Reviewdog
AgentSecOps/SecOpsAgentKit
Automated code review and security linting integration for CI/CD pipelines using reviewdog.
Generate CI/CD pipeline (GitHub Actions / GitLab CI) with linting, static analysis, tests, security.
$ npx skills add unxed/f4 --skill aif-ci -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install unxed/f4 aif-ci --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/unxed/f4.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/aif-ci .claude/skills/aif-ci && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "aif-ci" agent skill from https://github.com/unxed/f4/tree/main/.agents/skills/aif-ci into .claude/skills/aif-ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aif-ci", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/unxed/f4/tree/main/.agents/skills/aif-ciType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add unxed/f4 --skill aif-ci -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install unxed/f4 aif-ci --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/unxed/f4.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/aif-ci .agents/skills/aif-ci && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "aif-ci" agent skill from https://github.com/unxed/f4/tree/main/.agents/skills/aif-ci into .agents/skills/aif-ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aif-ci", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add unxed/f4 --skill aif-ci -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install unxed/f4 aif-ci --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/unxed/f4.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/aif-ci .cursor/skills/aif-ci && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "aif-ci" agent skill from https://github.com/unxed/f4/tree/main/.agents/skills/aif-ci into .cursor/skills/aif-ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aif-ci", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/unxed/f4.git --path .agents/skills/aif-ci--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add unxed/f4 --skill aif-ci -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install unxed/f4 aif-ci --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/unxed/f4.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/aif-ci .gemini/skills/aif-ci && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "aif-ci" agent skill from https://github.com/unxed/f4/tree/main/.agents/skills/aif-ci into .gemini/skills/aif-ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aif-ci", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install unxed/f4 aif-ciInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add unxed/f4 --skill aif-ci -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/unxed/f4.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/aif-ci .github/skills/aif-ci && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "aif-ci" agent skill from https://github.com/unxed/f4/tree/main/.agents/skills/aif-ci into .github/skills/aif-ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aif-ci", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add unxed/f4 --skill aif-ci -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install unxed/f4 aif-ci --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/unxed/f4.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/aif-ci .opencode/skills/aif-ci && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "aif-ci" agent skill from https://github.com/unxed/f4/tree/main/.agents/skills/aif-ci into .opencode/skills/aif-ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aif-ci", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
aif-ciGenerate CI/CD pipeline (GitHub Actions / GitLab CI) with linting, static analysis, tests, security.
Aif CI is an agent skill from unxed/f4. Generate CI/CD pipeline (GitHub Actions / GitLab CI) with linting, static analysis, tests, security. Use when user says "ci", "setup ci", "github actions", "gitlab ci", "pipeline".
Its SKILL.md is about 4.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 21 other files, including reference files (for example `references/AUDIT-REPORT.md`, `references/BEST-PRACTICES.md` and `references/GITLAB-PATTERNS.md`).
It sits in DevOps & Cloud, covering CI/CD, Linting and formatting and Static analysis and SAST. It works with GitHub Actions and GitLab. The repository describes itself as: dual pane like a charm. The licence is BSD-3-Clause.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 447642e. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadEditGlobGrepWriteBash(git *)AskUserQuestionQuestionsFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gocargopnpmnpmruffmysqlcomposerbunyarnuvpoetrypipFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm, npm, yarn, uv and pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Aif CI loads about 4.7k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 47 tokens; SKILL.md has 1,960 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from unxed/f4 at commit 447642e, republished under its BSD-3-Clause licence (© unxed). 1,960 words, ~4,705 tokens.
.claude/skills/aif-ci/SKILL.md (or your agent's skills folder). This skill also uses 17 other files; get the full folder from GitHub.Analyze a project and generate production-grade CI/CD pipeline configuration for GitHub Actions or GitLab CI. Generates separate jobs for linting, static analysis, tests, and security scanning — adapted to the project's language, framework, and existing tooling.
Three modes based on what exists:
| What exists | Mode | Action |
|---|---|---|
| No CI config | generate | Create pipeline from scratch with interactive setup |
| CI config exists but incomplete | enhance | Audit & improve, add missing jobs |
| Full CI config | audit | Audit against best practices, fix gaps |
Read the project description if available:
Read .ai-factory/DESCRIPTION.mdStore project context for later steps. If absent, Step 2 detects everything.
Read .ai-factory/skill-context/aif-ci/SKILL.md — MANDATORY if the file exists.
This file contains project-specific rules accumulated by /aif-evolve from patches,
codebase conventions, and tech-stack analysis. These rules are tailored to the current project.
How to apply skill-context rules:
Enforcement: After generating any output artifact, verify it against all skill-context rules. If any rule is violated — fix the output before presenting it to the user.
Glob: .github/workflows/*.yml, .github/workflows/*.yaml, .gitlab-ci.yml, .circleci/config.yml, Jenkinsfile, .travis.yml, bitbucket-pipelines.ymlClassify found files:
HAS_GITHUB_ACTIONS: .github/workflows/ contains YAML filesHAS_GITLAB_CI: .gitlab-ci.yml existsHAS_OTHER_CI: CircleCI, Jenkins, Travis, or Bitbucket detectedIf $ARGUMENTS contains --enhance -> set MODE = "enhance" regardless.
Path A: No CI config exists (!HAS_GITHUB_ACTIONS && !HAS_GITLAB_CI && !HAS_OTHER_CI):
MODE = "generate"Path B: CI config exists but is incomplete (e.g., has only tests, no linting):
MODE = "enhance"EXISTING_CONTENTPath C: Full CI setup (has linting + tests + static analysis):
MODE = "audit"EXISTING_CONTENTDetermine CI platform from $ARGUMENTS or ask:
If $ARGUMENTS contains github -> set PLATFORM = "github"
If $ARGUMENTS contains gitlab -> set PLATFORM = "gitlab"
Otherwise:
AskUserQuestion: Which CI/CD platform do you use?
Options:
1. GitHub Actions (Recommended) — .github/workflows/*.yml
2. GitLab CI — .gitlab-ci.ymlAsk about optional features:
AskUserQuestion: Which additional CI features do you need?
Options (multiSelect):
1. Security scanning — Dependency audit, SAST
2. Coverage reporting — Upload test coverage
3. Matrix builds — Test across multiple language versions
4. None — Just linting, static analysis, and testsStore choices:
PLATFORM: github | gitlabWANT_SECURITY: booleanWANT_COVERAGE: booleanWANT_MATRIX: booleanRead all existing CI files and store as EXISTING_CONTENT:
.github/workflows/*.yml files.gitlab-ci.ymlinclude: directives)Determine PLATFORM from existing files.
Scan the project thoroughly — every decision in the generated pipeline depends on this profile.
| File | Language |
|---|---|
composer.json | PHP |
package.json | Node.js / TypeScript |
pyproject.toml / setup.py / setup.cfg | Python |
go.mod | Go |
Cargo.toml | Rust |
pom.xml | Java (Maven) |
build.gradle / build.gradle.kts | Java/Kotlin (Gradle) |
Detect the project's language version to use in CI:
| Language | Version Source | Example |
|---|---|---|
| PHP | composer.json -> require.php | >=8.2 -> ['8.2', '8.3', '8.4'] |
| Node.js | package.json -> engines.node, .nvmrc, .node-version | >=18 -> [18, 20, 22] |
| Python | pyproject.toml -> requires-python, .python-version | >=3.11 -> ['3.11', '3.12', '3.13'] |
| Go | go.mod -> go directive | go 1.23 -> '1.23' |
| Rust | Cargo.toml -> rust-version, rust-toolchain.toml | 1.82 -> '1.82' |
| Java | pom.xml -> maven.compiler.source, build.gradle -> sourceCompatibility | 17 -> [17, 21] |
For matrix builds: use the minimum version from the project config as the lowest, and include the latest stable version. For non-matrix builds: use the latest version that satisfies the constraint.
| File | Package Manager | Install Command |
|---|---|---|
composer.lock | Composer | composer install --no-interaction --prefer-dist |
bun.lockb | Bun | bun install --frozen-lockfile |
pnpm-lock.yaml | pnpm | pnpm install --frozen-lockfile |
yarn.lock | Yarn | yarn install --frozen-lockfile |
package-lock.json | npm | npm ci |
uv.lock | uv | uv sync --all-extras --dev |
poetry.lock | Poetry | poetry install |
Pipfile.lock | Pipenv | pipenv install --dev |
requirements.txt | pip | pip install -r requirements.txt |
go.sum | Go modules | go mod download |
Cargo.lock | Cargo | (built-in) |
Store: PACKAGE_MANAGER, LOCK_FILE, INSTALL_CMD.
Detect project tools by scanning config files and dependencies. For the complete tool-to-command mapping → read references/TOOL-COMMANDS.md
Categories: Linters & Formatters (PHP-CS-Fixer, ESLint, Prettier, Biome, Ruff, golangci-lint, clippy, Checkstyle), Static Analysis (PHPStan, Psalm, Rector, mypy, tsc), Test Frameworks (PHPUnit, Pest, Jest, Vitest, pytest, go test, cargo test) with coverage flags, Security Audit (composer audit, npm audit, pip-audit, govulncheck, cargo audit).
Check if tests require external services (database, Redis, etc.):
Grep in tests/: postgres|mysql|redis|mongo|rabbitmq|elasticsearch
Glob: docker-compose.test.yml, docker-compose.ci.ymlIf services are needed, they will be configured in the CI pipeline as service containers.
Does the project have a build step?
| Language | Has Build | Build Command |
|---|---|---|
Node.js (with build script) | Yes | npm run build / pnpm build |
| Go | Yes | go build ./... |
| Rust | Yes | cargo build --release |
| Java | Yes | mvn package -DskipTests -B / ./gradlew assemble |
| PHP | Usually no | — |
| Python | Usually no | — |
Build PROJECT_PROFILE:
language, language_version, language_versions (for matrix)package_manager, lock_file, install_cmdlinters: list of {name, command, config_file}static_analyzers: list of {name, command}test_framework, test_cmd, coverage_cmdsecurity_tools: list of {name, command}has_build_step, build_cmdhas_typescript: boolean (for typecheck job)services_needed: list of services for CIsource_dir: main source directory (src/, app/, lib/)Read skills/ci/references/BEST-PRACTICES.mdSelect templates matching the platform and language:
GitHub Actions:
| Language | Template |
|---|---|
| PHP | templates/github/php.yml |
| Node.js | templates/github/node.yml |
| Python | templates/github/python.yml |
| Go | templates/github/go.yml |
| Rust | templates/github/rust.yml |
| Java | templates/github/java.yml |
GitLab CI:
| Language | Template |
|---|---|
| PHP | templates/gitlab/php.yml |
| Node.js | templates/gitlab/node.yml |
| Python | templates/gitlab/python.yml |
| Go | templates/gitlab/go.yml |
| Rust | templates/gitlab/rust.yml |
| Java | templates/gitlab/java.yml |
Read the selected template:
Read skills/ci/templates/<platform>/<language>.ymlUsing the PROJECT_PROFILE, best practices, and template as a base, generate a customized CI pipeline.
One workflow per concern — each file has its own triggers, permissions, concurrency:
| File | Name | Jobs | When to create |
|---|---|---|---|
lint.yml | Lint | code-style, static-analysis, rector | Linters or SA detected |
tests.yml | Tests | tests (+ service containers) | Always |
build.yml | Build | build | has_build_step |
security.yml | Security | dependency-audit, dependency-review | WANT_SECURITY |
Why one file per concern:
security-events: writetests but not security)When to keep single file: Only for very small projects with just lint + tests (2 jobs). As soon as there are 3+ concerns — split.
Every workflow gets the same header pattern:
name: <Name>
on:
push:
branches: [main]
pull_request:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: readPer-file job organization:
lint.yml — all code quality checks in parallel:
| Job | Purpose | When to include |
|---|---|---|
code-style | Formatting (CS-Fixer, Prettier, Ruff format, rustfmt) | Formatter detected |
lint | Linting (ESLint, Ruff check, Clippy, golangci-lint) | Linter detected |
static-analysis | Type checking / SA (PHPStan, Psalm, mypy, tsc) | SA tools detected |
rector | Rector dry-run (PHP only) | Rector detected |
All jobs run in parallel (no needs). If only one tool detected (e.g. Go with just golangci-lint) — single job in the file is fine.
tests.yml — test suite:
| Job | Purpose | When to include |
|---|---|---|
tests | Unit/integration tests | Always |
tests-<service> | Tests requiring service containers | services_needed detected |
Matrix builds (multiple language versions) only in this file.
build.yml — build verification:
| Job | Purpose | Notes |
|---|---|---|
build | Verify compilation/bundling | Can depend on external workflow via workflow_run or just run independently |
security.yml — security scanning:
| Job | Purpose | Extra triggers |
|---|---|---|
dependency-audit | Vulnerability scan | schedule: cron '0 6 * * 1' (weekly) |
dependency-review | PR dependency diff | Only on pull_request |
Per-job rules:
shivammathur/setup-php@v2 with tools: parameteractions/setup-node@v4 with cache: parameterastral-sh/setup-uv@v5 (if uv) or actions/setup-python@v5 (if pip)actions/setup-go@v5 (auto-caches)dtolnay/rust-toolchain@stable + Swatinem/rust-cache@v2actions/setup-java@v4 with cache: parameterfail-fast: false in matrix buildsWANT_COVERAGEMatrix builds (when WANT_MATRIX):
Only the tests job uses a matrix. Lint/SA jobs run on the latest version only.
tests:
name: Tests (${{ matrix.<language>-version }})
strategy:
fail-fast: false
matrix:
<language>-version: <language_versions from PROJECT_PROFILE>Combining linter jobs:
If the project has both a formatter AND a linter from the same ecosystem, combine them into one job:
php-cs-fixer check + other lint -> code-style jobeslint + prettier -> lint job. Biome replaces BOTH ESLint and Prettier — if Biome is detected, use only npx biome check . in a single lint jobruff check + ruff format --check -> lint job (Ruff handles both)cargo fmt + cargo clippy -> can be separate (fmt is fast, clippy needs compilation)Do NOT combine lint/SA with tests — they should fail independently with clear feedback.
Use the templates in templates/github/ and templates/gitlab/ as a base for generating workflow files. Follow the header pattern (name, on, concurrency, permissions) and per-file job organization described above.
Output file: .gitlab-ci.yml
For GitLab-specific pipeline structure, cache strategy, report format integration, and language-specific patterns → read references/GITLAB-PATTERNS.md
Pipeline stages: install → lint → test → build → security
If services_needed is not empty, add service containers to the test job.
For GitHub Actions and GitLab CI service container syntax → read references/SERVICE-CONTAINERS.md
Verify generated pipeline before writing:
Correctness:
Best practices:
concurrency group set (GitHub Actions)permissions: contents: read set (GitHub Actions)interruptible: true set (GitLab CI)workflow.rules defined (GitLab CI)needs)fail-fast: false on matrix buildsNo over-engineering:
When MODE = "enhance" or MODE = "audit", analyze EXISTING_CONTENT against the project profile and best practices.
Compare existing pipeline against PROJECT_PROFILE:
Missing jobs:
Configuration issues:
actions-rs instead of dtolnay/rust-toolchain)?fail-fast: false on matrix?policy: pull-push on all GitLab jobs instead of pull on non-install jobs?Missing features:
workflow_dispatch trigger (GitHub Actions)?For audit report format, fix flow options, and display templates → read references/AUDIT-REPORT.md
Present results as tables with ✅/❌/⚠️ per check. Categorize recommendations by severity (CRITICAL, HIGH, MEDIUM, LOW). Ask user to choose: fix all, fix critical only, or show details first.
If fixing: preserve existing structure, job names, and ordering conventions.
GitHub Actions:
Bash: mkdir -p .github/workflows
Write .github/workflows/lint.yml # If linters/SA detected
Write .github/workflows/tests.yml # Always
Write .github/workflows/build.yml # If has_build_step
Write .github/workflows/security.yml # If WANT_SECURITYOnly create files for detected concerns. If only lint + tests — two files. If the project is trivially small (single lint + single test job) — a single ci.yml is acceptable.
GitLab CI:
Write .gitlab-ci.ymlGitLab CI uses a single .gitlab-ci.yml — stages and DAG (needs:) handle separation.
Edit existing files using the Edit tool. Preserve the original structure and only add/modify what's needed.
Display summary using format from references/AUDIT-REPORT.md (Summary Display Template section). Show platform, files created, features, and quick start commands.
Suggest: /aif-build-automation for CI targets in Makefile/Taskfile, /aif-dockerize for containerization.
.github/workflows/* and .gitlab-ci.yml.config.yaml.© unxed, BSD-3-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 17 other files (references) in .agents/skills/aif-ci of unxed/f4.
Open the folder on GitHubat commit 447642e
Aif CI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Aif CI this skillunxed/f4 | 244 | — | ~4.7k | Automated safety check: Pass | BSD-3-Clause | |
| ReviewdogAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~3k | Automated safety check: Pass | Custom licence | |
| Megalinter Checknvuillam/npm-groovy-lint | 248 | 1 repos | ~3.9k | Automated safety check: Notes | MIT | |
| Hadolint Dockerfile Security LintingAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~4.4k | Automated safety check: Pass | Custom licence | |
| Golang Continuous Integrationsamber/cc-skills-golang | 3.4k | — | ~3.7k | Automated safety check: Pass | MIT | |
| Golang Continuous Integrationcontext-labs/whip | 1.1k | — | ~3.5k | Automated safety check: Pass | MIT |
AgentSecOps/SecOpsAgentKit
Automated code review and security linting integration for CI/CD pipelines using reviewdog.
nvuillam/npm-groovy-lint
Collect MegaLinter lint errors for the current repository. An agent skill from nvuillam/npm-groovy-lint.
AgentSecOps/SecOpsAgentKit
Lints Dockerfiles with Hadolint for security misconfigurations and best-practice violations, locally and in CI, with strict, balanced and permissive rule templates.
samber/cc-skills-golang
GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release…
context-labs/whip
CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines.
metalbear-co/mirrord
Help users set up mirrord in CI pipelines for testing against real Kubernetes environments.
unxed/f4
Comprehensive documentation guide for Golang projects, covering godoc comments, README, CONTRIBUTING, CHANGELOG, Go Playground, Example tests, API docs, and llms.txt.
unxed/f4
Golang code style conventions — line length and breaking, variable declarations, control flow clarity, when comments help vs hurt.
unxed/f4
Comprehensive guide for Go database access — parameterized queries, struct scanning, NULLable columns, transactions, isolation levels, SELECT FOR UPDATE, connection pool, batch processing, context…
unxed/f4
Security audit checklist based on OWASP Top 10 and best practices.
unxed/f4
Go (Golang) naming conventions — covers packages, constructors, structs, interfaces, constants, enums, errors, booleans, receivers, getters/setters, functional options, acronyms, test functions, and…
unxed/f4
Golang concurrency design — goroutine lifecycle and leak prevention, channels and select, channel ownership and direction, sync.Mutex/RWMutex/sync.Map/sync.Once/atomics, errgroup, singleflight…
Works with
Categories
Generate CI/CD pipeline (GitHub Actions / GitLab CI) with linting, static analysis, tests, security. Aif CI is an agent skill from unxed/f4. Generate CI/CD pipeline (GitHub Actions / GitLab CI) with linting, static analysis, tests, security.
Aif CI fits situations like: tasks that involve CI/CD; tasks that involve Linting and formatting; tasks that involve Static analysis and SAST.
Run `npx skills add unxed/f4 --skill aif-ci -a claude-code`. Or copy the skill folder (.agents/skills/aif-ci in unxed/f4) into .claude/skills/aif-ci in your project. Claude Code loads it when a task matches its description.
Run `npx skills add unxed/f4 --skill aif-ci -a codex`. Or copy the skill folder (.agents/skills/aif-ci in unxed/f4) into .agents/skills/aif-ci in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add unxed/f4 --skill aif-ci -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aif-ci, .gemini/skills/aif-ci, .github/skills/aif-ci and .opencode/skills/aif-ci in your project.
Going by SKILL.md and its folder, Aif CI needs the command-line tools its instructions call (go, cargo, pnpm, npm, ruff and mysql). Our summary lists: Python 3; Node.js; Docker. Its frontmatter pre-approves these tools: Read, Edit, Glob, Grep, Write, Bash(git *), AskUserQuestion, Questions.
SKILL.md contains no URLs. Its commands use npm, uv and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Aif CI is published under the BSD-3-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Aif CI: Reviewdog (AgentSecOps/SecOpsAgentKit, 220 stars), Megalinter Check (nvuillam/npm-groovy-lint, 248 stars), Hadolint Dockerfile Security Linting (AgentSecOps/SecOpsAgentKit, 220 stars) and Golang Continuous Integration (samber/cc-skills-golang, 3.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
unxed (a GitHub user) maintains it in unxed/f4, which has 244 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on October 10, 2026.
Source: unxed/f4 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.