Read, diagnose, and change the CI pipeline: GitHub Actions on pull requests, the nightly schedule and the release tag.

Apache-2.0Auto-check passedDevOps & Cloud

Install CI

skills CLI
$ npx skills add openJiuwen-ai/sciencediscovery --skill ci -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openJiuwen-ai/sciencediscovery ci --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openJiuwen-ai/sciencediscovery.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ci .claude/skills/ci && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ci
GitHub stars
159
Token cost
~2.2k tokens
SKILL.md length
1,202 words
Files
2 (incl. references)
Skills in repo
23
Repo updated
First seen
Licence
Apache-2.0

At a glance

Read, diagnose, and change the CI pipeline: GitHub Actions on pull requests, the nightly schedule and the release tag.

  • Works in 6 steps: Never weaken a sandbox assertion to make… → Call the pnpm ci:* entry points, never… → UT is one layer. A UT test needing the… → …
  • Editing .github/workflows/
  • SKILL.md covers What runs where, One plan, three layers, Shared rules and Platform routing, plus 1 more section
  • Calls pnpm, node and gh

What it does

CI is an agent skill from openJiuwen-ai/sciencediscovery. Read, diagnose, and change the CI pipeline: GitHub Actions on pull requests, the nightly schedule and the release tag. Use when a job fails, when editing .github/workflows/, when asking which layer runs what, when reproducing a pipeline failure locally, or when a job needs the bubblewrap sandbox. Running the layers before proposing a change, and reading the result a proposal receives, belong to create-github-pr.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/github.md`).

It sits in DevOps & Cloud, covering CI/CD and Pull requests. It works with GitHub Actions and GitHub. The repository describes itself as: ScienceDiscovery is an all‑in‑one agentic workbench built specifically for scientific research. The licence is Apache-2.0.

When your agent uses it

  • Editing .github/workflows/
  • Asking which layer runs what
  • Reproducing a pipeline failure locally
  • A job needs the bubblewrap sandbox

Example prompts

  • “/ci”

Requirements

  • Python 3
  • Docker

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Never weaken a sandbox assertion to make a pipeline green. Tests that
  2. Call the pnpm ci:* entry points, never their underlying commands. Do not
  3. UT is one layer. A UT test needing the sandbox says so with
  4. Read the failing job log before theorising. If the log is not accessible
  5. Preserve the real test exit code when adding artifact upload steps. Stage
  6. Reproduce a pipeline failure with the same layer entry point, on a checkout

What it can do on your machine

Read from SKILL.md and the folder at commit ab1403f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • node
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

CI loads about 2.2k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 105 tokens; SKILL.md has 1,202 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openJiuwen-ai/sciencediscovery at commit ab1403f, republished under its Apache-2.0 licence (© openJiuwen-ai). 1,202 words, ~2,187 tokens.

Download SKILL.mdSave it as .claude/skills/ci/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
ci
description
Read, diagnose, and change the CI pipeline: GitHub Actions on pull requests, the nightly schedule and the release tag. Use when a job fails, when editing .github/workflows/, when asking which layer runs what, when reproducing a pipeline failure locally, or when a job needs the bubblewrap sandbox. Running the layers before proposing a change, and reading the result a proposal receives, belong to create-github-pr.

ScienceDiscovery CI

Project-local skill for ScienceDiscovery.

CONTRIBUTING.md owns the layer entry points (pnpm ci:ut, ci:st, ci:e2e) and the writable CI_RESULTS_DIR / CI_RUNTIME_DIR overrides. .ci/README.md documents the toolchain image and the scheduler's tag catalog. This skill covers what the pipeline does with those entry points: how to read a run, how to validate a workflow change, and how to attribute a failure. Running the layers before proposing a change, and reading what the proposal receives, are in create-github-pr.

What runs where

Here, the CI e2e layer and pnpm ci:e2e mean the mocked browser subset. E2E as a validation method also includes user journeys through public API, CLI and local-stack product entry points; see the E2E skill. Those journeys have their own documented driver commands and are not automatically run by the browser layer. Adapter smokes in ci:st are not E2E merely because they call a model.

GitHub Actions is the only CI, and it is the gate, on the pull request. gitcode.com is a read-only mirror: nothing runs there and nothing is decided there. The CodeArts pipeline that used to run on a GitCode merge request, and the QEMU guest it needed because its pool could not create user namespaces, were removed — GitHub's ubuntu-latest runs every layer natively. What that removal cost, and nothing has replaced, is the externally registered code-check child (SCA, anti-poison, static analysis, blacklist); nothing runs those on a change today.

One workflow defines the gate. nightly.yml and release.yml are not a second and third definition: both call ci.yml through workflow_call, so what they run is the row below, and the reason they exist is in their own file headers.

PipelineGateTriggerProfileJobs
.github/workflows/ci.ymlyespush to main, pull request, or workflow_dispatchprci:ut and ci:st (each recording coverage), mocked ci:e2e, Coverage (merges UT's and ST's data, runs nothing), x86_64 + aarch64 release binaries (smoke-gated), the Docker image
.github/workflows/nightly.yml—16:00 UTC daily, or manualdailycalls ci.yml, adds real E2E, with a nightly-<date>-<sha> version
.github/workflows/release.yml—push of a version tagreleasecalls ci.yml with the tag's version, then publishes if it passes

The binary and Docker jobs are distribution gates and sit outside the plan: the four-entry smoke that proves a built binary boots is a job's exit code, not a planned identity, so planned == executed == passed says nothing about it.

One plan, three layers

ci:ut, ci:st and ci:e2e are not three suites. Each runs test/support/tagged/shared.mjs against the pr profile in test/support/tagged/profiles.mjs, narrowed to that layer's category. That profile is stated as tag dimensions rather than as a selector string, and pnpm test:policy prints it — read that before theorising about what a job covers. Each pipeline names its own: a pull request takes pr, nightly.yml takes daily, and release.yml takes the credential-free release profile (same policy as pr). Daily adds the disjoint e2e-real slice. The job passes it as an argument, so the command in the log is the command that reproduces the run. The three hermetic groups partition the PR plan, so these layers together run exactly pnpm test:shared, the command a developer runs locally.

What this means when reading a failure: selection comes from the tags in each test's source and from nothing else. A job's credentials, devices, installed services and CI_* variables cannot add a case or remove one — a missing capability fails the plan's preflight instead, before any test body runs. A skipped case is a failed run. So "the layer passed but ran fewer tests" is not a possible outcome any more; node .ci/tagged-summary.mjs fails the job unless planned == executed == passed, including when no plan was produced at all. Real E2E runs only in daily CI with explicit credentials. Live ST, NPU, legacy and macOS work is tagged out of the shared selector and keeps its own opt-in entry points; test/support/tagged/MIGRATION.md is the ledger of what is in and what is out.

Show full SKILL.md (563 more words)Show less

Shared rules

  1. Never weaken a sandbox assertion to make a pipeline green. Tests that assert isolation or the sandbox's /workspace view must run on a host where bubblewrap can create namespaces. Every job that needs it installs bubblewrap and clears kernel.apparmor_restrict_unprivileged_userns before using it.
  2. Call the pnpm ci:* entry points, never their underlying commands. Do not create a second test definition, and do not add a list of cases beside the tags: pnpm ci:catalog:check fails a layer that runs anything other than a slice of the shared plan, an entry point that drifts off that slice, and a package test file that sits outside the collection patterns the plan is built from. pnpm ci:selftest is that guard's regression suite. pnpm test:run --<group> <value> builds its own selector from the tag vocabulary and can therefore reach outside the shared plan. That is the developer entry point; CI uses --slice, which is appended to the shared selector with and and is always a subset of it. Do not put a query in a workflow.
  3. UT is one layer. A UT test needing the sandbox says so with sandbox:bubblewrap, which the plan turns into a preflight the whole run fails on; it does not move the test to a different job. Do not add a ci:ut:* entry point beside ci:ut.
  4. Read the failing job log before theorising. If the log is not accessible with the available credentials, ask for it instead of inferring the failure from a status badge.
  5. Preserve the real test exit code when adding artifact upload steps. Stage the result, upload diagnostics, then restore that exit code.
  6. Reproduce a pipeline failure with the same layer entry point, on a checkout of the commit the run tested, with CI_RESULTS_DIR / CI_RUNTIME_DIR pointed somewhere writable. Each layer leaves run.log and a summary under CI_RESULTS_DIR/<layer>/, and its frozen plan under CI_RESULTS_DIR/<layer>/tagged/.

Platform routing

For .github/workflows/, GitHub-hosted runner behavior, gh run, or GitHub artifacts, read references/github.md completely before acting.

Common failure signals

SymptomMeaning
bwrap: No permissions to create new namespaceThe host forbids user namespaces. On Ubuntu 24.04 that is the AppArmor restriction the jobs clear with sysctl kernel.apparmor_restrict_unprivileged_userns=0; do not weaken Runner tests instead.
Playwright is green with fewer tests than expectedA skip is not a pass, and the plan already says so. Read <CI_RESULTS_DIR>/e2e/tagged/summary.json: it names every planned journey that did not report one.
EMPTY_SELECTION, EMPTY_MODULE or COLLECTION_DRIFTA collection problem, not a product failure. The plan is frozen from source, so a selector that matches nothing, a module that registers no test, and a source that changed between freezing and running are all failures of the run.
PREPARATION_FAILEDThe shared runner's own setup — install, build, the five service virtualenvs, the pinned Chromium — did not complete. The message names the log to read; nothing was collected yet, so this is never a product assertion.
API test expects runner_exec, gets undefinedAn execution never ran; check sandbox availability first.
BLOCKED: isolated E2E stack did not become healthyThe Runner refused to serve; inspect the sandbox probe before application logs.
ERR_PNPM_OUTDATED_LOCKFILEpnpm-lock.yaml is behind a package.json; regenerate it with pnpm install --lockfile-only.
The E2E job spends its first minute downloading conda packagesExpected. E2E_SCIENTIFIC_ENVS=1 provisions the managed Python base so the environment journey runs instead of reporting a skip; it is about 330 MB on a runner with no cache.

© openJiuwen-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .agents/skills/ci of openJiuwen-ai/sciencediscovery.

  • SKILL.md
  • references/github.md

Open the folder on GitHubat commit ab1403f

Compare with similar skills

CI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

CI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
CI this skillopenJiuwen-ai/sciencediscovery159—~2.2kAutomated safety check: PassApache-2.0
CIaiblueprinthq/ai-blueprint463—~2.2kAutomated safety check: PassMIT
Michel Monitor Pull Request GitHub ActionsPackmindHub/packmind318—~2.6kAutomated safety check: PassApache-2.0
Diy Netlifyswyxio/skills176—~1.1kAutomated safety check: PassMIT
ONNX Runtime CI Managementmicrosoft/onnxruntime22k—~4.1kAutomated safety check: PassMIT
Renovate Actions PR Reviewbacknotprop/plannotator9.3k—~640Automated safety check: PassApache-2.0

Similar skills

  • CI

    aiblueprinthq/ai-blueprint

    Set up or normalize one project Verify command and matching GitHub Actions checks while preserving existing CI, with an optional local pre-push hook.

    463 GitHub stars~2.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Diagnose a failed, stuck, or never-triggered CI run on a GitHub PR, apply a local fix if possible, push it, and document the result in a single running PR comment.

    318 GitHub stars~2.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Diy Netlify

    swyxio/skills

    Build or audit an isolated Netlify/Vercel-style pull-request preview workflow using GitHub Actions and the project's existing hosting provider.

    176 GitHub stars~1.1k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • ONNX Runtime CI Management

    microsoft/onnxruntime

    Official

    Triggers, re-runs and unblocks the CI checks on an ONNX Runtime pull request, after diagnosing whether a failure is transient or needs a code change.

    22k GitHub stars~4.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Renovate Actions PR Review

    backnotprop/plannotator

    Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.

    9.3k GitHub stars~640 tokensUpdated today
    DevelopmentAuto-check passed
  • Generates and optimizes GitHub Actions workflows with swarm coordination, using named modes for PR management, issue tracking, releases and repository structure.

    818 GitHub starsUsed in 6 repos~6k tokens
    DevOps & CloudAuto-check passed

More from openJiuwen-ai/sciencediscovery

All 23 skills in this repo
  • Code Engineer

    openJiuwen-ai/sciencediscovery

    A skill your agent uses when you need to write and execute Python/R code to process, transform, and analyze data, delivering reproducible computational results with complete code-level methodology…

    159 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Gitcode

    openJiuwen-ai/sciencediscovery

    Operate GitCode issues, PRs, wikis, code/MR refs, and cached org templates.

    159 GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Structure Pocket Inspection

    openJiuwen-ai/sciencediscovery

    Inspect a local PDB structure, summarize chains and residue composition, and identify protein atoms near a user-specified ligand or pocket center.

    159 GitHub stars~624 tokensUpdated today
    Auto-check passed
  • Antibody Design

    openJiuwen-ai/sciencediscovery

    Prepare, launch, monitor, and summarize the real RFdiffusion to ProteinMPNN to Protenix antibody pipeline on a local or remote ScienceDiscovery Runner with sandboxed Ascend NPUs.

    159 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Science Research Team

    openJiuwen-ai/sciencediscovery

    A skill your agent uses to orchestrate a multi-domain research team for literature/evidence research and data analysis.

    159 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Literature Searcher

    openJiuwen-ai/sciencediscovery

    A skill your agent uses when a research workflow needs verified academic source retrieval through literature-search MCP interfaces available in the current session before evidence extraction.

    159 GitHub stars~5.8k tokensUpdated today
    Auto-check passed

Questions about CI

What does CI do?

Read, diagnose, and change the CI pipeline: GitHub Actions on pull requests, the nightly schedule and the release tag. CI is an agent skill from openJiuwen-ai/sciencediscovery. Read, diagnose, and change the CI pipeline: GitHub Actions on pull requests, the nightly schedule and the release tag.

When should I use CI?

CI fits situations like: editing .github/workflows/; asking which layer runs what; reproducing a pipeline failure locally; A job needs the bubblewrap sandbox.

How do I install CI in Claude Code?

Run `npx skills add openJiuwen-ai/sciencediscovery --skill ci -a claude-code`. Or copy the skill folder (.agents/skills/ci in openJiuwen-ai/sciencediscovery) into .claude/skills/ci in your project. Claude Code loads it when a task matches its description.

How do I install CI in Codex?

Run `npx skills add openJiuwen-ai/sciencediscovery --skill ci -a codex`. Or copy the skill folder (.agents/skills/ci in openJiuwen-ai/sciencediscovery) into .agents/skills/ci in your project. Codex loads it when a task matches its description.

Can I use CI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openJiuwen-ai/sciencediscovery --skill ci -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ci, .gemini/skills/ci, .github/skills/ci and .opencode/skills/ci in your project.

What does CI need to run?

Going by SKILL.md and its folder, CI needs the command-line tools its instructions call (pnpm, node and gh). Our summary lists: Python 3; Docker.

Does CI access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is CI safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does CI use?

CI is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does CI use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 837 tokens, read only when the agent opens those files.

What are the alternatives to CI?

Skills that share tags, products or a category with CI: CI (aiblueprinthq/ai-blueprint, 463 stars), Michel Monitor Pull Request GitHub Actions (PackmindHub/packmind, 318 stars), Diy Netlify (swyxio/skills, 176 stars) and ONNX Runtime CI Management (microsoft/onnxruntime, 22k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains CI?

openJiuwen-ai (a GitHub organization) maintains it in openJiuwen-ai/sciencediscovery, which has 159 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 10, 2026.

Source: openJiuwen-ai/sciencediscovery on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.