Agent skill

Simplify And Harden CI

by pskoett in pskoett/pskoett-ai-skills

CI-only Simplify & Harden workflow for pull requests using gh-aw (GitHub Agentic Workflows).

No licenceAuto-check passedDevelopment

Install Simplify And Harden CI

skills CLI
$ npx skills add pskoett/pskoett-ai-skills --skill simplify-and-harden-ci -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pskoett/pskoett-ai-skills simplify-and-harden-ci --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pskoett/pskoett-ai-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/simplify-and-harden-ci .claude/skills/simplify-and-harden-ci && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
simplify-and-harden-ci
GitHub stars
315
Token cost
~1.1k tokens
SKILL.md length
325 words
Files
2 (incl. references)
Skills in repo
24
Repo updated
First seen
Licence
None found

At a glance

CI-only Simplify & Harden workflow for pull requests using gh-aw (GitHub Agentic Workflows).

  • Works in 4 steps: GitHub Actions enabled for the repository → GitHub CLI authenticated (gh auth status) → gh-aw installed locally for… → …
  • : you want automated quality/security review in CI without interactive approvals
  • SKILL.md covers Install, Purpose, Context Limitation (Important) and Prerequisites, plus 5 more sections
  • Calls gh and npx

What it does

Simplify And Harden CI is an agent skill from pskoett/pskoett-ai-skills. CI-only Simplify & Harden workflow for pull requests using gh-aw (GitHub Agentic Workflows). Runs headless scan-and-report checks for simplify/harden/document, posts structured findings, and can block merges on critical or advisory classes. Use when: you want automated quality/security review in CI without interactive approvals.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/workflow-example.md`).

It sits in Development, covering Pull requests and Security review. It works with GitHub and GitHub Actions.

When your agent uses it

  • : you want automated quality/security review in CI without interactive approvals
  • Tasks that involve Pull requests
  • Tasks that involve Security review

Example prompts

  • “/simplify-and-harden-ci”

Requirements

  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. GitHub Actions enabled for the repository
  2. GitHub CLI authenticated (gh auth status)
  3. gh-aw installed locally for authoring/validation
  4. In GitHub Actions jobs, install the CLI with

What it can do on your machine

Read from SKILL.md and the folder at commit 5a836dc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Simplify And Harden CI loads about 1.1k tokens when it runs, and up to ~1.4k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 325 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 325 words (~1,084 tokens).

“Fallback using the Agent Skills CLI:”

— opening of SKILL.md by pskoett
name
simplify-and-harden-ci

Read the full SKILL.md on GitHub

Files

SKILL.md and 1 other file (references) in skills/simplify-and-harden-ci of pskoett/pskoett-ai-skills.

  • SKILL.md
  • references/workflow-example.md

Open the folder on GitHubat commit 5a836dc

Compare with similar skills

Simplify And Harden CI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Simplify And Harden CI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Simplify And Harden CI this skillpskoett/pskoett-ai-skills315—~1.1kAutomated safety check: PassNone
Qv Devops PR Reviewtetherto/qvac685—~2.5kAutomated safety check: PassApache-2.0
GitHub Actions Hardeninggithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT
Verdaccio Code Reviewverdaccio/verdaccio18k—~853Automated safety check: PassMIT
ReviewdogAgentSecOps/SecOpsAgentKit2201 repos~3kAutomated safety check: PassCustom licence
Openiap Workflowshyodotdev/openiap155—~1.9kAutomated safety check: PassMIT

Similar skills

  • Qv Devops PR Review

    tetherto/qvac

    PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).

    685 GitHub stars~2.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • GitHub Actions Hardening

    github/awesome-copilot

    Official

    Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).

    40k GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • Verdaccio Code Review

    verdaccio/verdaccio

    Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

    18k GitHub stars~853 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Reviewdog

    AgentSecOps/SecOpsAgentKit

    Automated code review and security linting integration for CI/CD pipelines using reviewdog.

    220 GitHub starsUsed in 1 repo~3k tokens
    DevelopmentAuto-check passed
  • Openiap Workflows

    hyodotdev/openiap

    A skill your agent uses for OpenIAP monorepo work that should follow the repository's shared agent workflows, including review-pr, audit-code, audit-security, audit-iapkit, compile-knowledge…

    155 GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Gh

    bubbuild/bub

    GitHub CLI skill for interacting with GitHub via the gh command line tool.

    1.7k GitHub stars~798 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from pskoett/pskoett-ai-skills

All 24 skills in this repo
  • Self Improvement

    pskoett/pskoett-ai-skills

    Captures learnings, errors, corrections, and feature requests to enable continuous improvement.

    315 GitHub stars~5k tokensUpdated 6 days ago
    Auto-check passed
  • Self Improvement

    pskoett/pskoett-ai-skills

    Captures learnings, errors, corrections, and feature requests to enable continuous improvement.

    315 GitHub stars~5.4k tokensUpdated 6 days ago
    Auto-check passed
  • Self Healing

    pskoett/pskoett-ai-skills

    Active runtime recovery for coding agents: when something breaks mid-task, diagnose the root cause, write a fix, VERIFY by re-running the broken thing, then file a HEAL- entry to .learnings/HEALS.md…

    315 GitHub stars~5.3k tokensUpdated 6 days ago
    Auto-check: notes
  • Skill Tester

    pskoett/pskoett-ai-skills

    Validates all interactive skills in this repo against the Agent Skills spec, project conventions, and structural requirements.

    315 GitHub stars~1.3k tokensUpdated 6 days ago
    Auto-check passed
  • Skill Tester CI

    pskoett/pskoett-ai-skills

    Validates all CI skills in this repo. An agent skill from pskoett/pskoett-ai-skills.

    315 GitHub stars~845 tokensUpdated 6 days ago
    Auto-check passed
  • Context Decay

    pskoett/pskoett-ai-skills

    Revalidate persistent agent knowledge by classifying why it can become stale and how quickly it changes, then retain, revise, externalize, or retire it.

    315 GitHub stars~3.3k tokensUpdated 6 days ago
    Auto-check passed

Questions about Simplify And Harden CI

What does Simplify And Harden CI do?

CI-only Simplify & Harden workflow for pull requests using gh-aw (GitHub Agentic Workflows). Simplify And Harden CI is an agent skill from pskoett/pskoett-ai-skills. CI-only Simplify & Harden workflow for pull requests using gh-aw (GitHub Agentic Workflows).

When should I use Simplify And Harden CI?

Simplify And Harden CI fits situations like: : you want automated quality/security review in CI without interactive approvals; tasks that involve Pull requests; tasks that involve Security review.

How do I install Simplify And Harden CI in Claude Code?

Run `npx skills add pskoett/pskoett-ai-skills --skill simplify-and-harden-ci -a claude-code`. Or copy the skill folder (skills/simplify-and-harden-ci in pskoett/pskoett-ai-skills) into .claude/skills/simplify-and-harden-ci in your project. Claude Code loads it when a task matches its description.

How do I install Simplify And Harden CI in Codex?

Run `npx skills add pskoett/pskoett-ai-skills --skill simplify-and-harden-ci -a codex`. Or copy the skill folder (skills/simplify-and-harden-ci in pskoett/pskoett-ai-skills) into .agents/skills/simplify-and-harden-ci in your project. Codex loads it when a task matches its description.

Can I use Simplify And Harden CI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pskoett/pskoett-ai-skills --skill simplify-and-harden-ci -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/simplify-and-harden-ci, .gemini/skills/simplify-and-harden-ci, .github/skills/simplify-and-harden-ci and .opencode/skills/simplify-and-harden-ci in your project.

What does Simplify And Harden CI need to run?

Going by SKILL.md and its folder, Simplify And Harden CI needs the command-line tools its instructions call (gh and npx). Our summary lists: Node.js.

Does Simplify And Harden CI access the network?

SKILL.md contains no URLs. Its commands use gh and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Simplify And Harden CI safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Simplify And Harden CI use?

No licence was found for Simplify And Harden CI or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Simplify And Harden CI use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 330 tokens, read only when the agent opens those files.

What are the alternatives to Simplify And Harden CI?

Skills that share tags, products or a category with Simplify And Harden CI: Qv Devops PR Review (tetherto/qvac, 685 stars), GitHub Actions Hardening (github/awesome-copilot, 40k stars), Verdaccio Code Review (verdaccio/verdaccio, 18k stars) and Reviewdog (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Simplify And Harden CI?

pskoett (a GitHub user) maintains it in pskoett/pskoett-ai-skills, which has 315 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 5, 2026.

Source: pskoett/pskoett-ai-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.