Skip to content
Back to skills

Github Actions

ASecurity

Author or fix a GitHub Actions workflow with correct triggers, jobs, caching, and permissions

  • 3 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 3, 2026
ai-agentsgodebugginggit

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add black141312/ada --skill github-actions --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Github Actions?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Github Actions
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/black141312-github-actions/badge)](https://www.skillsdirectory.com/skills/black141312-github-actions)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: github-actions
description: Author or fix a GitHub Actions workflow with correct triggers, jobs, caching, and permissions
category: ci-cd
---

# GitHub Actions

Use when creating a new `.github/workflows/*.yml` or debugging one that fails, misfires, or runs too often.

1. Set the right triggers in `on:` (`push`, `pull_request`, `workflow_dispatch`, `schedule`) and scope branches/paths to avoid noise.
2. Define jobs with a pinned `runs-on` image; use a `matrix` only when you genuinely test multiple versions.
3. Pin actions to a tag or SHA (`actions/checkout@v4`), set up the runtime, and cache deps with `actions/cache` or the setup action's built-in cache.
4. Grant least-privilege `permissions:` (default read; add `contents: write` / `id-token: write` only where needed).
5. Store credentials in repo/org Secrets and reference via `${{ secrets.X }}`; never echo them.
6. Validate by pushing to a branch and reading the run logs; when fixing, reproduce the failing step and inspect its exact output.

## Rules
- Pin third-party actions by SHA or major tag — floating `@master` is a supply-chain risk.
- Set explicit `permissions:` per workflow or job; the broad default token is too powerful.
- Add `concurrency:` with `cancel-in-progress` to kill superseded runs on the same ref.
- Don't print secrets to logs and don't expose them to PRs from forks.
- When debugging, read the failing job's logs first — guessing at YAML wastes runs.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…