Agent skill

Rigor CI Setup

by rigortype in rigortype/rigor

Set up Rigor in a project's CI and surface diagnostics on pull or merge requests.

MPL-2.0Auto-check passedDevOps & Cloud

Install Rigor CI Setup

skills CLI
$ npx skills add rigortype/rigor --skill rigor-ci-setup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rigortype/rigor rigor-ci-setup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rigortype/rigor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/rigor-ci-setup .claude/skills/rigor-ci-setup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rigor-ci-setup
GitHub stars
106
Token cost
~2.2k tokens
SKILL.md length
1,101 words
Files
1
Skills in repo
36
Repo updated
First seen
Licence
MPL-2.0

At a glance

Set up Rigor in a project's CI and surface diagnostics on pull or merge requests.

  • Works in 5 steps: Detect the project's CI platform → Pick the surface (what the reviewer… → Apply the matching template → …
  • Changing GitHub Actions
  • SKILL.md covers First: load the…, The one hard rule: Rigor gets…, Phase 0 — Detect the project's… and Phase 1 — Pick the surface…, plus 5 more sections
  • Calls gem

What it does

Rigor CI Setup is an agent skill from rigortype/rigor. Set up Rigor in a project's CI and surface diagnostics on pull or merge requests. Use when adding or changing GitHub Actions, GitLab CI, SARIF, or reviewdog wiring; not for first-time Rigor configuration or baseline reduction.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering CI/CD. It works with GitHub Actions, GitLab and Ruby. The repository describes itself as: Inference-first static analysis for Ruby. The licence is MPL-2.0.

When your agent uses it

  • Changing GitHub Actions
  • Reviewdog wiring
  • Not for first-time Rigor configuration
  • Baseline reduction

Example prompts

  • “/rigor-ci-setup”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Detect the project's CI platform
  2. Pick the surface (what the reviewer should see)
  3. Apply the matching template
  4. Pin Rigor's version (reproducible CI)
  5. Gate behaviour (optional, with the user)

What it can do on your machine

Read from SKILL.md and the folder at commit 57a67cf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gem

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rigor CI Setup loads about 2.2k tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 1,101 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rigortype/rigor at commit 57a67cf, republished under its MPL-2.0 licence (© rigortype). 1,101 words, ~2,153 tokens.

Download SKILL.mdSave it as .claude/skills/rigor-ci-setup/SKILL.md (or your agent's skills folder).
name
rigor-ci-setup
description
Set up Rigor in a project's CI and surface diagnostics on pull or merge requests. Use when adding or changing GitHub Actions, GitLab CI, SARIF, or reviewdog wiring; not for first-time Rigor configuration or baseline reduction.
license
MPL-2.0
metadata.version
0.1.0
metadata.homepage
https://github.com/rigortype/rigor

Rigor CI Setup

Wire Rigor into a project's CI so type diagnostics appear inline on the pull / merge request, not just in the job log. This skill is the workflow — detect the platform, choose the surface, apply the matching template, pin, gate, verify. It does not copy the CI YAML inline: the authoritative, version-matched templates live in the manual's CI chapter (rigor docs ci) and as ready-to-copy files, so this skill cannot drift out of date as --format surfaces and action versions move.

This is for users running Rigor on their own project with the published rigor executable — Rigor is a tool, not a library, so it is not added to the project's Gemfile.

First: load the version-current copy

Follow the copy that ships with the installed Rigor, not any vendored or frozen copy of this file. Two version-matched sources, both offline once Rigor is installed:

sh
rigor skill --full rigor-ci-setup   # this skill's current workflow, in one call
rigor docs ci                       # the manual's CI chapter — the actual templates

If you already loaded this skill via rigor skill you have the current copy — just proceed. If rigor is not on PATH, this task needs it: run rigor-next-steps to install Rigor first, then come back.

The one hard rule: Rigor gets its own job

Rigor runs on Ruby 4.0. ruby/setup-ruby sets the job's active Ruby, so a job that provisions the project's test Ruby (often 3.x, or a matrix) cannot also provision Rigor's 4.0 — the second setup-ruby clobbers the first. Always give Rigor a separate job (better: a separate workflow file, for its own triggers, concurrency, and status badge). Every template in rigor docs ci does this.

Phase 0 — Detect the project's CI platform

Inspect the repository first; do not ask what you can detect. Look for these markers from the project root and let them drive the platform choice:

Marker (check existence)Platform
.github/workflows/ directory existsGitHub Actions
.gitlab-ci.yml existsGitLab CI
.circleci/config.yml existsCircleCI (generic recipe, junit)
Jenkinsfile existsJenkins (generic recipe, junit / checkstyle)
bitbucket-pipelines.yml / azure-pipelines.yml / .drone.ymlthat platform (generic recipe)
none of the aboveno CI yet — ask the user which platform they use

Concretely:

  • List .github/workflows/*.yml and .gitlab-ci.yml. If .github/workflows/rigor.yml already exists, read it — this is an update, not a fresh add: preserve the user's triggers / pinning and only change the format / steps that are wrong or missing. The same applies to an existing rigor job inside .gitlab-ci.yml.
  • Check for an existing pin: .github/rigor/Gemfile (+ lockfile) means the project already pins Rigor — keep it (Phase 3).
  • Check for .rigor-baseline.yml — if present, the project is in baseline adoption mode, which changes the gate advice (Phase 4).
  • Grep existing CI files for reviewdog — if already used, prefer the reviewdog surface for consistency.

Routing: exactly one platform marker → use it, state what you found, and proceed. Multiple (e.g. both .github/workflows/ and .gitlab-ci.yml) → tell the user both were found and ask which to wire (or do both). None → ask.

Phase 1 — Pick the surface (what the reviewer should see)

All --format surfaces are pure renderings of the same diagnostics; the exit code is unchanged (0 clean, 1 on errors), so the job still gates. The full format→platform table and severity mapping are in rigor docs ci; this is the decision:

  • GitHub → lead with github (annotations). It works on every repository with zero setup — no upload, no permissions, no paid features. In fact Rigor auto-detects GitHub Actions / TeamCity and emits native annotations even without --format, so a plain rigor check already annotates the PR (--no-ci-detect turns that off). Only upgrade when there is a concrete reason:
    • sarif (Security tab, deduped/persistent alerts) — only when code scanning is available: a public repo (free) or a private repo with GitHub Advanced Security. Without it upload-sarif fails. If you cannot tell, do not default to SARIF — use github and offer SARIF to a public-repo / GHAS user.
    • reviewdog when the team wants threaded review comments filtered to changed lines (works on private repos; needs a token — Phase 2).
    • Annotation caveat: the run UI caps annotations per type, so on a first adoption of a large codebase prefer the baseline gate (Phase 4) or SARIF/reviewdog, which page through everything.
  • GitLab → gitlab (the MR Code Quality widget) or reviewdog.
  • Any test-report CI (CircleCI, Jenkins, …) → junit.
Show full SKILL.md (419 more words)Show less

Phase 2 — Apply the matching template

Take the template for your (platform, surface) choice from rigor docs ci (GitHub annotations / SARIF / reviewdog, and GitLab). Copy it in, adjust nothing but the trigger unless asked, and pin the version next (Phase 3).

reviewdog is platform-specific. It reads Rigor's checkstyle (preferred — light, no code scanning) or sarif, but the -reporter must match the platform: github-pr-review posts only to GitHub, gitlab-mr-discussion only to GitLab — there is no cross-platform reporter. So a reviewdog setup is tied to one platform; for a repo mirrored across two, wire one reviewdog job per platform (or use each platform's native format). The reporter table, tokens, and the -fail-level / -filter-mode knobs are in rigor docs ci — keep -filter-mode=added to adopt on an existing codebase (the reviewdog analogue of a baseline).

Phase 3 — Pin Rigor's version (reproducible CI)

The templates install the latest rigortype at run time. To pin it, use a CI-only Gemfile (.github/rigor/Gemfile, read only by the Rigor job, Dependabot-updatable) or a pinned gem install rigortype -v "X.Y.Z". The exact recipe (the BUNDLE_GEMFILE wiring, the Dependabot entry) is in rigor docs ci § "Pinning Rigor's version".

Phase 4 — Gate behaviour (optional, with the user)

  • Baseline adoption. If the project uses .rigor-baseline.yml, the same rigor check honours it — CI fails only on new diagnostics. Add --baseline-strict to also fail when the baseline drifts loose (forces regeneration). With reviewdog, -filter-mode=added plays the analogous role.
  • Determinism. Add --no-cache in CI if you want each run independent of any persisted .rigor/cache.
  • Cache persistence (opposite trade). When the Rigor job's runtime matters, persist .rigor/cache with the CI's cache facility. Rigor detects CI and validates the restored cache by content hash automatically (cache.validation: auto). A self-hosted runner that reuses its workspace opts back into the faster stat check with cache.validation: stat. Snippets: rigor docs ci § "Persisting the analysis cache across runs".

Verify

  1. The Rigor job runs on ruby-version: "4.0" in its own job (not merged into a test matrix job).
  2. On a PR that introduces a type error, the finding appears inline (an annotation / review comment / widget entry, per the chosen surface) and the job fails (exit 1).
  3. On a clean PR the job passes (exit 0).

References

© rigortype, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/rigor-ci-setup of rigortype/rigor.

Open the folder on GitHubat commit 57a67cf

Compare with similar skills

Rigor CI Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rigor CI Setup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rigor CI Setup this skillrigortype/rigor106—~2.2kAutomated safety check: PassMPL-2.0
Fingerprint CI Gateliarjsdev/liarjs-skills5181 repos~986Automated safety check: NotesMIT
Swig CI Reproswig/swig6.3k—~1.2kAutomated safety check: PassCustom licence
Megalinter Checknvuillam/npm-groovy-lint2481 repos~3.9kAutomated safety check: NotesMIT
Migrate To TeamcityJetBrains/teamcity-cli125—~1.3kAutomated safety check: PassApache-2.0
CI/CD Failure Troubleshootingruby-git/ruby-git1.8k—~1.9kAutomated safety check: PassMIT

Similar skills

  • Fingerprint CI Gate

    liarjsdev/liarjs-skills

    Gate a build on browser fingerprint regressions with liarjs - save a baseline scan as JSON, diff later runs against it, and fail the job when the consistency score falls below a floor.

    518 GitHub starsUsed in 1 repo~986 tokens
    DevOps & CloudAuto-check: notes
  • Swig CI Repro

    swig/swig

    Reproduce a GitHub Actions Linux CI failure locally when it does not happen on your machine: a podman/docker image that mirrors the ubuntu-22.04 runner by reusing the real Tools/CI-linux-.sh install…

    6.3k GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Megalinter Check

    nvuillam/npm-groovy-lint

    Collect MegaLinter lint errors for the current repository. An agent skill from nvuillam/npm-groovy-lint.

    248 GitHub starsUsed in 1 repo~3.9k tokens
    DevOps & CloudAuto-check: notes
  • Migrate To Teamcity

    JetBrains/teamcity-cli

    Official

    Migrating CI/CD pipelines to TeamCity. An agent skill from JetBrains/teamcity-cli.

    125 GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Diagnoses and fixes failing GitHub Actions runs by identifying the failure, fetching only the relevant logs, finding the root cause and reproducing it locally.

    1.8k GitHub stars~1.9k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • CI CD

    EliasOulkadi/shokunin

    Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary)…

    114 GitHub stars~3.4k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes

More from rigortype/rigor

All 36 skills in this repo
  • Rigor Regression Sweep

    rigortype/rigor

    Measure Rigor's baseline drift across the tagged history of a real OSS Ruby project.

    106 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Adjudicate a rigor unused report safely before proposing dead-code removal.

    106 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Rigor Baseline Reduce

    rigortype/rigor

    Reduce an existing .rigor-baseline.yml rule by rule by triaging sites, fixing or intentionally suppressing them, and regenerating the baseline.

    106 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Rigor Doctor

    rigortype/rigor

    Validate that a project's Rigor configuration, plugins, paths, and baseline are actually healthy.

    106 GitHub stars~767 tokensUpdated today
    Auto-check passed
  • Rigor Plugin Author

    rigortype/rigor

    Author a new Rigor plugin, choosing plugins/ for production support or examples/ for a contract walkthrough.

    106 GitHub stars~3.3k tokensUpdated today
    Auto-check: notes
  • Rigor Plugin Author

    rigortype/rigor

    Author a Rigor plugin in an adopting project or standalone rigor- gem for a DSL, framework, or metaprogramming pattern.

    106 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Categories

Questions about Rigor CI Setup

What does Rigor CI Setup do?

Set up Rigor in a project's CI and surface diagnostics on pull or merge requests. Rigor CI Setup is an agent skill from rigortype/rigor. Set up Rigor in a project's CI and surface diagnostics on pull or merge requests.

When should I use Rigor CI Setup?

Rigor CI Setup fits situations like: changing GitHub Actions; reviewdog wiring; not for first-time Rigor configuration; baseline reduction.

How do I install Rigor CI Setup in Claude Code?

Run `npx skills add rigortype/rigor --skill rigor-ci-setup -a claude-code`. Or copy the skill folder (skills/rigor-ci-setup in rigortype/rigor) into .claude/skills/rigor-ci-setup in your project. Claude Code loads it when a task matches its description.

How do I install Rigor CI Setup in Codex?

Run `npx skills add rigortype/rigor --skill rigor-ci-setup -a codex`. Or copy the skill folder (skills/rigor-ci-setup in rigortype/rigor) into .agents/skills/rigor-ci-setup in your project. Codex loads it when a task matches its description.

Can I use Rigor CI Setup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rigortype/rigor --skill rigor-ci-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rigor-ci-setup, .gemini/skills/rigor-ci-setup, .github/skills/rigor-ci-setup and .opencode/skills/rigor-ci-setup in your project.

What does Rigor CI Setup need to run?

Going by SKILL.md and its folder, Rigor CI Setup needs the command-line tools its instructions call (gem).

Does Rigor CI Setup access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Rigor CI Setup safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Rigor CI Setup use?

Rigor CI Setup is published under the MPL-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rigor CI Setup use?

About 2.2k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rigor CI Setup?

Skills that share tags, products or a category with Rigor CI Setup: Fingerprint CI Gate (liarjsdev/liarjs-skills, 518 stars), Swig CI Repro (swig/swig, 6.3k stars), Megalinter Check (nvuillam/npm-groovy-lint, 248 stars) and Migrate To Teamcity (JetBrains/teamcity-cli, 125 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rigor CI Setup?

rigortype (a GitHub organization) maintains it in rigortype/rigor, which has 106 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on October 8, 2026.

Source: rigortype/rigor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.