Agent skill

Managing Pipelines

by rileyhilliard in rileyhilliard/claude-essentials

Guides GitHub Actions CI/CD architecture, security hardening, and deployment strategies.

MITAuto-check passedDevOps & Cloud

Install Managing Pipelines

skills CLI
$ npx skills add rileyhilliard/claude-essentials --skill managing-pipelines -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rileyhilliard/claude-essentials managing-pipelines --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rileyhilliard/claude-essentials.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ce/skills/managing-pipelines .claude/skills/managing-pipelines && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
managing-pipelines
GitHub stars
130
Token cost
~1.5k tokens
SKILL.md length
681 words
Files
7 (incl. references)
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

Guides GitHub Actions CI/CD architecture, security hardening, and deployment strategies.

  • Works in 5 steps: Check cache hit rates (low = cold start… → Look for sequential jobs that could run… → Verify concurrency groups aren't queuing… → …
  • Designing workflows
  • SKILL.md covers Contents, When to use which pattern, Security quick reference and Performance quick reference, plus 5 more sections
  • Needs GITHUB_TOKEN

What it does

Managing Pipelines is an agent skill from rileyhilliard/claude-essentials. Guides GitHub Actions CI/CD architecture, security hardening, and deployment strategies. Use when designing workflows, securing supply chains, optimizing build performance, or configuring deployments.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/deployment-strategies.md`, `references/infrastructure-pipelines.md` and `references/performance-optimization.md`).

It sits in DevOps & Cloud, covering CI/CD, Deployment and Security review. It works with GitHub Actions. The licence is MIT.

When your agent uses it

  • Designing workflows
  • Securing supply chains
  • Optimizing build performance
  • Configuring deployments

Example prompts

  • “Use the managing-pipelines skill to guide GitHub Actions CI/CD architecture, security hardening, and deployment strategies”
  • “/managing-pipelines”

Requirements

  • A credential in GITHUB_TOKEN

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Check cache hit rates (low = cold start overhead)
  2. Look for sequential jobs that could run in parallel
  3. Verify concurrency groups aren't queuing unnecessarily
  4. Check runner specs (CPU-bound work on small runners)
  5. Look for full-repo checkouts when sparse checkout would work

What it can do on your machine

Read from SKILL.md and the folder at commit 3a67a01. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Managing Pipelines loads about 1.5k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 681 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~15k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rileyhilliard/claude-essentials at commit 3a67a01, republished under its MIT licence (© rileyhilliard). 681 words, ~1,528 tokens.

Download SKILL.mdSave it as .claude/skills/managing-pipelines/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
managing-pipelines
description
Guides GitHub Actions CI/CD architecture, security hardening, and deployment strategies. Use when designing workflows, securing supply chains, optimizing build performance, or configuring deployments.

Pipeline Management

Decision guidance for GitHub Actions CI/CD pipelines, deployment strategies, and infrastructure automation.

Contents

  • When to use which pattern
  • Security quick reference
  • Performance quick reference
  • Workflow architecture quick reference
  • Deployment quick reference
  • Infrastructure as code quick reference
  • Observability quick reference
  • Cross-pipeline conventions
  • Pipeline debugging checklist

When to use which pattern

ScenarioReferenceWhy
Hardening against supply chain attacksSecuritySHA pinning, permissions, OIDC
Speeding up slow CI buildsPerformanceCaching, matrix builds, concurrency
DRY-ing up duplicated workflow YAMLWorkflow architectureReusable workflows vs composite actions
Setting up staging/production deploysDeploymentEnvironment promotion, protection rules
Adding Terraform/OpenTofu to CIInfrastructurePlan-on-PR, apply-on-merge, drift detection
Tracking pipeline reliabilityObservabilityOTel, DORA metrics, SLOs
Reviewing a PR that modifies workflowsSecurity + WorkflowPermissions audit, secret exposure review
Debugging flaky pipelinesObservability + PerformanceMetrics, cache hit rates, concurrency
Migrating from Jenkins/CircleCIWorkflow architectureAction patterns, reusable workflow design
Setting up monorepo CIPerformancePath filtering, selective job execution

Security quick reference

Use for: Preventing supply chain attacks, minimizing credential exposure, hardening runner environments.

Key decisions:

  • Pin all third-party actions to full commit SHAs, not tags
  • Set org-level default token permissions to read-only
  • Use OIDC for cloud auth instead of stored credentials
  • Never use pull_request_target without understanding the security model

See references/security-hardening.md for attack patterns and mitigations.

Performance quick reference

Use for: Reducing CI times, optimizing runner costs, parallelizing builds.

Key decisions:

  • Cache dependency installs AND build artifacts (not just node_modules)
  • Use fail-fast: false for CI matrices, true for deployment
  • Set concurrency groups with cancel-in-progress: true for CI, false for deploys
  • Use path filtering in monorepos to skip irrelevant jobs

See references/performance-optimization.md for caching strategies and runner selection.

Workflow architecture quick reference

Use for: Structuring reusable CI/CD components, managing action dependencies.

Key decisions:

  • Reusable workflows for entire pipeline templates; composite actions for shared steps
  • Pass secrets explicitly, not with secrets: inherit
  • Automate SHA pin updates with Dependabot or Renovate
  • Restrict allowed actions at the org level

See references/workflow-architecture.md for patterns and versioning.

Deployment quick reference

Use for: Environment promotion, deployment gates, progressive delivery.

Key decisions:

  • Use GitHub Environments with branch restrictions for production
  • Release-based promotion gives the cleanest audit trail
  • Progressive delivery (canary/blue-green) via Argo Rollouts or Flagger
  • Custom deployment protection rules for SLO-gated deployments

See references/deployment-strategies.md for promotion patterns and rollback strategies.

Infrastructure as code quick reference

Use for: Terraform/OpenTofu pipelines, drift detection, policy enforcement.

Key decisions:

  • Always save plan output and apply the saved plan (never plan-then-apply without -out)
  • Post plan output as PR comments for review
  • Segment state by functional boundary, not geography
  • Run scheduled drift detection separately from code-triggered deploys

See references/infrastructure-pipelines.md for IaC workflow patterns.

Show full SKILL.md (245 more words)Show less

Observability quick reference

Use for: Pipeline reliability tracking, incident response, capacity planning.

Key decisions:

  • Instrument pipelines with OpenTelemetry (runs as traces, jobs as spans)
  • Track DORA metrics: deployment frequency, lead time, change failure rate, MTTR
  • Set SLOs for pipeline reliability (e.g., 99% main branch build success)
  • Monitor cache hit rates and queue times as leading indicators

See references/pipeline-observability.md for instrumentation and metrics.

Pipeline debugging checklist

Slow CI builds
  1. Check cache hit rates (low = cold start overhead)
  2. Look for sequential jobs that could run in parallel
  3. Verify concurrency groups aren't queuing unnecessarily
  4. Check runner specs (CPU-bound work on small runners)
  5. Look for full-repo checkouts when sparse checkout would work
Failed deployments
  1. Check environment protection rule approvals
  2. Verify OIDC token audience and subject claims
  3. Check if concurrency group blocked/cancelled the run
  4. Review Terraform plan output for unexpected changes
  5. Check if deployment protection rules (Datadog, etc.) rejected
Security incidents
  1. Audit recent changes to workflow files and action versions
  2. Check for new pull_request_target usage
  3. Review GITHUB_TOKEN permissions in affected workflows
  4. Scan for secrets in workflow logs (step outputs, artifacts)
  5. Check if any action SHAs were recently changed
Flaky pipelines
  1. Check if tests have timing dependencies (see async waiting patterns in writing-tests skill)
  2. Look for shared state between matrix jobs
  3. Verify caches aren't corrupted (clear and rebuild)
  4. Check for rate limiting from external services
  5. Review runner availability (self-hosted runner capacity)

© rileyhilliard, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in plugins/ce/skills/managing-pipelines of rileyhilliard/claude-essentials.

  • SKILL.md
  • references/deployment-strategies.md
  • references/infrastructure-pipelines.md
  • references/performance-optimization.md
  • references/pipeline-observability.md
  • references/security-hardening.md
  • references/workflow-architecture.md

Open the folder on GitHubat commit 3a67a01

Compare with similar skills

Managing Pipelines next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Managing Pipelines compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Managing Pipelines this skillrileyhilliard/claude-essentials130—~1.5kAutomated safety check: PassMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Azure Bicep Skilltimothywarner-org/claude-code224—~2.9kAutomated safety check: PassMIT
Devops EngineerYikai-Liao/symusic1891 repos~1.5kAutomated safety check: PassMIT
APIOps Deployment for Azure APIMthomast1906/github-copilot-agent-skills202—~3.6kAutomated safety check: PassMIT
Devops InfrastructureCloudAI-X/claude-workflow-v21.4k—~2.7kAutomated safety check: NotesMIT

Similar skills

  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Azure Bicep Skill

    timothywarner-org/claude-code

    A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.

    224 GitHub stars~2.9k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Devops Engineer

    Yikai-Liao/symusic

    Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates.

    189 GitHub starsUsed in 1 repo~1.5k tokens
    DevOps & CloudAuto-check passed
  • APIOps Deployment for Azure APIM

    thomast1906/github-copilot-agent-skills

    Supplies Bicep and Terraform templates, CI/CD pipeline patterns and phased promotion plans for deploying Azure API Management with APIOps workflows.

    202 GitHub stars~3.6k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Devops Infrastructure

    CloudAI-X/claude-workflow-v2

    Guides Docker, CI/CD pipelines, deployment strategies, infrastructure as code, and observability setup.

    1.4k GitHub stars~2.7k tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes
  • CI/CD Pipeline Principles

    irahardianto/awesome-agv

    Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

    156 GitHub stars~2.7k tokensUpdated 5 days ago
    DevOps & CloudAuto-check: notes

More from rileyhilliard/claude-essentials

All 17 skills in this repo
  • Handling Errors

    rileyhilliard/claude-essentials

    Prevents silent failures and context loss in error handling.

    130 GitHub stars~632 tokensUpdated 1 mo ago
    Auto-check passed
  • Planning Products

    rileyhilliard/claude-essentials

    Defines product features from a PM perspective (JTBD, competitive research, scope negotiation) before technical planning.

    130 GitHub stars~1.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Writing Tests

    rileyhilliard/claude-essentials

    Writes behavior-focused tests using Testing Trophy model with real dependencies.

    130 GitHub stars~999 tokensUpdated 1 mo ago
    Auto-check passed
  • Optimizing Performance

    rileyhilliard/claude-essentials

    Measure-first performance optimization that balances gains against complexity.

    130 GitHub stars~470 tokensUpdated 1 mo ago
    Auto-check passed
  • Architecting Systems

    rileyhilliard/claude-essentials

    Guides clean, scalable system architecture during the build phase.

    130 GitHub stars~713 tokensUpdated 1 mo ago
    Auto-check passed
  • Design

    rileyhilliard/claude-essentials

    Enforces precise, minimal design for dashboards and admin interfaces.

    130 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Managing Pipelines

What does Managing Pipelines do?

Guides GitHub Actions CI/CD architecture, security hardening, and deployment strategies. Managing Pipelines is an agent skill from rileyhilliard/claude-essentials. Guides GitHub Actions CI/CD architecture, security hardening, and deployment strategies.

When should I use Managing Pipelines?

Managing Pipelines fits situations like: designing workflows; securing supply chains; optimizing build performance; configuring deployments.

How do I install Managing Pipelines in Claude Code?

Run `npx skills add rileyhilliard/claude-essentials --skill managing-pipelines -a claude-code`. Or copy the skill folder (plugins/ce/skills/managing-pipelines in rileyhilliard/claude-essentials) into .claude/skills/managing-pipelines in your project. Claude Code loads it when a task matches its description.

How do I install Managing Pipelines in Codex?

Run `npx skills add rileyhilliard/claude-essentials --skill managing-pipelines -a codex`. Or copy the skill folder (plugins/ce/skills/managing-pipelines in rileyhilliard/claude-essentials) into .agents/skills/managing-pipelines in your project. Codex loads it when a task matches its description.

Can I use Managing Pipelines in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rileyhilliard/claude-essentials --skill managing-pipelines -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/managing-pipelines, .gemini/skills/managing-pipelines, .github/skills/managing-pipelines and .opencode/skills/managing-pipelines in your project.

What does Managing Pipelines need to run?

Going by SKILL.md and its folder, Managing Pipelines needs credentials named GITHUB_TOKEN. Our summary lists: A credential in GITHUB_TOKEN.

Does Managing Pipelines access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Managing Pipelines safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Managing Pipelines use?

Managing Pipelines is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Managing Pipelines use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 14k tokens, read only when the agent opens those files.

What are the alternatives to Managing Pipelines?

Skills that share tags, products or a category with Managing Pipelines: Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Azure Bicep Skill (timothywarner-org/claude-code, 224 stars), Devops Engineer (Yikai-Liao/symusic, 189 stars) and APIOps Deployment for Azure APIM (thomast1906/github-copilot-agent-skills, 202 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Managing Pipelines?

rileyhilliard (a GitHub user) maintains it in rileyhilliard/claude-essentials, which has 130 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on August 18, 2026.

Source: rileyhilliard/claude-essentials on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.