Agent skill

Pinact

by saleor in saleor/apps

Read pinact's documentation with pinact docs list and pinact docs show <name before answering.

Custom licenceAuto-check passedDevOps & Cloud

Install Pinact

skills CLI
$ npx skills add saleor/apps --skill pinact -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install saleor/apps pinact --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/saleor/apps.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/pinact .claude/skills/pinact && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pinact
GitHub stars
162
Token cost
~685 tokens
SKILL.md length
311 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
Custom licence

At a glance

Read pinact's documentation with pinact docs list and pinact docs show <name before answering.

  • Any question about pinact
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • PINACT environment variables
  • Pinact run / init / migrate / token

What it does

Pinact is an agent skill from saleor/apps. Read pinact's documentation with pinact docs list and pinact docs show <name before answering. pinact is a CLI that pins GitHub Actions and reusable workflows to full commit SHAs, updates them, and verifies their version comments. Use for any question about pinact, PINACT environment variables, pinact run / init / migrate / token, the configuration file .pinact.yaml, pinact's exit codes, or errors from pinact. Use it too when a workflow fails a pinact check in CI, or when an action isn't pinned and it isn't clear…

Its SKILL.md is about 690 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering CI/CD and Secrets management. It works with GitHub Actions. The repository describes itself as: OSS mirror for public Saleor Apps.

When your agent uses it

  • Any question about pinact
  • PINACT environment variables
  • Pinact run / init / migrate / token
  • The configuration file .pinact.yaml

Example prompts

  • “t pinned and it isn”
  • “/pinact”

What it can do on your machine

Read from SKILL.md and the folder at commit 4400af6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pinact loads about 685 tokens when it runs. Until then it costs about 137 tokens; SKILL.md has 311 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~137
When it runs · the whole SKILL.md, loaded when a task matches
~685

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 311 words (~685 tokens).

“Don't answer from your training knowledge about pinact itself - its commands, flags, environment variables, configuration, or what its errors mean. Run pinact docs list to list the documentation, then pinact docs show to read the relevant topics before answering…”

— opening of SKILL.md by saleor, Custom licence
name
pinact
metadata.github-path
skills/pinact
metadata.github-ref
refs/tags/v5.0.0
metadata.github-repo
https://github.com/suzuki-shunsuke/pinact
metadata.github-tree-sha
18df7e16e6048abf1740043ce814853ee63e80aa

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .claude/skills/pinact of saleor/apps.

Open the folder on GitHubat commit 4400af6

Compare with similar skills

Pinact next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pinact compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pinact this skillsaleor/apps162—~685Automated safety check: PassCustom licence
Azure Bicep Skilltimothywarner-org/claude-code224—~2.9kAutomated safety check: PassMIT
Secure GitHub Actionsvechain/x-app-template450—~1.2kAutomated safety check: PassMIT
Managing Workflow Secretsbitwarden/ai-plugins155—~4kAutomated safety check: PassCustom licence
Sicurezza GitHubccplugins/awesome-claude-code-plugins970—~486Automated safety check: NotesApache-2.0
Nextjs Deploymentgiuseppe-trisciuoglio/developer-kit357—~2.3kAutomated safety check: NotesMIT

Similar skills

  • Azure Bicep Skill

    timothywarner-org/claude-code

    A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.

    224 GitHub stars~2.9k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Secure GitHub Actions

    vechain/x-app-template

    Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.

    450 GitHub stars~1.2k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Managing Workflow Secrets

    bitwarden/ai-plugins

    Official

    Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions…

    155 GitHub stars~4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Sicurezza GitHub

    ccplugins/awesome-claude-code-plugins

    Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot.

    970 GitHub stars~486 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Nextjs Deployment

    giuseppe-trisciuoglio/developer-kit

    Provides comprehensive patterns for deploying Next.js applications to production.

    357 GitHub stars~2.3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • CD Pipeline Generator

    ArabelaTso/Skills-4-SE

    Generate GitHub Actions deployment workflows for automated deployment to staging and production environments on cloud platforms (AWS, GCP, Azure).

    253 GitHub stars~1.3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from saleor/apps

  • Scaffold a new shared package in the saleor-apps monorepo under ./packages/.

    162 GitHub stars~608 tokensUpdated 3 days ago
    Auto-check passed
  • A skill your agent uses when adding a changeset, writing changelog or release notes, or when a functional change (feature, fix) is ready to commit.

    162 GitHub stars~514 tokensUpdated 3 days ago
    Auto-check passed
  • A skill your agent uses when writing or editing GraphQL operations (queries, mutations, fragments, webhook subscriptions) in a Saleor app — adding a .graphql file, adding fields to an existing one…

    162 GitHub stars~544 tokensUpdated 3 days ago
    Auto-check passed
  • Saleor App UI

    saleor/apps

    Styling and layout guide for Saleor Apps using modern macaw-ui and @saleor/apps-ui-next.

    162 GitHub stars~5.8k tokensUpdated 3 days ago
    Auto-check passed
  • A skill your agent uses when asked to create a pull request, write a PR description, or update/rewrite an existing PR description.

    162 GitHub stars~630 tokensUpdated 3 days ago
    Auto-check passed

Works with

Categories

Questions about Pinact

What does Pinact do?

Read pinact's documentation with pinact docs list and pinact docs show <name before answering. Pinact is an agent skill from saleor/apps. Read pinact's documentation with pinact docs list and pinact docs show <name before answering.

When should I use Pinact?

Pinact fits situations like: any question about pinact; PINACT environment variables; pinact run / init / migrate / token; the configuration file .pinact.yaml.

How do I install Pinact in Claude Code?

Run `npx skills add saleor/apps --skill pinact -a claude-code`. Or copy the skill folder (.claude/skills/pinact in saleor/apps) into .claude/skills/pinact in your project. Claude Code loads it when a task matches its description.

How do I install Pinact in Codex?

Run `npx skills add saleor/apps --skill pinact -a codex`. Or copy the skill folder (.claude/skills/pinact in saleor/apps) into .agents/skills/pinact in your project. Codex loads it when a task matches its description.

Can I use Pinact in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add saleor/apps --skill pinact -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pinact, .gemini/skills/pinact, .github/skills/pinact and .opencode/skills/pinact in your project.

What does Pinact need to run?

SKILL.md names no scripts, command-line tools or credentials: Pinact is instructions for the agent only.

Does Pinact access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Pinact safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pinact use?

Pinact has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Pinact use?

About 685 tokens (SKILL.md is roughly 2.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pinact?

Skills that share tags, products or a category with Pinact: Azure Bicep Skill (timothywarner-org/claude-code, 224 stars), Secure GitHub Actions (vechain/x-app-template, 450 stars), Managing Workflow Secrets (bitwarden/ai-plugins, 155 stars) and Sicurezza GitHub (ccplugins/awesome-claude-code-plugins, 970 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pinact?

saleor (a GitHub organization) maintains it in saleor/apps, which has 162 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 7, 2026.

Source: saleor/apps on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.