Agent skill

GitHub Actions

by OpenHands in OpenHands/extensions

Create, debug, and test GitHub Actions workflows and custom actions.

MITAuto-check passedDevOps & Cloud

Install GitHub Actions

skills CLI
$ npx skills add OpenHands/extensions --skill github-actions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install OpenHands/extensions github-actions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/OpenHands/extensions.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/github-actions .claude/skills/github-actions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
github-actions
GitHub stars
157
Token cost
~472 tokens
SKILL.md length
222 words
Files
5
Skills in repo
78
Repo updated
First seen
Licence
MIT

At a glance

Create, debug, and test GitHub Actions workflows and custom actions.

  • Works in 5 steps: Monitor, don't poll - use gh run watch /… → Read logs, don't guess - fetch the… → Print actual values - debug steps reveal… → …
  • Building CI/CD pipelines
  • SKILL.md covers Critical Rules, Effectiveness Principles and Key Gotchas
  • Calls gh; needs GITHUB_TOKEN

What it does

GitHub Actions is an agent skill from OpenHands/extensions. Create, debug, and test GitHub Actions workflows and custom actions. Use when building CI/CD pipelines, automating workflows, or troubleshooting GitHub Actions.

Its SKILL.md is about 470 tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `.plugin/plugin.json` and `README.md`).

It sits in DevOps & Cloud, covering CI/CD. It works with GitHub Actions. The repository describes itself as: Public registry for OpenHands extensions. The licence is MIT.

When your agent uses it

  • Building CI/CD pipelines
  • Automating workflows
  • Troubleshooting GitHub Actions

Example prompts

  • “/github-actions”

Requirements

  • A credential in GITHUB_TOKEN

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Monitor, don't poll - use gh run watch / gh pr checks --watch to follow runs live
  2. Read logs, don't guess - fetch the failed job's log before changing code
  3. Print actual values - debug steps reveal the real inputs/github context, not your assumptions
  4. Test locally first - act runs workflows on your machine and avoids burning CI minutes
  5. Plan the smallest reproduction - one job, minimal matrix, narrow trigger before scaling up

What it can do on your machine

Read from SKILL.md and the folder at commit d008b81. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GitHub Actions loads about 472 tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 222 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~472

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from OpenHands/extensions at commit d008b81, republished under its MIT licence (© OpenHands). 222 words, ~472 tokens.

Download SKILL.mdSave it as .claude/skills/github-actions/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
github-actions
description
Create, debug, and test GitHub Actions workflows and custom actions. Use when building CI/CD pipelines, automating workflows, or troubleshooting GitHub Actions.
triggers
github actions, github workflow, actions workflow, gh actions, .github/workflows

GitHub Actions Guide

Critical Rules

Custom Action Deployment:

  • New custom actions MUST be merged to the main branch before they can be used
  • After the initial merge, they should be tested from feature branches

Debug Steps: Add debug steps that print non-secret parameters when:

  • Creating a new action, OR
  • Troubleshooting a particularly tricky issue

(Not required for every workflow - use when needed)

Effectiveness Principles

Actions cost CI minutes. Be deliberate, not iterative:

  1. Monitor, don't poll - use gh run watch / gh pr checks --watch to follow runs live
  2. Read logs, don't guess - fetch the failed job's log before changing code
  3. Print actual values - debug steps reveal the real inputs/github context, not your assumptions
  4. Test locally first - act runs workflows on your machine and avoids burning CI minutes
  5. Plan the smallest reproduction - one job, minimal matrix, narrow trigger before scaling up

See README.md for the full debugging workflow, gh commands, and YAML debug-step examples.

Key Gotchas

  1. Secrets unavailable in fork PRs - pull_request has no secrets for forks; pull_request_target does but never check out or execute fork PR code inside it (RCE with write permissions)
  2. Pin action versions - Use @v4 or SHA, not @main (prevents breaking changes)
  3. Explicit permissions - Set permissions: block for GITHUB_TOKEN operations
  4. Artifacts for job-to-job data - Files don't persist between jobs without upload-artifact/download-artifact

© OpenHands, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files in skills/github-actions of OpenHands/extensions.

  • SKILL.md
  • .claude-plugin
  • .codex-plugin
  • .plugin/plugin.json
  • README.md

Open the folder on GitHubat commit d008b81

Compare with similar skills

GitHub Actions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitHub Actions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitHub Actions this skillOpenHands/extensions157—~472Automated safety check: PassMIT
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
GitHub Actions Templatesbartstc/vite-ts-react-template12213 repos~1.9kAutomated safety check: PassMIT
Nushellccusage/ccusage19k—~938Automated safety check: PassCustom licence
Repo Hygiene Scan and FixQwenLM/qwen-code28k—~1.7kAutomated safety check: PassApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2596 repos~1.1kAutomated safety check: NotesCustom licence

Similar skills

  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • GitHub Actions Templates

    bartstc/vite-ts-react-template

    Create production-ready GitHub Actions workflows for automated testing, building, and deploying applications.

    122 GitHub starsUsed in 13 repos~1.9k tokens
    DevOps & CloudAuto-check passed
  • Nushell

    ccusage/ccusage

    Guides ccusage Nushell scripts. An agent skill from ccusage/ccusage.

    19k GitHub stars~938 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Scheduled CI skill that scans a repository for small, certain docs, test and code hygiene issues and fixes them on one branch with a commit per finding.

    28k GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    259 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • CI Failure Triage and Repair

    Chachamaru127/claude-code-harness

    Diagnoses failing CI pipelines and tests, deciding first whether the test or the implementation is at fault, and hands hard cases to a dedicated fixer subagent.

    3.2k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check: notes

More from OpenHands/extensions

All 78 skills in this repo
  • Agent Readiness Report

    OpenHands/extensions

    Evaluate how well a codebase supports autonomous AI-assisted development.

    157 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Discord

    OpenHands/extensions

    Build and automate Discord integrations (bots, webhooks, slash commands, and REST API workflows).

    157 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • GitHub

    OpenHands/extensions

    Interact with GitHub repositories, pull requests, issues, and workflows using the GITHUBTOKEN environment variable and GitHub CLI.

    157 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • GitHub Issue To PR

    OpenHands/extensions

    Create an automation that implements GitHub issues when a configurable trigger label is applied.

    157 GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed
  • GitHub Repo Monitor

    OpenHands/extensions

    This skill should be used when the user asks to "monitor a GitHub repository", "watch GitHub for issues or PRs", "respond to @OpenHands mentions on GitHub", "set up an OpenHands GitHub integration"…

    157 GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • GitLab Issue To Mr

    OpenHands/extensions

    Create an automation that implements GitLab issues when a configurable trigger label is applied.

    157 GitHub stars~4.9k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about GitHub Actions

What does GitHub Actions do?

Create, debug, and test GitHub Actions workflows and custom actions. GitHub Actions is an agent skill from OpenHands/extensions. Create, debug, and test GitHub Actions workflows and custom actions.

When should I use GitHub Actions?

GitHub Actions fits situations like: building CI/CD pipelines; automating workflows; troubleshooting GitHub Actions.

How do I install GitHub Actions in Claude Code?

Run `npx skills add OpenHands/extensions --skill github-actions -a claude-code`. Or copy the skill folder (skills/github-actions in OpenHands/extensions) into .claude/skills/github-actions in your project. Claude Code loads it when a task matches its description.

How do I install GitHub Actions in Codex?

Run `npx skills add OpenHands/extensions --skill github-actions -a codex`. Or copy the skill folder (skills/github-actions in OpenHands/extensions) into .agents/skills/github-actions in your project. Codex loads it when a task matches its description.

Can I use GitHub Actions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OpenHands/extensions --skill github-actions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-actions, .gemini/skills/github-actions, .github/skills/github-actions and .opencode/skills/github-actions in your project.

What does GitHub Actions need to run?

Going by SKILL.md and its folder, GitHub Actions needs the command-line tools its instructions call (gh) and credentials named GITHUB_TOKEN. Our summary lists: A credential in GITHUB_TOKEN.

Does GitHub Actions access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is GitHub Actions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does GitHub Actions use?

GitHub Actions is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitHub Actions use?

About 472 tokens (SKILL.md is roughly 1.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to GitHub Actions?

Skills that share tags, products or a category with GitHub Actions: Analyze GitHub Action Logs (withastro/astro, 63k stars), GitHub Actions Templates (bartstc/vite-ts-react-template, 122 stars), Nushell (ccusage/ccusage, 19k stars) and Repo Hygiene Scan and Fix (QwenLM/qwen-code, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitHub Actions?

OpenHands (a GitHub organization) maintains it in OpenHands/extensions, which has 157 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: OpenHands/extensions on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.