GitHub Actions Hardening
github/awesome-copilot
Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).
PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).
$ npx skills add tetherto/qvac --skill qv-devops-pr-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install tetherto/qvac qv-devops-pr-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/qv-devops-pr-review .claude/skills/qv-devops-pr-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "qv-devops-pr-review" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-devops-pr-review into .claude/skills/qv-devops-pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-devops-pr-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-devops-pr-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add tetherto/qvac --skill qv-devops-pr-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install tetherto/qvac qv-devops-pr-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/qv-devops-pr-review .agents/skills/qv-devops-pr-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "qv-devops-pr-review" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-devops-pr-review into .agents/skills/qv-devops-pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-devops-pr-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tetherto/qvac --skill qv-devops-pr-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install tetherto/qvac qv-devops-pr-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/qv-devops-pr-review .cursor/skills/qv-devops-pr-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "qv-devops-pr-review" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-devops-pr-review into .cursor/skills/qv-devops-pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-devops-pr-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/tetherto/qvac.git --path .agents/skills/qv-devops-pr-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add tetherto/qvac --skill qv-devops-pr-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install tetherto/qvac qv-devops-pr-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/qv-devops-pr-review .gemini/skills/qv-devops-pr-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "qv-devops-pr-review" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-devops-pr-review into .gemini/skills/qv-devops-pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-devops-pr-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install tetherto/qvac qv-devops-pr-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add tetherto/qvac --skill qv-devops-pr-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/qv-devops-pr-review .github/skills/qv-devops-pr-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "qv-devops-pr-review" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-devops-pr-review into .github/skills/qv-devops-pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-devops-pr-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tetherto/qvac --skill qv-devops-pr-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install tetherto/qvac qv-devops-pr-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/qv-devops-pr-review .opencode/skills/qv-devops-pr-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "qv-devops-pr-review" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-devops-pr-review into .opencode/skills/qv-devops-pr-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-devops-pr-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
qv-devops-pr-reviewPR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).
Qv Devops PR Review is an agent skill from tetherto/qvac. PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling). Use when reviewing a PR that touches DevOps paths or invoking /qv-devops-pr-review.
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Development, covering Pull requests, Security review and CI/CD. It works with GitHub Actions, Git and GitHub. The repository describes itself as: Open-source local AI SDK - run AI on-device with no cloud, no API keys. Supports GGUF, RAG, image, music, and video generation, speech-to-text, P2P inference, and more… The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c3a6030. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitghbashFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Qv Devops PR Review loads about 2.5k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 963 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from tetherto/qvac at commit c3a6030, republished under its Apache-2.0 licence (© tetherto). 963 words, ~2,511 tokens.
.claude/skills/qv-devops-pr-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.A DevOps-flavored PR review on top of the generic /qv-pr-review flow. Adds a deterministic GitHub Actions security audit pass grounded in the repository's GitHub and CI guidance and the checklist below, so DevOps reviewers always see the same high-risk patterns regardless of the prose style of the diff.
The skill is a wrapper, not a fork — the bulk of the review (gitflow, CI, title/body, generic correctness, security) is done by /qv-pr-review. This skill layers DevOps-specific findings into the same pending review payload.
Use when:
.github/workflows/, .github/actions/, .github/scripts/, scripts/, IaC under terraform/, ansible/, k8s/, Dockerfile*, .github/CODEOWNERS, .github/dependabot.yml)/qv-devops-pr-review with a PR URL/qv-devops-pr-status after the user picks a PRIf the PR's touched paths are dominated by a different pod, fall back to /qv-pr-review. The generic flow already auto-loads the relevant pod's rules.
https://github.com/tetherto/qvac/pull/<num>)If the URL is missing, ask for it. Nothing else to ask up-front.
Inherits all safety rules from /qv-pr-review verbatim:
git switch, git checkout, git reset, git restore, git stash, git pull, git merge, git rebase, git cherry-pick, git clean, gh pr checkout, or any write inside the user's working tree.~/.cache/qvac-pr-review/pr-<num>/ (managed by worktree-prepare.mjs) or via gh api .../contents/<path>?ref=<sha> to /tmp/.Inherits the ~5–8 shell-call budget from /qv-pr-review. The DevOps audit pass adds at most 3 additional reads (Read/Grep/Glob, not shell) per touched workflow/action file. Cache: reuse /tmp/pr-<num>.json, /tmp/pr-<num>.patch, and the worktree path from the underlying /qv-pr-review run.
Read .agents/skills/qv-pr-review/SKILL.md and follow steps 0a → 7a inclusive:
worktree-prepare.mjs).github/AGENTS.md and its linked source documents. The PR-format spec lives in the devops-pr-create skill and is invoked explicitly.infra/feat/fix/chore/doc/test; tags: [bc]/[notask]/[skiplog]; title regex: ^([A-Z]+-\d+ )?(infra|feat|fix|chore|doc|test)(\[(bc|notask|skiplog)\])?: \S.+$)For every .github/workflows/*.yml and .github/actions/**/action.yml in the patch, perform the checks below using Read/Grep/Glob against the worktree path. Each check that fires becomes a finding with a tier per the table.
| # | Check | Basis | Finding tier |
|---|---|---|---|
| A1 | Every uses: <vendor>/<action>@<ref> is pinned to a 40-char SHA (regex @[0-9a-f]{40}\b) with a trailing # v<ver> comment. Tag pins (@v3, @main, branch refs) fail. First-party ./.github/actions/<name> references are exempt. | .github/AGENTS.md | High |
| A2 | Permissions are declared explicitly — either a top-level permissions: block, OR every job has its own permissions: block. Relying on repo-default permissions fails. | .github/AGENTS.md | High |
| A3 | No occurrence of permissions: write-all anywhere in the workflow. | .github/AGENTS.md | High |
| A4 | If the workflow uses pull_request_target, none of its jobs check out PR HEAD via actions/checkout@... ref: ${{ github.event.pull_request.head.sha }} or ${{ github.head_ref }}. | .github/AGENTS.md | High |
| A5 | No direct interpolation of ${{ github.event.pull_request.title }}, body, head_ref, commits[*].message, or any github.event.* user-controlled field inside run: blocks. They MUST be piped via env:. | .github/AGENTS.md | High |
| A6 | If the workflow has id-token: write, OIDC is consumed by an auth action (google-github-actions/auth, aws-actions/configure-aws-credentials, azure/login) — not used for token forging that reaches a long-lived credential. | .github/AGENTS.md | Medium |
| A7 | No ${{ secrets.X }} interpolated directly inside a run: block. Pass via env: or action with: instead. | .github/AGENTS.md | High |
| A8 | No set -x / bash -x in steps that touch secrets; no printenv, env, cat, or echo of a secret value, even for "debugging". | .github/AGENTS.md | High |
| A9 | Concurrency block is declared. Release/state-mutating workflows have cancel-in-progress: false. | Current workflow conventions | Medium |
| A10 | Every job has timeout-minutes. Default budget 30; >30 needs a justifying comment. | Current workflow conventions | Low |
| A11 | continue-on-error: true is NOT set on Tier-1 checks (lint, format, type-check, security scans, tests). | docs/devops/TIER-1-SCOPE.md | Medium |
| A12 | Outputs use $GITHUB_OUTPUT, never the deprecated ::set-output::. | Current workflow conventions | Low |
| A13 | When actions/cache is used, cache writes are gated on non-fork triggers (push / workflow_dispatch / merge_group) — not blanket on pull_request. | .github/AGENTS.md | Medium |
| A14 | Workflow filename matches the existing repo conventions (on-pr-*.yml, on-merge-*.yml, on-pr-close-*.yml, release-*.yml, create-github-release-*.yml, prebuilds-*.yml, pr-test-*.yml, pr-validation-*.yml, pr-checks-*.yml, integration-*-*.yml, reusable-*.yml, trigger-reusable-*.yml). New file with a divergent name → finding. Pre-existing files keep their name unless the PR renames them. | Active workflow names | Low |
For each finding, capture: file, line, the offending excerpt (3-8 lines), the tier, and a one-line "why" pulled from the rule. Write findings into the same chat overview structure that /qv-pr-review step 7a uses, under a new sub-heading ### GHA security audit.
After both passes, re-print the full overview (gitflow / CI / generic-high / generic-medium / GHA-audit / lows / verified) so the user sees one ranked list. Findings retain the deep-link + excerpt rules from /qv-pr-review step 7a.
Continue with the generic flow:
gh api ... pulls/<num>/reviews command, wait for confirmationAfter the pending review URL is printed, append a single-line audit summary:
GHA audit: <H high> / <M medium> / <L low> findings on N workflow files. <K> filed inline; <skipped> skipped per user.This makes audit coverage observable without reading the inline payload.
Inherit the comment style from /qv-pr-review. Add one DevOps-specific convention: every GHA-audit finding's body MUST cite the rule it traces back to, e.g.:
Untrusted input piped directly into shell. Per `.github/AGENTS.md`,
this MUST go through an `env:` block — `${{ github.event.pull_request.title }}` lands in the rendered shell verbatim and is exploitable.
```yaml
env:
PR_TITLE: ${{ github.event.pull_request.title }}
run: |
echo "$PR_TITLE"
The cite makes the audit finding auditable: the reviewer can verify the rule still says what the comment claims.
## Quality Checklist
Before posting the pending review, verify:
- [ ] Underlying `/qv-pr-review` workflow ran through step 7a successfully (worktree prepared, gitflow checked, CI checked, scoped instructions loaded, title/body validated)
- [ ] GHA-audit pass ran on every changed `.github/workflows/*.yml` and `.github/actions/**/action.yml`
- [ ] Each GHA-audit finding has: file path, post-change line, 3-8 line excerpt at PR head SHA, deep link, tier, and source citation
- [ ] User-confirmed selection from step 7b matches the assembled payload exactly (count + IDs)
- [ ] Audit summary line is printed after step 12
## References
- Generic PR review skill (parent flow): [.agents/skills/qv-pr-review/SKILL.md](../qv-pr-review/SKILL.md)
- GitHub Actions and secrets guidance: [.github/AGENTS.md](../../../.github/AGENTS.md)
- DevOps PR-create skill (canonical home for commit / PR-title format): [`devops-pr-create`](../qv-devops-pr-create/SKILL.md)
- Pod metadata: [.github/teams/devops.json](../../../.github/teams/devops.json)
- Worktree manager: [.agents/skills/_lib/pr-skills/worktree-prepare.mjs](../_lib/pr-skills/worktree-prepare.mjs)© tetherto, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .agents/skills/qv-devops-pr-review of tetherto/qvac.
Open the folder on GitHubat commit c3a6030
Qv Devops PR Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Qv Devops PR Review this skilltetherto/qvac | 681 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | |
| GitHub Actions Hardeninggithub/awesome-copilot | 40k | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| PR Createposit-dev/skills | 531 | — | ~4.3k | Automated safety check: Warn | MIT | |
| ReviewdogAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~3k | Automated safety check: Pass | Custom licence | |
| Ghbubbuild/bub | 1.7k | — | ~798 | Automated safety check: Pass | Apache-2.0 | |
| ZCF Release AutomationUfoMiao/zcf | 6.1k | — | ~3.4k | Automated safety check: Pass | MIT |
github/awesome-copilot
Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).
posit-dev/skills
Creates a pull request from current changes, monitors GitHub CI, and debugs any failures until CI passes.
AgentSecOps/SecOpsAgentKit
Automated code review and security linting integration for CI/CD pipelines using reviewdog.
bubbuild/bub
GitHub CLI skill for interacting with GitHub via the gh command line tool.
UfoMiao/zcf
Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.
backnotprop/plannotator
Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.
tetherto/qvac
Creates a Solutions page in the QVAC documentation website from a real use case, generalizing the case into reusable guidance and registering the page in the site navigation.
tetherto/qvac
Updates the docs website after a change to the SDK or CLI. An agent skill from tetherto/qvac.
tetherto/qvac
Plan and prepare the QVAC agent-stack release cascade across @qvac/inference, @qvac/sdk, @qvac/cli, @qvac/ai-sdk-provider, @qvac/opencode-plugin, and @qvac/openclaw-plugin.
tetherto/qvac
Run the deterministic code-quality audit, turn related findings into contextual remediation groups, prepare approval-gated Asana proposals, reconcile recurring runs, or configure twice-monthly…
tetherto/qvac
Review C++ changes for string parameter and call-site efficiency conventions (std::stringview, std::string&&, const std::string&, const char, and TransparentStringMap lookup).
tetherto/qvac
Generate changelog entries for a target add-on package. An agent skill from tetherto/qvac.
Works with
Categories
PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling). Qv Devops PR Review is an agent skill from tetherto/qvac. PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).
Qv Devops PR Review fits situations like: reviewing a PR that touches DevOps paths; invoking /qv-devops-pr-review.
Run `npx skills add tetherto/qvac --skill qv-devops-pr-review -a claude-code`. Or copy the skill folder (.agents/skills/qv-devops-pr-review in tetherto/qvac) into .claude/skills/qv-devops-pr-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add tetherto/qvac --skill qv-devops-pr-review -a codex`. Or copy the skill folder (.agents/skills/qv-devops-pr-review in tetherto/qvac) into .agents/skills/qv-devops-pr-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tetherto/qvac --skill qv-devops-pr-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/qv-devops-pr-review, .gemini/skills/qv-devops-pr-review, .github/skills/qv-devops-pr-review and .opencode/skills/qv-devops-pr-review in your project.
Going by SKILL.md and its folder, Qv Devops PR Review needs the command-line tools its instructions call (git, gh and bash).
SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Qv Devops PR Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Qv Devops PR Review: GitHub Actions Hardening (github/awesome-copilot, 40k stars), PR Create (posit-dev/skills, 531 stars), Reviewdog (AgentSecOps/SecOpsAgentKit, 220 stars) and Gh (bubbuild/bub, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
tetherto (a GitHub organization) maintains it in tetherto/qvac, which has 681 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on October 7, 2026.
Source: tetherto/qvac on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.