Pester Failure Analysis
PowerShell/PowerShell
Investigates failing Pester tests in PowerShell CI jobs by following a six-step workflow from pull request status to documented fix recommendations.
Daily autonomous classifier for failing PRs across your repos.
$ npx skills add yonatangross/orchestkit --skill ci-sentinel -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install yonatangross/orchestkit ci-sentinel --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/yonatangross/orchestkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/skills/ci-sentinel .claude/skills/ci-sentinel && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ci-sentinel" agent skill from https://github.com/yonatangross/orchestkit/tree/main/src/skills/ci-sentinel into .claude/skills/ci-sentinel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-sentinel", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/yonatangross/orchestkit/tree/main/src/skills/ci-sentinelType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add yonatangross/orchestkit --skill ci-sentinel -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install yonatangross/orchestkit ci-sentinel --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yonatangross/orchestkit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/src/skills/ci-sentinel .agents/skills/ci-sentinel && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ci-sentinel" agent skill from https://github.com/yonatangross/orchestkit/tree/main/src/skills/ci-sentinel into .agents/skills/ci-sentinel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-sentinel", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yonatangross/orchestkit --skill ci-sentinel -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install yonatangross/orchestkit ci-sentinel --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yonatangross/orchestkit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/src/skills/ci-sentinel .cursor/skills/ci-sentinel && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ci-sentinel" agent skill from https://github.com/yonatangross/orchestkit/tree/main/src/skills/ci-sentinel into .cursor/skills/ci-sentinel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-sentinel", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/yonatangross/orchestkit.git --path src/skills/ci-sentinel--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add yonatangross/orchestkit --skill ci-sentinel -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install yonatangross/orchestkit ci-sentinel --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yonatangross/orchestkit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/src/skills/ci-sentinel .gemini/skills/ci-sentinel && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ci-sentinel" agent skill from https://github.com/yonatangross/orchestkit/tree/main/src/skills/ci-sentinel into .gemini/skills/ci-sentinel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-sentinel", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install yonatangross/orchestkit ci-sentinelInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add yonatangross/orchestkit --skill ci-sentinel -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/yonatangross/orchestkit.git skills-src && mkdir -p .github/skills && cp -r skills-src/src/skills/ci-sentinel .github/skills/ci-sentinel && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ci-sentinel" agent skill from https://github.com/yonatangross/orchestkit/tree/main/src/skills/ci-sentinel into .github/skills/ci-sentinel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-sentinel", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yonatangross/orchestkit --skill ci-sentinel -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install yonatangross/orchestkit ci-sentinel --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yonatangross/orchestkit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/src/skills/ci-sentinel .opencode/skills/ci-sentinel && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ci-sentinel" agent skill from https://github.com/yonatangross/orchestkit/tree/main/src/skills/ci-sentinel into .opencode/skills/ci-sentinel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ci-sentinel", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ci-sentinelDaily autonomous classifier for failing PRs across your repos.
CI Sentinel is an agent skill from yonatangross/orchestkit. Daily autonomous classifier for failing PRs across your repos. Runs /ci-debug headless against every open PR with red required checks, posts the verdict as a collapsed PR comment, and appends to a per-repo .sentinel/ledger.jsonl. v1 is propose-don't-apply — NEVER auto-pushes a fix. Use when you're tired of /status sweeps catching the same 10 CI failure patterns over and over.
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Claude Code 2.1.277+ (uses --permission-mode + --no-session-persistence for headless GHA runs; --bare was tried but doesn't honor ANTHROPICAPIKEY in CC…
It sits in Testing & QA, covering Failing and flaky tests. The repository describes itself as: The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install ork for stable (v9.x), or ork-alpha for the v10 line, which ships daily. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 02bbf9a. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadWriteEditGrepGlobFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
claudeghgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
CLAUDE_CODE_OAUTH_TOKENANTHROPIC_API_KEYGITHUB_TOKENGH_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Claude Code 2.1.277+ (uses --permission-mode + --no-session-persistence for headless GHA runs; --bare was tried but doesn't honor ANTHROPIC_API_KEY in CC 2.1.143 — see SKILL body for the trade-off).
From compatibility in the SKILL.md frontmatter.
CI Sentinel loads about 3.7k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 1,787 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, Write, Edit, Grep, GlobAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from yonatangross/orchestkit at commit 02bbf9a, republished under its MIT licence (© yonatangross). 1,787 words, ~3,733 tokens.
.claude/skills/ci-sentinel/SKILL.md (or your agent's skills folder).Direct response to the 275-session insights audit (2026-05-16): 14 ci-debugging + 7 fix-ci-failures sessions in one month, most of them re-running the same 10-pattern classification you already encoded in /ci-debug. This skill makes the classifier autonomous.
⏰ daily cron (08:17 UTC)
│
▼
📥 gh pr list → PRs with FAILURE checks (yours, max 10)
│
▼
🤖 for each PR (skipping those already commented at this SHA):
claude -p → run /ci-debug → capture verdict markdown
│
▼
💬 post collapsed PR comment with marker so future runs dedupe
│
▼
📜 append { ts, pr, sha, tokens } to .sentinel/ledger.jsonl
│
▼
💰 if daily token spend > ORK_SENTINEL_DAILY_TOKEN_BUDGET → pause🆕 flag in the comment; you find them on your normal status sweep, not via a notification storm./status is for.Read("${CLAUDE_PLUGIN_ROOT}/shared/rules/untrusted-input-quarantine.md"), the classifier reads them read-only and extracts the failure class as structured facts; the propose-don't-apply design (no auto-push) already keeps the actor away from the raw bytes — quarantine makes that explicit, and deterministic signals (exit codes, test output) bypass the reader as ground truth.| Risk | Mitigation |
|---|---|
| Token cost runaway | ORK_SENTINEL_DAILY_TOKEN_BUDGET=1000000 ceiling, enforced by the workflow's first step. Resets daily. |
| Duplicate comments on the same SHA | Marker <!-- ork:ci-sentinel sha=<short> --> on every comment; workflow scans existing comments before posting. |
| Wrong-classification spam | Propose-don't-apply means the worst outcome is a noisy but accurate-looking comment. You can collapse them; you can't unmerge a bad auto-fix. |
| Stuck PR keeps re-classifying | Idempotent on SHA — only re-runs if you push new commits. |
| Sentinel itself breaking CI | Runs on ubuntu-latest, no pull_request trigger, no push trigger. Cannot block any other workflow. |
.github/workflows/ci-sentinel.yml from the OrchestKit repo into the target repo (this skill ships it).claude setup-token, then add it as the CLAUDE_CODE_OAUTH_TOKEN secret: gh secret set CLAUDE_CODE_OAUTH_TOKEN -R <owner>/<repo>. The workflow reads this natively from job-level env; ANTHROPIC_API_KEY is not used any more, and setting it alone leaves the run red: the workflow's auth canary hard-fails when CLAUDE_CODE_OAUTH_TOKEN is unset or expired.ORK_SENTINEL_DAILY_TOKEN_BUDGET env in the workflow.inputs.dry_run = true to validate the wiring.Rotate the token the same way when the canary reports a 401: claude setup-token, then re-run gh secret set.
If you run the sentinel locally via claude --bg instead of the workflow:
Pin it (CC 2.1.147+): Press
Ctrl+Tinclaude agentsto pin the session. Pinned background sessions stay alive when idle (no silent reaping between runs), restart in place to apply CC updates rather than dying, and under memory pressure are shed only after non-pinned sessions.
Resume it (CC 2.1.144+): Sessions started via
claude --bgnow appear in/resumemarkedbg— recover a crashed sentinel directly through/resumeinstead of the agent view.
The workflow is intentionally configured via in-file env vars (not workflow inputs) so a fork stays self-contained:
| Var | Default | Meaning |
|---|---|---|
ORK_SENTINEL_DAILY_TOKEN_BUDGET | 1000000 | Hard daily ceiling. Hour-of-day not enforced; calendar day in UTC. Bumped from 500k after dropping --bare (see "Why no --bare" below). |
ORK_SENTINEL_PER_PR_TIMEOUT_S | 300 | Per-PR wall-clock cap on the claude -p invocation. |
max_prs (workflow_dispatch input) | 10 | Cap on PRs analyzed in one sweep. |
dry_run (workflow_dispatch input) | false | Skip comment posting (for spec validation). |
Originally designed around claude -p --bare (CC 2.1.81+) for minimal plugin/hook load and predictable ~4k tokens/PR. First real dispatch revealed --bare doesn't honor ANTHROPIC_API_KEY env var, --settings.apiKey, or --settings.apiKeyHelper — every call returns "Not logged in · Please run /login". Reproduced locally against multiple settings shapes.
Dropped --bare; cost per PR rises ~4k → ~10k tokens (plugins + hooks load), partially offset by --no-session-persistence (avoids disk writes). Daily budget bumped 500k → 1M to absorb the change. (That budget bump predates the 2026-07 move to a daily cron and Max-plan OAuth auth; at the current cadence the ceiling is pure headroom, see "Cost model" below.)
If/when CC fixes --bare auth, the workflow can revert to bare mode by changing one line.
Each claude -p invocation locks the dispatch envelope so cost-per-PR stays predictable regardless of what the runner inherits:
| Flag | Value | Why |
|---|---|---|
--permission-mode | acceptEdits | The headless "use tools without prompting" mode. /ci-debug needs Bash (gh pr checks, gh api ...logs) to read the failure. dontAsk was the original value but it silently REFUSES permission-requiring tools, so every analysis came back empty (M146-7, #1862 Bug C). Never use bypassPermissions here. |
--max-turns | 4 | Cap on the conversation length. Sweep, classify, report — done. |
--output-format | json | Ledger needs usage.total_tokens for the budget circuit-breaker. |
--no-session-persistence | (flag) | Don't write session state to disk; sentinel runs are ephemeral. |
⚠️
acceptEditsis edit-capable. The permission mode is NOT what keeps the sentinel propose-don't-apply. Be precise about which control does what:
- The real structural control is
permissions: contents: readat the top ofci-sentinel.yml. TheGITHUB_TOKENthe job runs under simply cannot write repo contents, so agit push, a branch update, or agh pr mergeis rejected by GitHub's API regardless of what the model tries. That is enforcement, not convention. It is also why local edits the model makes to the runner checkout go nowhere: not because the runner is ephemeral, but because nothing can push them.- The model CAN still write, and those writes persist. The job sets
GH_TOKENand grantspull-requests: write+issues: write, and the prompt tells the model to use theghCLI. AnacceptEditsmodel can therefore post, edit, or delete comments, edit PR/issue titles and bodies, add labels, and close or reopen PRs and issues. None of that is undone when the job ends. Treat GitHub-conversation state as writable blast radius.- Prompt wording is a convention, not a control. The dispatch prompt is
Run /ci-debug on PR N ... Use only the gh CLI. Output the report markdown only, and/ci-debugis specified to propose and never apply. That is what keeps the model from using its write scope destructively, but it is unenforced, and CI logs and PR bodies are untrusted input.Consequences: keep
contents: read. Widening it tocontents: write(or adding a git write step plus the matching permission) is the change that actually converts this into an auto-fix bot, and it demotes prompt wording to the sole control. Narrowingpull-requests/issuestoreadwould shrink the remaining blast radius, at the cost of the verdict comment the sentinel exists to post. Never usebypassPermissionshere.
These are hardcoded in the workflow. If you need to override for a fork (e.g. you want a different permission-mode), edit .github/workflows/ci-sentinel.yml directly — intentionally not exposed as workflow_dispatch inputs to prevent accidental cost spikes from a one-off manual run.
Every verdict comment looks like:
<!-- ork:ci-sentinel sha=abc123def -->
<details><summary>🛰️ <b>CI Sentinel verdict</b> (sha abc123def)</summary>
## CI Debug: <repo> · #<n>
**Failing job:** ...
**Classification:** Pattern #N — <name>
**Reference:** memory <file.md>
**Proposed fix:** ...
</details>Collapsed by default — no inbox noise unless you click. Always carries the SHA so you know whether the verdict is still current.
The insights audit's horizon-#1 design called for a CI_PLAYBOOK.md the sentinel mutates after each human-driven novel-failure fix. v1 doesn't write to the playbook — it just appends classification rows to .sentinel/ledger.jsonl. The playbook lives in /ci-debug's SKILL.md and stays human-curated for v1.
When v1.1 lands the journal:
/ci-debug SKILL.md.Per-PR analysis: ~8-12k tokens (full CC load — plugins + hooks — since --bare was dropped, see "Why no --bare" above).
One daily sweep with avg 3 failing PRs: ~30k tokens/day. A bad day at the max_prs=10 cap is ~120k tokens.
Daily budget 1M tokens = roughly 30x headroom on a typical day and ~8x at the cap. At this cadence the ceiling is a runaway-loop guard (a stuck retry loop), not a spend cap you will ever approach normally.
Dollar cost: the workflow authenticates with a Max-plan OAuth token, so a sweep draws on plan quota rather than metered credits, with no incremental invoice line. If you swap a fork back to a metered ANTHROPIC_API_KEY, ~30k tokens/day at ~$15/MTok (Sonnet input/output blended) is roughly $12-15/month per repo. Either way, against 21 manual ci-debug sessions/month at 10-20 minutes each, payback is immediate.
The old figures in this section ("~30k tokens/hour", "~720k/day") were derived from the original hourly cron. The workflow was throttled to daily in 2026-07 (
cron: "17 8 * * *") alongside the OAuth migration, since an hourly sweep would draw on the same interactive Max-plan quota.
/ci-debug does the classification (sentinel is the trigger).swarm-migrate (after sentinel diagnoses, you might fix-and-swarm across repos), /status (sentinel doesn't replace org-wide sweeps)./loop /ci-debug in your own session is the manual analog; ship the sentinel and unplug from that.ci-sentinel install — copy the workflow into a new repo + check secrets.ci-sentinel status — read .sentinel/ledger.jsonl and summarize the last 24h.ci-sentinel enable / disable — toggle the workflow's on.schedule block.The daily cron run itself does not invoke this skill — the workflow calls claude -p against /ci-debug directly (headless mode — not --bare, which was dropped over the auth failure documented in "Why no --bare" above). This skill is for the human admin actions around the sentinel.
CC 2.1.183 hardens propose-don't-apply: Scheduled-task and webhook trigger deliveries now classify as task notifications, not keyboard input — so a delivery can no longer approve a pending action or set the session title in auto mode. If you ever run the sentinel inside a live auto-mode session (rather than the headless
-pcron), a triggered re-run can no longer auto-approve a fix prompt. That closes the trigger-delivery vector at the harness layer. It does not change the headless cron path: there, the enforced control ispermissions: contents: read(no push or merge is possible), while the model still holdspull-requests: write+issues: writeand is held to propose-don't-apply by prompt wording alone. See the dispatch-envelope note above.
You already have 10 encoded CI failure patterns in /ci-debug and 632 ScheduleWakeup invocations in your history — you trust async, and you trust pattern-matched classifications when they cite the memory entry. The CI sentinel is composition, not invention: a GitHub Actions cron triggers headless /ci-debug against every open red PR, posts a collapsed verdict, and respects propose-don't-apply. Worst case is a noisy comment. Best case is 21 sessions/month of recurring CI archaeology reclaimed. Build effort: hours. Payback: immediate.
© yonatangross, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in src/skills/ci-sentinel of yonatangross/orchestkit.
Open the folder on GitHubat commit 02bbf9a
CI Sentinel next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| CI Sentinel this skillyonatangross/orchestkit | 290 | — | ~3.7k | Automated safety check: Notes | MIT | |
| Pester Failure AnalysisPowerShell/PowerShell | 56k | — | ~5.1k | Automated safety check: Pass | MIT | |
| Apple Container Test RunnerRustPython/RustPython | 22k | — | ~467 | Automated safety check: Pass | MIT | |
| Perf Regression Triagemozilla-firefox/firefox | 13k | — | ~1.7k | Automated safety check: Pass | Custom licence | |
| Testingkortix-ai/suna | 20k | — | ~3.6k | Automated safety check: Notes | Custom licence | |
| OpenLogi Change VerificationAprilNEA/OpenLogi | 23k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 |
PowerShell/PowerShell
Investigates failing Pester tests in PowerShell CI jobs by following a six-step workflow from pull request status to documented fix recommendations.
RustPython/RustPython
Runs RustPython tests inside a Linux container built with Apple's container CLI, so macOS users can compare Linux results with their local ones.
mozilla-firefox/firefox
Handle a Perfherder performance regression bug end to end: read the alert bug, confirm whether the regression is real, find the cause, and iterate to a fix.
kortix-ai/suna
A skill your agent uses for every Kortix test task, behavior change, bug fix, refactor, API route change, CLI change, SDK change, browser journey, test failure, coverage question, local benchmark…
AprilNEA/OpenLogi
Plans the smallest check that could disprove a code change in the OpenLogi project, then escalates through reproduction, focused tests and a final gate before a push.
RustPython/RustPython
Investigates a failing RustPython test by comparing it with CPython, then either fixes it or gathers the details for an incompatibility report.
yonatangross/orchestkit
API contract design for REST and GraphQL, covering resource shape, URL and header versioning with deprecation windows, RFC 9457 Problem Details error handling, and OpenAPI specs.
yonatangross/orchestkit
ADR templates in the Nygard format with context, decision, consequences, and alternatives.
yonatangross/orchestkit
Single-pass codebase analysis leveraging a 1M-token context window for comprehensive security scanning, architecture review, and dependency auditing.
yonatangross/orchestkit
Structured review processes, conventional comments, language-specific checklists, and feedback templates.
yonatangross/orchestkit
Creates GitHub pull requests with pre-flight validation, conventional title formatting, and structured summary generation.
yonatangross/orchestkit
Multi-angle codebase exploration spawning 3-5 parallel agents for code structure, data flow, architecture patterns, and health assessment.
Categories
Daily autonomous classifier for failing PRs across your repos. CI Sentinel is an agent skill from yonatangross/orchestkit. Daily autonomous classifier for failing PRs across your repos.
CI Sentinel fits situations like: youre tired of /status sweeps catching the same 10 CI failure patterns over and over; tasks that involve Failing and flaky tests.
Run `npx skills add yonatangross/orchestkit --skill ci-sentinel -a claude-code`. Or copy the skill folder (src/skills/ci-sentinel in yonatangross/orchestkit) into .claude/skills/ci-sentinel in your project. Claude Code loads it when a task matches its description.
Run `npx skills add yonatangross/orchestkit --skill ci-sentinel -a codex`. Or copy the skill folder (src/skills/ci-sentinel in yonatangross/orchestkit) into .agents/skills/ci-sentinel in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yonatangross/orchestkit --skill ci-sentinel -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ci-sentinel, .gemini/skills/ci-sentinel, .github/skills/ci-sentinel and .opencode/skills/ci-sentinel in your project.
Going by SKILL.md and its folder, CI Sentinel needs the command-line tools its instructions call (claude, gh and git) and credentials named CLAUDE_CODE_OAUTH_TOKEN, ANTHROPIC_API_KEY, GITHUB_TOKEN and GH_TOKEN. Our summary lists: A credential in ANTHROPIC_API_KEY; A credential in CLAUDE_CODE_OAUTH_TOKEN. Its frontmatter pre-approves these tools: Bash, Read, Write, Edit, Grep, Glob. Compatibility (from SKILL.md): Claude Code 2.1.277+ (uses --permission-mode + --no-session-persistence for headless GHA runs; --bare was tried but doesn't honor ANTHROPIC_API_KEY in CC 2.1.143 — see SKILL body for the trade-off)..
SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
CI Sentinel is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with CI Sentinel: Pester Failure Analysis (PowerShell/PowerShell, 56k stars), Apple Container Test Runner (RustPython/RustPython, 22k stars), Perf Regression Triage (mozilla-firefox/firefox, 13k stars) and Testing (kortix-ai/suna, 20k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
yonatangross (a GitHub user) maintains it in yonatangross/orchestkit, which has 290 GitHub stars. The repository holds 108 skills in this directory. The repository was last updated on October 9, 2026.
Source: yonatangross/orchestkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.