Agent skill

Authoring GitHub Workflows

by rodri-oliveira-dev in rodri-oliveira-dev/Dapper-FluentMap

Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run.

MITAuto-check passedDevOps & Cloud

Install Authoring GitHub Workflows

skills CLI
$ npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill authoring-github-workflows -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rodri-oliveira-dev/Dapper-FluentMap authoring-github-workflows --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rodri-oliveira-dev/Dapper-FluentMap.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/authoring-github-workflows .claude/skills/authoring-github-workflows && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
authoring-github-workflows
GitHub stars
453
Token cost
~1.1k tokens
SKILL.md length
349 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run.

  • Works in 4 steps: Identify changed workflows → Inspect repository semantics before… → Validate with actionlint → …
  • Reviewing any file under .github/workflows/
  • SKILL.md covers When to Use, The # trap, Workflow and Validation, plus 1 more section
  • Calls git, curl and actionlint; reaches github.com

What it does

Authoring GitHub Workflows is an agent skill from rodri-oliveira-dev/Dapper-FluentMap. Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run. USE FOR: editing, adding, or reviewing any file under .github/workflows/, writing run-name/name/if/env/run values that contain ${{ }} expressions, diagnosing workflow-load failures, deciding when a workflow scalar must be quoted, and validating workflows with actionlint. DO NOT USE FOR: non-GitHub-Actions YAML. SCOPE: syntactic/structural workflow correctness; pair with…

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering CI/CD. It works with GitHub Actions. The repository describes itself as: Fluent mapping for Dapper, with conventions, immutable object materialization, analyzers, source generators, DI integration, and Dommel support. The licence is MIT.

When your agent uses it

  • Reviewing any file under .github/workflows/
  • Writing run-name/name/if/env/run values that contain ${{ }} expressions
  • Diagnosing workflow-load failures
  • Deciding when a workflow scalar must be quoted

Example prompts

  • “/authoring-github-workflows”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Identify changed workflows
  2. Inspect repository semantics before editing
  3. Validate with actionlint
  4. Review security-sensitive workflow behavior

What it can do on your machine

Read from SKILL.md and the folder at commit 90600cb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • curl
    • actionlint

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • docs.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Authoring GitHub Workflows loads about 1.1k tokens when it runs. Until then it costs about 148 tokens; SKILL.md has 349 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~148
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rodri-oliveira-dev/Dapper-FluentMap at commit 90600cb, republished under its MIT licence (© rodri-oliveira-dev). 349 words, ~1,128 tokens.

Download SKILL.mdSave it as .claude/skills/authoring-github-workflows/SKILL.md (or your agent's skills folder).
name
authoring-github-workflows
description
Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run. USE FOR: editing, adding, or reviewing any file under .github/workflows/, writing run-name/name/if/env/run values that contain ${{ }} expressions, diagnosing workflow-load failures, deciding when a workflow scalar must be quoted, and validating workflows with actionlint. DO NOT USE FOR: non-GitHub-Actions YAML. SCOPE: syntactic/structural workflow correctness; pair with ci-release-governance for semantic CI/release design.
license
MIT

Authoring GitHub Actions Workflows Safely

GitHub Actions workflow files are YAML, but valid YAML is not the same as a valid workflow. A file can parse as YAML yet still be rejected by GitHub Actions before any job starts.

Repository integration: AGENTS.md and the existing Dapper-FluentMap workflows are authoritative. Preserve the repository's SHA-pinned actions, least-privilege permissions, release/recovery semantics, main default branch, Sonar Quality Gate, and multi-package publishing rules. Use ci-release-governance for what a workflow should do; use this skill for whether the workflow is structurally valid and safely authored.

When to Use

  • Editing, adding, or reviewing .github/workflows/*.yml.
  • Writing run-name, name, if, env, with, or run values containing ${{ }} expressions.
  • Diagnosing a workflow rejected before jobs start.
  • Reviewing download steps, permissions, expressions, quoting, or reusable workflow syntax.

The # trap

In an unquoted YAML scalar, a space followed by # begins a comment and can truncate a GitHub expression.

yaml
# BAD
run-name: ${{ inputs.pr_number != '' && format('Evaluate PR #{0}', inputs.pr_number) || '' }}

# GOOD
run-name: "${{ inputs.pr_number != '' && format('Evaluate PR #{0}', inputs.pr_number) || '' }}"

Quote expression-bearing scalars whenever literal #, colon-space, leading special characters, or significant whitespace make YAML interpretation ambiguous.

Workflow

1. Identify changed workflows
bash
git diff --name-only origin/main... -- .github/workflows/
2. Inspect repository semantics before editing

For release-related changes, read the existing release.yml, recovery workflow, eng/package-catalog.json, and relevant publishing scripts. Do not replace established behavior with a generic workflow pattern.

3. Validate with actionlint

Prefer a repository-owned pinned validation command when available. For manual validation:

bash
ACTIONLINT_VERSION=1.7.12
ACTIONLINT_SHA256=8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8
curl \
  --fail \
  --silent \
  --show-error \
  --location \
  --proto '=https' \
  --proto-redir '=https' \
  --output actionlint.tar.gz \
  "https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz"
echo "${ACTIONLINT_SHA256}  actionlint.tar.gz" | sha256sum -c -
tar -xzf actionlint.tar.gz actionlint
./actionlint -shellcheck= -pyflakes= -color .github/workflows/*.yml

Pin both version and checksum. Restrict both initial and redirected downloads to HTTPS.

The repository also uses GitHub-workflow JSON schema validation; preserve that existing gate rather than substituting actionlint for it.

4. Review security-sensitive workflow behavior
  • keep actions SHA-pinned;
  • keep permissions minimal and job-scoped when practical;
  • do not expose secrets to fork PRs;
  • do not add continue-on-error to bypass required quality/release checks;
  • do not weaken NuGet OIDC, artifact validation, release recovery, or Sonar Quality Gate behavior;
  • for network downloads that follow redirects, enforce HTTPS redirects and validate checksums where feasible.

Validation

  • Changed workflow files pass repository schema validation
  • actionlint exits 0 when used
  • Risky ${{ }} scalars are quoted
  • Actions remain SHA-pinned
  • Permissions remain least privilege
  • Redirect-following downloads enforce HTTPS
  • Existing release, recovery, CI Gate, and Sonar semantics remain intact unless intentionally changed

References

© rodri-oliveira-dev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/authoring-github-workflows of rodri-oliveira-dev/Dapper-FluentMap.

Open the folder on GitHubat commit 90600cb

Compare with similar skills

Authoring GitHub Workflows next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Authoring GitHub Workflows compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Authoring GitHub Workflows this skillrodri-oliveira-dev/Dapper-FluentMap453—~1.1kAutomated safety check: PassMIT
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
GitHub Actions Templatesbartstc/vite-ts-react-template12213 repos~1.9kAutomated safety check: PassMIT
Nushellccusage/ccusage19k—~938Automated safety check: PassCustom licence
Repo Hygiene Scan and FixQwenLM/qwen-code28k—~1.7kAutomated safety check: PassApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2596 repos~1.1kAutomated safety check: NotesCustom licence

Similar skills

  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • GitHub Actions Templates

    bartstc/vite-ts-react-template

    Create production-ready GitHub Actions workflows for automated testing, building, and deploying applications.

    122 GitHub starsUsed in 13 repos~1.9k tokens
    DevOps & CloudAuto-check passed
  • Nushell

    ccusage/ccusage

    Guides ccusage Nushell scripts. An agent skill from ccusage/ccusage.

    19k GitHub stars~938 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Scheduled CI skill that scans a repository for small, certain docs, test and code hygiene issues and fixes them on one branch with a commit per finding.

    28k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    259 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • CI Failure Triage and Repair

    Chachamaru127/claude-code-harness

    Diagnoses failing CI pipelines and tests, deciding first whether the test or the implementation is at fault, and hands hard cases to a dedicated fixer subagent.

    3.2k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check: notes

More from rodri-oliveira-dev/Dapper-FluentMap

All 11 skills in this repo
  • Directory Build Organization

    rodri-oliveira-dev/Dapper-FluentMap

    Guide for organizing MSBuild infrastructure with Directory.Build.props, Directory.Build.targets, Directory.Packages.props when present, and related repository build files.

    453 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Microbenchmarking

    rodri-oliveira-dev/Dapper-FluentMap

    Activate when BenchmarkDotNet is involved or when a .NET performance question requires controlled microbenchmark measurement.

    453 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Nuget Trusted Publishing

    rodri-oliveira-dev/Dapper-FluentMap

    Review, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions.

    453 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Test Gap Analysis

    rodri-oliveira-dev/Dapper-FluentMap

    Pseudo-mutation analysis for behavioral blind spots: determine whether existing tests would catch meaningful caller-visible production changes, identify survivors or untested outcomes, and…

    453 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Binlog Failure Analysis

    rodri-oliveira-dev/Dapper-FluentMap

    Analyze MSBuild binary logs to diagnose build failures. An agent skill from rodri-oliveira-dev/Dapper-FluentMap.

    453 GitHub stars~750 tokensUpdated yesterday
    Auto-check passed
  • CI Release Governance

    rodri-oliveira-dev/Dapper-FluentMap

    A skill your agent uses to review or adjust Dapper-FluentMap GitHub Actions, packaging, NuGet publishing, versioning, release, rollback, recovery, provenance, and automation security.

    453 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Authoring GitHub Workflows

What does Authoring GitHub Workflows do?

Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run. Authoring GitHub Workflows is an agent skill from rodri-oliveira-dev/Dapper-FluentMap. Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run.

When should I use Authoring GitHub Workflows?

Authoring GitHub Workflows fits situations like: reviewing any file under .github/workflows/; writing run-name/name/if/env/run values that contain ${{ }} expressions; diagnosing workflow-load failures; deciding when a workflow scalar must be quoted.

How do I install Authoring GitHub Workflows in Claude Code?

Run `npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill authoring-github-workflows -a claude-code`. Or copy the skill folder (.agents/skills/authoring-github-workflows in rodri-oliveira-dev/Dapper-FluentMap) into .claude/skills/authoring-github-workflows in your project. Claude Code loads it when a task matches its description.

How do I install Authoring GitHub Workflows in Codex?

Run `npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill authoring-github-workflows -a codex`. Or copy the skill folder (.agents/skills/authoring-github-workflows in rodri-oliveira-dev/Dapper-FluentMap) into .agents/skills/authoring-github-workflows in your project. Codex loads it when a task matches its description.

Can I use Authoring GitHub Workflows in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill authoring-github-workflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/authoring-github-workflows, .gemini/skills/authoring-github-workflows, .github/skills/authoring-github-workflows and .opencode/skills/authoring-github-workflows in your project.

What does Authoring GitHub Workflows need to run?

Going by SKILL.md and its folder, Authoring GitHub Workflows needs the command-line tools its instructions call (git, curl and actionlint).

Does Authoring GitHub Workflows access the network?

SKILL.md names 2 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: docs.github.com. This is read from the text; nothing was executed.

Is Authoring GitHub Workflows safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Authoring GitHub Workflows use?

Authoring GitHub Workflows is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Authoring GitHub Workflows use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Authoring GitHub Workflows?

Skills that share tags, products or a category with Authoring GitHub Workflows: Analyze GitHub Action Logs (withastro/astro, 63k stars), GitHub Actions Templates (bartstc/vite-ts-react-template, 122 stars), Nushell (ccusage/ccusage, 19k stars) and Repo Hygiene Scan and Fix (QwenLM/qwen-code, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Authoring GitHub Workflows?

rodri-oliveira-dev (a GitHub user) maintains it in rodri-oliveira-dev/Dapper-FluentMap, which has 453 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 6, 2026.

Source: rodri-oliveira-dev/Dapper-FluentMap on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.