ci-watch -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nubjs/nub ci-watch --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/ci-watch .cursor/skills/ci-watch && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ci-watch" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/ci-watch into .cursor/skills/ci-watch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-watch", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nubjs/nub.git --path .claude/skills/ci-watch--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nubjs/nub --skill ci-watch -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nubjs/nub ci-watch --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/ci-watch .gemini/skills/ci-watch && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ci-watch" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/ci-watch into .gemini/skills/ci-watch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-watch", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nubjs/nub ci-watchInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nubjs/nub --skill ci-watch -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/ci-watch .github/skills/ci-watch && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ci-watch" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/ci-watch into .github/skills/ci-watch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-watch", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nubjs/nub --skill ci-watch -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nubjs/nub ci-watch --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/ci-watch .opencode/skills/ci-watch && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ci-watch" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/ci-watch into .opencode/skills/ci-watch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-watch", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ci-watchWatch GitHub Actions CI correctly with the gh CLI — block until a run / PR check rollup is TRULY terminal, then trust the exit code.
CI Watch is an agent skill from nubjs/nub. Watch GitHub Actions CI correctly with the gh CLI — block until a run / PR check rollup is TRULY terminal, then trust the exit code. Invoke (via the Skill tool) whenever you need to wait on CI after REQUESTING a pull-request run (gh pr edit <n --add-label ci — PR CI is opt-in, so a push starts nothing), after a push to main, or after a tag, and act on the result (merge-on-green, release-on-green, fail-fast on red). Encodes the premature-exit pitfall (raw gh run watch / gh pr checks --watch exit 0 while the run is…
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering CI/CD and Pull requests. It works with GitHub Actions. The repository describes itself as: The fast all-in-one Node.js toolkit. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 568e73a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghnodeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
CI Watch loads about 2.2k tokens when it runs. Until then it costs about 217 tokens; SKILL.md has 1,038 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from nubjs/nub at commit 568e73a, republished under its MIT licence (© nubjs). 1,038 words, ~2,242 tokens.
.claude/skills/ci-watch/SKILL.md (or your agent's skills folder).gh run watch <id> --exit-status and gh pr checks <pr> --watch are not safe to arm right after a push / tag / PR-open:
HTTP 401: Bad credentials (token refresh) or a 5xx exits non-zero, indistinguishable from a real CI failure.--interval only tunes the poll cadence.Never trust a raw watcher's exit code alone. Re-verify terminal status with gh run view <id> --json status,conclusion (done only when status == "completed") or gh pr view <pr> --json statusCheckRollup (done only when every item is terminal). And always fail-fast — act on the first failing check, never wait for all checks to finish.
scripts/ci-watch.tsBlocks until the target is truly terminal, then exits with a trustworthy status. Dogfoods nub; runs under plain Node too.
nub scripts/ci-watch.ts --run <run-id> [--repo o/r] [--timeout <min>]
node scripts/ci-watch.ts --pr <number> [--repo o/r] [--timeout <min>]--run <run-id> — watch a workflow run (polls gh run view --json status,conclusion,jobs).--pr <number> — watch a PR's check rollup (polls gh pr view --json statusCheckRollup,…).--repo <owner/repo> — defaults to the current repo.--timeout <minutes> — wall-clock cap before giving up as pending (default 45).--required <names> — comma-separated branch-protection check names to gate on (e.g. --required "CI gate"). Success fires the instant every required check is green; a ghost or a non-required check — pending or failed — never blocks, matching branch-protection semantics. Prefer it when you know the required check name.--no-progress <minutes> — how long an unchanged incomplete set (all named checks green, only a ghost left) may sit before exiting 4 STUCK-but-safe (default 8).What it fixes: waits for the target to EXIST (not-found / no-jobs-yet is "keep polling," never "done"); polls authoritative terminal state; fails fast on the first FAILURE/CANCELLED/TIMED_OUT/ STARTUP_FAILURE; never hangs on a ghost; tolerates transient gh/API errors (retried with exponential jittered backoff, 10s → cap 60s, 90s unauthenticated).
GitHub occasionally registers a check-run that never reports a status: PENDING, nameless, forever. A watcher waiting for every rollup item to be terminal blocks indefinitely even though every real check is green. So a nameless / never-terminating non-required check does not block a green verdict: once every named check is green and the incomplete set has been unchanged for --no-progress minutes, the watcher exits 4 (STUCK-but-safe) and the caller --admin merges. A named pending check is never treated as a ghost, so a real in-flight check is never green-lit early.
| code | meaning |
|---|---|
| 0 | completed AND all green |
| 1 | a check/job failed (the summary names which + the URL) |
| 2 | required/named checks still NOT green after --timeout (genuinely stuck) |
| 3 | usage / target-unresolvable / unrecoverable error |
| 4 | STUCK-but-safe — required/named checks all green, but a ghost check will never terminate; safe to --admin merge (the caller decides) |
The final stdout line is a single self-describing summary, e.g. CI-WATCH run 27972328590: SUCCESS (25 job(s) green), CI-WATCH pr 73: FAILURE — check "Test (ubuntu-latest, node 22.13)" → FAILURE (https://…), or CI-WATCH pr 327: STUCK — required/named checks GREEN (51), 1 non-terminal ghost/non-required check(s): (unnamed); safe to --admin merge.
The exit code IS the contract, and a pipeline throws it away: in ci-watch.ts … | tail -20, $? is tail's status, so a FAILED CI reads as SUCCESS. The pipe also buffers stdout until the pipeline ends, so the log stays empty while the watcher runs.
# WRONG — $? is tail's, a red CI looks green, and no interim output
node scripts/ci-watch.ts --pr 604 --repo nubjs/nub | tail -25; echo "exit=$?"
# RIGHT — redirect, then gate on the watcher's OWN status
node scripts/ci-watch.ts --pr 604 --repo nubjs/nub > /tmp/ci604.log 2>&1; rc=$?
tail -15 /tmp/ci604.log; echo "exit=$rc"main() warns on stderr when it detects a piped stdout (fd 1 is a FIFO for | cmd, not for > file), but redirect by default rather than relying on the warning. Bash ${PIPESTATUS[0]} / zsh ${pipestatus[1]} recover the real status if a pipe is unavoidable.
Cross-check the rollup regardless of what the watcher says. Read gh pr view <pr> --json statusCheckRollup,mergeStateStatus directly and act on any FAILURE. A watcher that has produced nothing for a long stretch is a suspect, not a status.
For a merge-queue drain, prefer scripts/merge-cascade.ts (it gates positively and merges on green); reach for ci-watch.ts when you need to block on one run/PR and branch on the result.
run_in_background behaves the same for the orchestrator and for a sub-agent: a backgrounded Bash command persists across turns and re-invokes its launcher on exit. Both patterns below are valid.
Merge-on-green (the default). The orchestrator runs the blocking watcher as its own run_in_background Bash task:
{"pr":N,"branch":"…","thread":"…","note":"…"} (optional "hold":true) to .frizz/merge-queue.jsonl. Enqueue UNHELD only once the PR's FINAL head is pushed AND gh pr edit <n> --add-label ci has requested a run against it — a stale head can be green-but-wrong, and an unrequested one never goes green at all, so the queue would hold it until the cascade times out.node scripts/merge-cascade.ts --max-minutes 40 with run_in_background: true. It gates positively on the required CI gate (present + SUCCESS) + mergeable, merges --squash --admin, ff-pulls, dequeues, exits → re-invokes the orchestrator. It shares ci-watch's ghost carve-out (scripts/lib/ci-rollup.ts), so a still-running or failed REQUIRED gate always blocks and a red PR is never mis-merged.gh pr edit <n> --add-label ci, and report pushed <sha>, CI requested, queued. They never watch.Self-contained landing agent (one agent traces push→merge): push the branch; request the run with gh pr edit <n> --add-label ci; launch node scripts/merge-cascade.ts --max-minutes 40 (or ci-watch.ts) for its OWN PR via run_in_background: true; end its turn; it is re-invoked when the command exits, reports merged/red, and iterates. Do not preempt a landing agent's background watch by checking CI yourself and merging manually mid-trace — that impatience is what breaks the flow.
Foreground chunk loop (fallback only) — for an agent that must actively iterate and cannot rest:
# Bash tool: foreground (NOT run_in_background), timeout: 570000 (9.5 min, under the 600000 cap)
nub scripts/ci-watch.ts --pr <N> --chunk # --chunk caps the watch ~9 min and exits 2 with "RERUN to continue" if still pending
# exit 0 = green → act exit 1 = red → fix + re-push exit 2 = pending → RE-RUN the SAME command exit 3 = errorWhile it exits 2, call it again — each chunk completes within the cap (no kill, no orphan). Blocking in the sub-agent's foreground is fine: it is backgrounded relative to the orchestrator. A dispatch prompt for a self-gating landing agent must spell this loop out — a sub-agent won't infer it.
A CronCreate heartbeat (every ~4 min, one non-blocking gh pr view poll per queued PR) is a FALLBACK only if a background shell ever proves unreliable.
© nubjs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/ci-watch of nubjs/nub.
Open the folder on GitHubat commit 568e73a
CI Watch next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| CI Watch this skillnubjs/nub | 4.4k | — | ~2.2k | Automated safety check: Pass | MIT | |
| GitHub Workflow AutomationFNOSP/FlyNarwhal | 495 | 8 repos | ~5.4k | Automated safety check: Pass | AGPL-3.0 | |
| CIaiblueprinthq/ai-blueprint | 461 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Michel Monitor Pull Request GitHub ActionsPackmindHub/packmind | 317 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| CIopenJiuwen-ai/sciencediscovery | 151 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Watch CIsd0xdev/sd0x-harness | 192 | — | ~2.5k | Automated safety check: Pass | MIT |
FNOSP/FlyNarwhal
Automate GitHub workflows with AI assistance. An agent skill from FNOSP/FlyNarwhal.
aiblueprinthq/ai-blueprint
Set up or normalize one project Verify command and matching GitHub Actions checks while preserving existing CI, with an optional local pre-push hook.
PackmindHub/packmind
Diagnose a failed, stuck, or never-triggered CI run on a GitHub PR, apply a local fix if possible, push it, and document the result in a single running PR comment.
openJiuwen-ai/sciencediscovery
Read, diagnose, and change the CI pipeline: GitHub Actions on pull requests, the nightly schedule and the release tag.
sd0xdev/sd0x-harness
Monitor GitHub Actions CI runs until completion. An agent skill from sd0xdev/sd0x-harness.
swyxio/skills
Build or audit an isolated Netlify/Vercel-style pull-request preview workflow using GitHub Actions and the project's existing hosting provider.
nubjs/nub
Diagnose and clear CPU, memory, and disk contention on the maintainer's dev host.
nubjs/nub
Reclaim disk on the maintainer's Mac when the volume is full or filling — ENOSPC, "no space left on device", a failed build or agent harness, or a routine sweep of Rust build residue.
nubjs/nub
Build a performance chart for nubjs.com — the SVG bar figures in blog posts, docs pages and social posts (a runtime augmentation against plain node, an install or dispatch comparison, a cross-tool…
nubjs/nub
A skill your agent uses when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a…
nubjs/nub
Run ad-hoc Nub tests and debugging probes on real local Linux guests.
nubjs/nub
Performance-trace Nub package-manager installs using the existing phase timings, structured diagnostics, and sampling-profiler workflow.
Works with
Categories
Watch GitHub Actions CI correctly with the gh CLI — block until a run / PR check rollup is TRULY terminal, then trust the exit code. CI Watch is an agent skill from nubjs/nub. Watch GitHub Actions CI correctly with the gh CLI — block until a run / PR check rollup is TRULY terminal, then trust the exit code.
CI Watch fits situations like: tasks that involve CI/CD; tasks that involve Pull requests.
Run `npx skills add nubjs/nub --skill ci-watch -a claude-code`. Or copy the skill folder (.claude/skills/ci-watch in nubjs/nub) into .claude/skills/ci-watch in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nubjs/nub --skill ci-watch -a codex`. Or copy the skill folder (.claude/skills/ci-watch in nubjs/nub) into .agents/skills/ci-watch in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nubjs/nub --skill ci-watch -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ci-watch, .gemini/skills/ci-watch, .github/skills/ci-watch and .opencode/skills/ci-watch in your project.
Going by SKILL.md and its folder, CI Watch needs the command-line tools its instructions call (gh and node).
SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
CI Watch is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with CI Watch: GitHub Workflow Automation (FNOSP/FlyNarwhal, 495 stars), CI (aiblueprinthq/ai-blueprint, 461 stars), Michel Monitor Pull Request GitHub Actions (PackmindHub/packmind, 317 stars) and CI (openJiuwen-ai/sciencediscovery, 151 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nubjs (a GitHub organization) maintains it in nubjs/nub, which has 4,372 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 7, 2026.
Source: nubjs/nub on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.