Official agent skill

Maintain CI

by NVIDIA in NVIDIA/NeMo-Relay

Change or review NeMo Relay GitHub Actions workflows where permissions, pinned actions, caching, reusable workflows, or release gates require repository-specific handling.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Maintain CI

skills CLI
$ npx skills add NVIDIA/NeMo-Relay --skill maintain-ci -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NVIDIA/NeMo-Relay maintain-ci --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NVIDIA/NeMo-Relay.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/maintain-ci .claude/skills/maintain-ci && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
maintain-ci
GitHub stars
190
Token cost
~1k tokens
SKILL.md length
443 words
Files
1
Skills in repo
30
Repo updated
First seen
Licence
Apache-2.0

At a glance

Change or review NeMo Relay GitHub Actions workflows where permissions, pinned actions, caching, reusable workflows, or release gates require repository-specific handling.

  • Ordinary source changes that merely run in CI
  • SKILL.md covers Standards, Permission Model, Caching and Review Checklist, plus 2 more sections
  • Calls ruby, uv and rg
  • Tasks that involve CI/CD

What it does

Maintain CI is an agent skill from NVIDIA/NeMo-Relay, published by the product's own GitHub organization. Change or review NeMo Relay GitHub Actions workflows where permissions, pinned actions, caching, reusable workflows, or release gates require repository-specific handling. Do not use for ordinary source changes that merely run in CI.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering CI/CD and Caching. It works with GitHub Actions. The repository describes itself as: Multi-language agent runtime and library for execution scope management, lifecycle events, and middleware on tool and LLM calls. The licence is Apache-2.0.

When your agent uses it

  • Ordinary source changes that merely run in CI
  • Tasks that involve CI/CD
  • Tasks that involve Caching

Example prompts

  • “/maintain-ci”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 651453f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • ruby
    • uv
    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Maintain CI loads about 1k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 443 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from NVIDIA/NeMo-Relay at commit 651453f, republished under its Apache-2.0 licence (© NVIDIA). 443 words, ~1,010 tokens.

Download SKILL.mdSave it as .claude/skills/maintain-ci/SKILL.md (or your agent's skills folder).
name
maintain-ci
description
Change or review NeMo Relay GitHub Actions workflows where permissions, pinned actions, caching, reusable workflows, or release gates require repository-specific handling. Do not use for ordinary source changes that merely run in CI.
license
Apache-2.0

Maintain GitHub Actions CI

Use this skill when a change touches .github/workflows/*.yml or .github/workflows/*.yaml, or when reviewing CI behavior for security, reliability, or reproducibility.

Standards

  • Put permissions: on each job that needs token access.
  • Avoid workflow-level permissions unless the repository intentionally centralizes them and the inheritance tradeoff is documented.
  • Keep third-party actions pinned to full commit SHAs and preserve the readable version comment after the SHA.
  • Prefer action-native or ecosystem-native caching over generic actions/cache.
  • Use lockfiles or dependency manifests to drive cache invalidation.
  • Keep deploy and publish permissions isolated to the jobs that need them.
  • Read both caller and callee when a workflow uses workflow_call.
  • Put release-tag validation in the earliest practical caller job when the pipeline has tag-based publish behavior.
  • Keep release-tag policy aligned with RELEASING.md: raw SemVer tags only, no leading v.
  • Keep Codecov component paths aligned with new crates, packages, and generated outputs. Dynamic plugin SDK/protocol paths belong in the plugin component.
  • Keep pure-Python plugin SDK packaging as a single wheel artifact instead of duplicating it across every platform matrix entry.

Permission Model

  • contents: read is the default minimum for checkout-based build, test, docs, and packaging jobs.
  • pull-requests: read is required for PR metadata lookup jobs.
  • pages: write and id-token: write should be limited to Pages deployment jobs and any caller that invokes them through a reusable workflow.
  • For reusable workflows, the caller must grant every permission the called jobs require. The callee cannot elevate beyond what the caller provides.

Caching

  • Prefer astral-sh/setup-uv cache support with cache-dependency-glob anchored to uv.lock.
  • Prefer Swatinem/rust-cache with explicit shared-key and workspaces instead of ad hoc target-directory caching.
  • Avoid caching generated outputs that can hide stale behavior unless the repo already relies on them deliberately.
Show full SKILL.md (160 more words)Show less

Review Checklist

  • Each job has the minimum permissions it needs
  • Reusable workflow callers grant only the scopes their callees require
  • Every external action is pinned to a full SHA
  • Cache settings are tied to lockfiles, manifests, or explicit tool versions
  • Secrets are only passed to the jobs that consume them
  • Codecov upload counts match codecov.yml after adding or removing upload jobs
  • Package artifacts include any first-class SDK packages introduced by the change
  • Concurrency, branch filters, and publish guards still reflect release intent
  • Artifact upload, download, and Pages deploy steps have matching permissions
  • Tag-triggered release workflows fail early when a tag violates repo policy

Validation

Start with the narrowest useful checks:

bash
ruby -e 'require "yaml"; Dir[".github/workflows/*.{yml,yaml}"].each { |f| YAML.load_file(f) }; puts "yaml-ok"'
uv run pre-commit run

Use ripgrep to inspect the workflow graph before editing:

bash
rg -n "uses:|permissions:|workflow_call|secrets:|upload-artifact|download-artifact|upload-pages-artifact|deploy-pages|codecov|cache" .github/workflows

If local lint passes but the question is whether GitHub will authorize the run, inspect GitHub's permission model and the upstream action or reusable workflow source instead of assuming local success proves remote success.

Canonical References

  • .github/workflows/ci.yaml
  • .github/workflows/ci_python.yml
  • RELEASING.md
  • .pre-commit-config.yaml
  • .github/ci-path-filters.yml

© NVIDIA, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/maintain-ci of NVIDIA/NeMo-Relay.

Open the folder on GitHubat commit 651453f

Compare with similar skills

Maintain CI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Maintain CI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Maintain CI this skillNVIDIA/NeMo-Relay190—~1kAutomated safety check: PassApache-2.0
CI Pipeline Synthesizerkajisho5/ffmpeg-skill1.9k1 repos~1.1kAutomated safety check: PassMIT
CI GitHub Actionsgnomeria/usbtree688—~1.4kAutomated safety check: PassMIT
Atmos Cachecloudposse/atmos1.4k—~793Automated safety check: PassApache-2.0
Cloud Deploy GCP AWSmakifbaysal/tasktrooper109—~984Automated safety check: PassApache-2.0
CI Pipeline Patternsvibeeval/vibecosystem531—~682Automated safety check: PassMIT

Similar skills

  • CI Pipeline Synthesizer

    kajisho5/ffmpeg-skill

    Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.

    1.9k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check passed
  • CI GitHub Actions

    gnomeria/usbtree

    GitHub Actions CI pipeline conventions — job shape, caching, permissions, and action pinning.

    688 GitHub stars~1.4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Atmos Cache

    cloudposse/atmos

    Atmos caching: CI cache configuration and commands, GitHub Actions cache integration, Terraform registry cache mirror/list/prune/stats/trust, and cache modernization guidance

    1.4k GitHub stars~793 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Cloud Deploy GCP AWS

    makifbaysal/tasktrooper

    A skill your agent uses when a web/frontend app needs a cloud deploy - GitHub Actions to Cloud Run/ECS for SSR or GCS+CDN/Firebase and S3+CloudFront for static, with build-time env and cache…

    109 GitHub stars~984 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • CI Pipeline Patterns

    vibeeval/vibecosystem

    GitHub Actions workflow templates, matrix builds, caching, and monorepo CI strategies

    531 GitHub stars~682 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Official

    Set up NuGet trusted publishing (OIDC) on a GitHub Actions repo — replaces long-lived API keys with short-lived tokens.

    5.6k GitHub starsUsed in 2 repos~2.3k tokens
    DevOps & CloudAuto-check passed

More from NVIDIA/NeMo-Relay

All 30 skills in this repo
  • Draft Release Notes

    NVIDIA/NeMo-Relay

    Official

    Compare NeMo Relay release refs and draft the current documentation release-notes page from verified repository evidence.

    190 GitHub stars~575 tokensUpdated today
    Auto-check passed
  • Official

    A skill your agent uses when migrating applications, examples, integrations, documentation, manifests, or repository code from NeMo Flow to NeMo Relay across Python, Rust, Node.js, Go, C FFI, CLI…

    190 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Add Middleware

    NVIDIA/NeMo-Relay

    Official

    Add a new NeMo Relay guardrail or intercept type, registration surface, or pipeline stage.

    190 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Contribute Docs

    NVIDIA/NeMo-Relay

    Official

    Author or edit NeMo Relay documentation or examples when repository-specific MDX, public API, integration, or release-history conventions matter.

    190 GitHub stars~710 tokensUpdated today
    Auto-check passed
  • Nemo Relay Install

    NVIDIA/NeMo-Relay

    Official

    A skill your agent uses when choosing or running NeMo Relay installation for the CLI, Python, Node.js, Rust, OpenClaw, or maintained framework integrations, or when explaining Hermes Agent's…

    190 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Nemo Relay Plugin Build

    NVIDIA/NeMo-Relay

    Official

    A skill your agent uses when building or packaging reusable NeMo Relay runtime behavior as an embedded configuration component or a manifest-backed rustdynamic native or worker gRPC plugin, with…

    190 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Works with

Questions about Maintain CI

What does Maintain CI do?

Change or review NeMo Relay GitHub Actions workflows where permissions, pinned actions, caching, reusable workflows, or release gates require repository-specific handling. Maintain CI is an agent skill from NVIDIA/NeMo-Relay, published by the product's own GitHub organization. Change or review NeMo Relay GitHub Actions workflows where permissions, pinned actions, caching, reusable workflows, or release gates require repository-specific handling.

When should I use Maintain CI?

Maintain CI fits situations like: ordinary source changes that merely run in CI; tasks that involve CI/CD; tasks that involve Caching.

How do I install Maintain CI in Claude Code?

Run `npx skills add NVIDIA/NeMo-Relay --skill maintain-ci -a claude-code`. Or copy the skill folder (.agents/skills/maintain-ci in NVIDIA/NeMo-Relay) into .claude/skills/maintain-ci in your project. Claude Code loads it when a task matches its description.

How do I install Maintain CI in Codex?

Run `npx skills add NVIDIA/NeMo-Relay --skill maintain-ci -a codex`. Or copy the skill folder (.agents/skills/maintain-ci in NVIDIA/NeMo-Relay) into .agents/skills/maintain-ci in your project. Codex loads it when a task matches its description.

Can I use Maintain CI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NVIDIA/NeMo-Relay --skill maintain-ci -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/maintain-ci, .gemini/skills/maintain-ci, .github/skills/maintain-ci and .opencode/skills/maintain-ci in your project.

What does Maintain CI need to run?

Going by SKILL.md and its folder, Maintain CI needs the command-line tools its instructions call (ruby, uv and rg). Our summary lists: Python 3.

Does Maintain CI access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Maintain CI safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Maintain CI use?

Maintain CI is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Maintain CI use?

About 1k tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Maintain CI?

Skills that share tags, products or a category with Maintain CI: CI Pipeline Synthesizer (kajisho5/ffmpeg-skill, 1.9k stars), CI GitHub Actions (gnomeria/usbtree, 688 stars), Atmos Cache (cloudposse/atmos, 1.4k stars) and Cloud Deploy GCP AWS (makifbaysal/tasktrooper, 109 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Maintain CI?

NVIDIA (a GitHub organization, an official publisher) maintains it in NVIDIA/NeMo-Relay, which has 190 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 7, 2026.

Source: NVIDIA/NeMo-Relay on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.