Agent skill

GitHub Actions

by tddworks in tddworks/ClaudeBar

Manage ClaudeBar's GitHub Actions CI/CD pipelines: build, test, and release workflows.

Apache-2.0Auto-check passedDevOps & Cloud

Install GitHub Actions

skills CLI
$ npx skills add tddworks/ClaudeBar --skill github-actions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tddworks/ClaudeBar github-actions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tddworks/ClaudeBar.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/github-actions .claude/skills/github-actions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
github-actions
GitHub stars
1.5k
Token cost
~1k tokens
SKILL.md length
222 words
Files
3 (incl. references)
Skills in repo
6
Repo updated
First seen
Licence
Apache-2.0

At a glance

Manage ClaudeBar's GitHub Actions CI/CD pipelines: build, test, and release workflows.

  • Works in 3 steps: Go to Actions → Release → Run workflow → Enter version (e.g. 1.2.0 or 1.2.0-beta.1) → Optionally toggle publish_appcast and…
  • Setting up secrets for CI/CD (certificate
  • SKILL.md covers Workflows at a Glance, Create a Release, Secrets Required and What the Release Pipeline Does, plus 2 more sections
  • Calls git; needs APPLE_CERTIFICATE_PASSWORD and APP_STORE_CONNECT_KEY_ID

What it does

GitHub Actions is an agent skill from tddworks/ClaudeBar. Manage ClaudeBar's GitHub Actions CI/CD pipelines: build, test, and release workflows. Use this skill when: (1) Setting up secrets for CI/CD (certificate, API key, Sparkle key, Codecov) (2) Creating a new release — tag-based or manual workflowdispatch (3) Triggering or explaining the build.yml, tests.yml, or release.yml workflows (4) Debugging release failures (signing, notarization, appcast) (5) Managing beta vs stable channels for Sparkle auto-updates (6) User says "release a new version", "push a tag", "set up…

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/release-workflow.md` and `references/secrets-setup.md`).

It sits in DevOps & Cloud, covering CI/CD. It works with GitHub Actions, App Store Connect and macOS. The repository describes itself as: A macOS menu bar application that monitors AI coding assistant usage quotas. Keep track of your Claude, Codex, Antigravity ,and Gemini usage at a glance. The licence is Apache-2.0.

When your agent uses it

  • Setting up secrets for CI/CD (certificate
  • Creating a new release — tag-based
  • Manual workflowdispatch
  • Explaining the build.yml

Example prompts

  • “release a new version”
  • “push a tag”
  • “set up CI secrets”
  • “/github-actions”

Requirements

  • A credential in SPARKLE_EDDSA_PRIVATE_KEY
  • A credential in CODECOV_TOKEN

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Go to Actions → Release → Run workflow
  2. Enter version (e.g. 1.2.0 or 1.2.0-beta.1)
  3. Optionally toggle publish_appcast and debug

What it can do on your machine

Read from SKILL.md and the folder at commit 1dcaa62. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • APPLE_CERTIFICATE_PASSWORD
    • APP_STORE_CONNECT_KEY_ID
    • SPARKLE_EDDSA_PRIVATE_KEY
    • CODECOV_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GitHub Actions loads about 1k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 144 tokens; SKILL.md has 222 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~144
When it runs · the whole SKILL.md, loaded when a task matches
~1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tddworks/ClaudeBar at commit 1dcaa62, republished under its Apache-2.0 licence (© tddworks). 222 words, ~1,039 tokens.

Download SKILL.mdSave it as .claude/skills/github-actions/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
github-actions
description
Manage ClaudeBar's GitHub Actions CI/CD pipelines: build, test, and release workflows. Use this skill when: (1) Setting up secrets for CI/CD (certificate, API key, Sparkle key, Codecov) (2) Creating a new release — tag-based or manual workflow_dispatch (3) Triggering or explaining the build.yml, tests.yml, or release.yml workflows (4) Debugging release failures (signing, notarization, appcast) (5) Managing beta vs stable channels for Sparkle auto-updates (6) User says "release a new version", "push a tag", "set up CI secrets", "why did the release fail"

ClaudeBar GitHub Actions

Three workflows live in .github/workflows/. See reference files for setup and troubleshooting.

Workflows at a Glance

WorkflowTriggerRunnerPurpose
build.ymlpush/PR to main, developmacos-15Debug + release build verification
tests.ymlpush/PR to main, developmacos-26Unit tests + Codecov coverage upload
release.ymlv* tag push OR manualmacos-15Sign → notarize → DMG → GitHub release → appcast

Create a Release

Option A — Tag (recommended):

bash
# 1. Update CHANGELOG.md with release notes for this version
# 2. Commit and push
git add CHANGELOG.md
git commit -m "docs: add release notes for v1.2.0"
git push origin main

# 3. Tag and push — this triggers release.yml automatically
git tag v1.2.0 && git push origin v1.2.0

# Beta / pre-release (automatically flagged on GitHub)
git tag v1.2.0-beta.1 && git push origin v1.2.0-beta.1

Option B — Manual dispatch:

  1. Go to Actions → Release → Run workflow
  2. Enter version (e.g. 1.2.0 or 1.2.0-beta.1)
  3. Optionally toggle publish_appcast and debug

Supported version formats: X.Y.Z, X.Y.Z-beta, X.Y.Z-beta.N, X.Y.Z-alpha.N, X.Y.Z-rc.N

Secrets Required

SecretRequired ForSee
APPLE_CERTIFICATE_P12Code signingsecrets-setup.md
APPLE_CERTIFICATE_PASSWORDCode signingsecrets-setup.md
APP_STORE_CONNECT_API_KEY_P8Notarizationsecrets-setup.md
APP_STORE_CONNECT_KEY_IDNotarizationsecrets-setup.md
APP_STORE_CONNECT_ISSUER_IDNotarizationsecrets-setup.md
SPARKLE_EDDSA_PRIVATE_KEYIn-app auto-updatessecrets-setup.md
CODECOV_TOKENCoverage uploadsecrets-setup.md
APP_IDENTITYOptional signing overridesecrets-setup.md

What the Release Pipeline Does

git tag v1.2.0
      │
      ▼
release.yml
  1. Extract + validate version (SemVer)
  2. Update Info.plist (CFBundleShortVersionString + CFBundleVersion = run_number)
  3. tuist install → tuist generate
  4. xcodebuild archive (arm64 + x86_64, unsigned)
  5. Import Developer ID cert into temp keychain
  6. codesign with entitlements
  7. notarytool submit + staple
  8. Create ZIP + DMG (signed), SHA256 checksums
  9. Extract release notes from CHANGELOG.md
 10. Publish GitHub Release (draft: false)
 11. Generate Sparkle appcast with EdDSA signature
 12. Deploy appcast to GitHub Pages

Debugging Failures

Enable verbose output via manual dispatch → debug: true. This prints:

  • P12 certificate details and contents
  • All identities in the signing keychain
  • Certificate subject and expiry dates

For detailed troubleshooting: release-workflow.md → Troubleshooting

Beta Channel

Pre-release tags (v1.2.0-beta.1) automatically:

  • Set GitHub release as prerelease: true
  • Add <sparkle:channel>beta</sparkle:channel> to the appcast entry
  • Are only offered to users with Beta Updates enabled in Settings

Stable releases always win over betas of the same version (stable gets higher build number).

See release-workflow.md for the full beta channel matrix.

© tddworks, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .claude/skills/github-actions of tddworks/ClaudeBar.

  • SKILL.md
  • references/release-workflow.md
  • references/secrets-setup.md

Open the folder on GitHubat commit 1dcaa62

Compare with similar skills

GitHub Actions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitHub Actions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitHub Actions this skilltddworks/ClaudeBar1.5k—~1kAutomated safety check: PassApache-2.0
CI CD Setuprshankras/claude-code-apple-skills783—~1.5kAutomated safety check: NotesMIT
Releasearul28/ADE114—~17kAutomated safety check: PassAGPL-3.0
Reproduce macOS Python FlavorsNuitka/Nuitka15k—~1.7kAutomated safety check: PassAGPL-3.0
Releasingmarciogranzotto/clawd-tank164—~923Automated safety check: PassMIT
CI Workflow Audithewigovens/jayjay172—~703Automated safety check: PassCustom licence

Similar skills

  • CI CD Setup

    rshankras/claude-code-apple-skills

    Generate CI/CD configuration for automated builds, tests, and distribution of iOS/macOS apps.

    783 GitHub stars~1.5k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: notes
  • Release

    arul28/ADE

    ADE release conductor: detect whether desktop, iOS, and/or the Cloudflare web tier actually changed, bump desktop patch versions, keep iOS marketing versions fixed while bumping build numbers, ship…

    114 GitHub stars~17k tokensUpdated today
    MobileAuto-check passed
  • Reproduce macOS Nuitka issues across Python distributions and GitHub Actions Python packaging.

    15k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Releasing

    marciogranzotto/clawd-tank

    Cuts a new versioned release of the Clawd Tank macOS menu bar app.

    164 GitHub stars~923 tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • CI Workflow Audit

    hewigovens/jayjay

    Audit GitHub Actions duplication, timing, filters, and gates.

    172 GitHub stars~703 tokensUpdated today
    DevOps & CloudAuto-check passed
  • GitHub Actions Pin Audit

    hewigovens/jayjay

    Audit unpinned GitHub Actions references or related bot PRs.

    172 GitHub stars~558 tokensUpdated today
    DevOps & CloudAuto-check passed

More from tddworks/ClaudeBar

  • Add Provider

    tddworks/ClaudeBar

    Add an AI provider to ClaudeBar as a JSON definition run by the one generic Provider and DataSource.

    1.5k GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • Add Report

    tddworks/ClaudeBar

    Guide for adding new report cards to ClaudeBar that analyze local data sources and display metrics with comparison deltas.

    1.5k GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Implement Feature

    tddworks/ClaudeBar

    Guide for implementing features in ClaudeBar following architecture-first design, TDD, rich domain models, and Swift 6.2 patterns.

    1.5k GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • Fix Bug

    tddworks/ClaudeBar

    Guide for fixing bugs in ClaudeBar following Chicago School TDD and rich domain design.

    1.5k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Improvement

    tddworks/ClaudeBar

    Guide for making improvements to existing ClaudeBar functionality using TDD.

    1.5k GitHub stars~2.1k tokensUpdated today
    Auto-check passed

Categories

Questions about GitHub Actions

What does GitHub Actions do?

Manage ClaudeBar's GitHub Actions CI/CD pipelines: build, test, and release workflows. GitHub Actions is an agent skill from tddworks/ClaudeBar. Manage ClaudeBar's GitHub Actions CI/CD pipelines: build, test, and release workflows.

When should I use GitHub Actions?

GitHub Actions fits situations like: setting up secrets for CI/CD (certificate; creating a new release — tag-based; manual workflowdispatch; explaining the build.yml.

How do I install GitHub Actions in Claude Code?

Run `npx skills add tddworks/ClaudeBar --skill github-actions -a claude-code`. Or copy the skill folder (.claude/skills/github-actions in tddworks/ClaudeBar) into .claude/skills/github-actions in your project. Claude Code loads it when a task matches its description.

How do I install GitHub Actions in Codex?

Run `npx skills add tddworks/ClaudeBar --skill github-actions -a codex`. Or copy the skill folder (.claude/skills/github-actions in tddworks/ClaudeBar) into .agents/skills/github-actions in your project. Codex loads it when a task matches its description.

Can I use GitHub Actions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tddworks/ClaudeBar --skill github-actions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-actions, .gemini/skills/github-actions, .github/skills/github-actions and .opencode/skills/github-actions in your project.

What does GitHub Actions need to run?

Going by SKILL.md and its folder, GitHub Actions needs the command-line tools its instructions call (git) and credentials named APPLE_CERTIFICATE_PASSWORD, APP_STORE_CONNECT_KEY_ID, SPARKLE_EDDSA_PRIVATE_KEY and CODECOV_TOKEN. Our summary lists: A credential in SPARKLE_EDDSA_PRIVATE_KEY; A credential in CODECOV_TOKEN.

Does GitHub Actions access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is GitHub Actions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does GitHub Actions use?

GitHub Actions is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitHub Actions use?

About 1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.

What are the alternatives to GitHub Actions?

Skills that share tags, products or a category with GitHub Actions: CI CD Setup (rshankras/claude-code-apple-skills, 783 stars), Release (arul28/ADE, 114 stars), Reproduce macOS Python Flavors (Nuitka/Nuitka, 15k stars) and Releasing (marciogranzotto/clawd-tank, 164 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitHub Actions?

tddworks (a GitHub organization) maintains it in tddworks/ClaudeBar, which has 1,530 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 8, 2026.

Source: tddworks/ClaudeBar on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.