Analyze GitHub Action Logs
withastro/astro
Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.
GitHub Actions, Renovate, the two-branch release model, signing, and promotion.
$ npx skills add projectbluefin/finpilot --skill ci -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install projectbluefin/finpilot ci --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/projectbluefin/finpilot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ci .claude/skills/ci && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ci" agent skill from https://github.com/projectbluefin/finpilot/tree/main/.agents/skills/ci into .claude/skills/ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/projectbluefin/finpilot/tree/main/.agents/skills/ciType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add projectbluefin/finpilot --skill ci -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install projectbluefin/finpilot ci --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/projectbluefin/finpilot.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/ci .agents/skills/ci && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ci" agent skill from https://github.com/projectbluefin/finpilot/tree/main/.agents/skills/ci into .agents/skills/ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add projectbluefin/finpilot --skill ci -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install projectbluefin/finpilot ci --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/projectbluefin/finpilot.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/ci .cursor/skills/ci && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ci" agent skill from https://github.com/projectbluefin/finpilot/tree/main/.agents/skills/ci into .cursor/skills/ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/projectbluefin/finpilot.git --path .agents/skills/ci--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add projectbluefin/finpilot --skill ci -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install projectbluefin/finpilot ci --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/projectbluefin/finpilot.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/ci .gemini/skills/ci && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ci" agent skill from https://github.com/projectbluefin/finpilot/tree/main/.agents/skills/ci into .gemini/skills/ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install projectbluefin/finpilot ciInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add projectbluefin/finpilot --skill ci -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/projectbluefin/finpilot.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/ci .github/skills/ci && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ci" agent skill from https://github.com/projectbluefin/finpilot/tree/main/.agents/skills/ci into .github/skills/ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add projectbluefin/finpilot --skill ci -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install projectbluefin/finpilot ci --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/projectbluefin/finpilot.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/ci .opencode/skills/ci && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ci" agent skill from https://github.com/projectbluefin/finpilot/tree/main/.agents/skills/ci into .opencode/skills/ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ciGitHub Actions, Renovate, the two-branch release model, signing, and promotion.
CI is an agent skill from projectbluefin/finpilot. GitHub Actions, Renovate, the two-branch release model, signing, and promotion. Use when changing workflows, dependency policy, or releasing.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering CI/CD. It works with GitHub Actions. The repository describes itself as: Build your own custom Bluefin. The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 8e0eb5d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
justghgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
RENOVATE_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
CI loads about 1.5k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 808 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from projectbluefin/finpilot at commit 8e0eb5d, republished under its Apache-2.0 licence (© projectbluefin). 808 words, ~1,493 tokens.
.claude/skills/ci/SKILL.md (or your agent's skills folder).| Workflow | Trigger | Does |
|---|---|---|
build-image.yml | push to main or stable, dispatch | Builds, signs, and pushes the image. |
execute-release.yml | push to stable | Promotes the candidate digest. Does not rebuild. |
promote-main-to-stable.yml | daily schedule, dispatch | Opens the squash promotion PR and runs the release gate on it. |
sync-stable-to-main.yml | push to stable | Merges stable hotfixes back into main. |
pr-validation.yml | pull request | The validate check: shellcheck and hadolint. |
validate-brewfiles.yml | pull request | Brewfiles, without evaluating them. |
validate-flatpaks.yml | pull request | Flatpak preinstall files against Flathub. |
validate-justfiles.yml | pull request | just check. |
validate-renovate.yml | pull request | Renovate config. |
unit-tests.yml | push, pull request | The bats suite. |
renovate.yml | schedule, config change | Runs Renovate. |
clean.yml | schedule | Deletes images older than 90 days. |
Most are thin callers of reusable workflows in projectbluefin/actions.
main publishes :stable-testing. stable never rebuilds: promotion is a
squash PR from main to stable, and execute-release.yml copies the digest
:testing resolves to. The README owns the release table and the promotion
gate's current limits.
The factory reusable puts its release gate and its auto-merge enrollment behind
one input, enqueue_promotion. A personal repository cannot enroll — there is no
merge queue, and gh pr merge --auto refuses without a merge method — so
enrollment is off, and promote-main-to-stable.yml runs the gate itself in its
own gate job to keep the pre-merge check. That gate resolves :testing when it
runs, so it attests the current candidate. The binding comes from
execute-release.yml passing source_branch: main, which makes the reusable
refuse to promote at all once main has moved past the promotion commit; a
manual dispatch is exempt, because that path is deliberate recovery.
The same reusable builds the squash branch, and it stages deletions with
git diff --diff-filter=D. Git reports a moved file as a rename, so a path main
moved survives on its old path and the branch's tree stops matching main's —
the state the guard above refuses, but only after the PR is merged.
repair-promotion-branch in promote-main-to-stable.yml rebuilds the branch from
main's tree when it has drifted, and the validate check fails a promotion PR
whose tree does not match main. The sweep belongs to projectbluefin/actions;
the one-line fix there is --no-renames.
Keyless OIDC via Cosign. There are no keys to generate or store; the workflow
needs id-token: write and packages: write. Unsigned images fail the promotion
gate. The README has the command to verify an image.
The promotion gate is the only enforcement point. Nothing checks the signature
on an installed system, so 00-image-info.sh writes an unverified update
transport (ostree-unverified-image:docker://…) and the README says so.
ostree-image-signed: would send the client to /etc/containers/policy.json,
which Common supplies with no scope for this namespace — it would verify against
the "" catch-all, insecureAcceptAnything, and report success having checked
nothing. Adding a scope does not rescue it while signing stays keyless:
containers/image matches a Fulcio certificate on subjectEmail alone
(mandatory, exact, with a standing FIXME for URI SANs in
signature/fulcio_cert.go), and a GitHub Actions certificate names its workflow
in a URI SAN with no email to match. Device-side verification is a key-based
signing change first, a policy change second.
tests/contract/image-signing_test.bats fails if either side moves alone.
The identity regexp the release workflows pass to the reusables is scoped with
github.repository, not github.repository_owner. Matching the owner and then
any repository accepts a signature minted by any repository in the org, and
github.repository keeps the scope correct in a fork without hardcoding it.
Self-hosted through projectbluefin/actions, running every six hours. It pins
GitHub Actions to SHAs and updates image digests. The policy lives in
.github/renovate.json: updates below a major automerge once checks pass;
majors wait for a pull request — except quay.io/fedora-ostree-desktops/*,
where cross-major bumps do not open a PR at all (the rule is enabled: false).
A Fedora major rebase for that namespace is a deliberate manual step: bump the
tag in Containerfile by hand when the next major is released and validated.
Renovate needs the RENOVATE_TOKEN secret and auto-merge enabled. Both are
onboarding steps. The secret is optional: with it unset the workflow logs a skip
and the run stays green, which is how upstream runs, where an org-wide app does
the work instead. The check sits in its own token job because a job that calls
a reusable workflow cannot hold steps, and jobs.<job_id>.if cannot read the
secrets context — secrets in a job-level if is a parse error, not a skip.
Automerge deliberately covers GitHub Actions SHA bumps, which reverses a guard
upstream kept. Those SHAs run in jobs holding packages: write,
id-token: write, and secrets: inherit, and PR builds are disabled, so a bump
merges with only shellcheck, hadolint, and the test suite having run. Putting the
guard back is one rule — matchManagers: ["github-actions"] with
automerge: false.
main.validate and the image build.main publishes :stable-testing.:stable.© projectbluefin, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/ci of projectbluefin/finpilot.
Open the folder on GitHubat commit 8e0eb5d
CI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| CI this skillprojectbluefin/finpilot | 126 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Analyze GitHub Action Logswithastro/astro | 63k | 1 repos | ~1.3k | Automated safety check: Pass | Custom licence | |
| GitHub Actions Templatesbartstc/vite-ts-react-template | 122 | 14 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Nushellccusage/ccusage | 19k | — | ~938 | Automated safety check: Pass | Custom licence | |
| Repo Hygiene Scan and FixQwenLM/qwen-code | 28k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence |
withastro/astro
Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.
bartstc/vite-ts-react-template
Create production-ready GitHub Actions workflows for automated testing, building, and deploying applications.
ccusage/ccusage
Guides ccusage Nushell scripts. An agent skill from ccusage/ccusage.
QwenLM/qwen-code
Scheduled CI skill that scans a repository for small, certain docs, test and code hygiene issues and fixes them on one branch with a commit per finding.
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
Chachamaru127/claude-code-harness
Diagnoses failing CI pipelines and tests, deciding first whether the test or the implementation is at fault, and hands hard cases to a dedicated fixer subagent.
projectbluefin/finpilot
Decide where a package, app, or command belongs — dnf5 at build time, Homebrew, Flatpak, or ujust — and how each is validated.
projectbluefin/finpilot
Bootstrap a new image from this template: rename the project, enable Actions and Renovate, protect the branch, and reach a first green build.
projectbluefin/finpilot
Architecture, repository layout, and file map for this template.
projectbluefin/finpilot
Symptom to cause to fix for build, CI, and runtime failures, plus the pre-commit checklist.
Works with
Categories
GitHub Actions, Renovate, the two-branch release model, signing, and promotion. CI is an agent skill from projectbluefin/finpilot. GitHub Actions, Renovate, the two-branch release model, signing, and promotion.
CI fits situations like: changing workflows; dependency policy.
Run `npx skills add projectbluefin/finpilot --skill ci -a claude-code`. Or copy the skill folder (.agents/skills/ci in projectbluefin/finpilot) into .claude/skills/ci in your project. Claude Code loads it when a task matches its description.
Run `npx skills add projectbluefin/finpilot --skill ci -a codex`. Or copy the skill folder (.agents/skills/ci in projectbluefin/finpilot) into .agents/skills/ci in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add projectbluefin/finpilot --skill ci -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ci, .gemini/skills/ci, .github/skills/ci and .opencode/skills/ci in your project.
Going by SKILL.md and its folder, CI needs the command-line tools its instructions call (just, gh and git) and credentials named RENOVATE_TOKEN. Our summary lists: Docker; A credential in RENOVATE_TOKEN.
SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
CI is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with CI: Analyze GitHub Action Logs (withastro/astro, 63k stars), GitHub Actions Templates (bartstc/vite-ts-react-template, 122 stars), Nushell (ccusage/ccusage, 19k stars) and Repo Hygiene Scan and Fix (QwenLM/qwen-code, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
projectbluefin (a GitHub organization) maintains it in projectbluefin/finpilot, which has 126 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 8, 2026.
Source: projectbluefin/finpilot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.