Skip to content
Back to skills

Codeowners Manager

ASecurity

Scaffold and validate GitHub CODEOWNERS files — map path patterns to owning teams and ensure critical paths are covered. Use when creating, editing, or reviewing a CODEOWNERS file, setting up code-review ownership, or checking that sensitive paths have required reviewers. Triggers on "CODEOWNERS", "code owners", "who owns this path", "required reviewers", "ownership rules".

  • 2 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added October 1, 2026
ai-agentsgoterraformdebuggingcode-reviewgitci/cdsecurity

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 1, 2026

npx -y skills add matthews-wong/claude-code-plugins --skill codeowners-manager --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Codeowners Manager?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Codeowners Manager
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/matthews-wong-codeowners-manager/badge)](https://www.skillsdirectory.com/skills/matthews-wong-codeowners-manager)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: codeowners-manager
description: 'Scaffold and validate GitHub CODEOWNERS files — map path patterns to owning teams and ensure critical paths are covered. Use when creating, editing, or reviewing a CODEOWNERS file, setting up code-review ownership, or checking that sensitive paths have required reviewers. Triggers on "CODEOWNERS", "code owners", "who owns this path", "required reviewers", "ownership rules".'
---

# CODEOWNERS Manager

Build and check GitHub CODEOWNERS files. The golden rule: **the last matching pattern wins** — order general-to-specific, not the reverse.

## Valid locations

GitHub reads CODEOWNERS from (first found wins): `.github/CODEOWNERS`, root `/CODEOWNERS`, or `/docs/CODEOWNERS`. Only one is used.

## Syntax essentials

- One rule per line: `<pattern>  <owner> [<owner>...]`.
- Patterns follow gitignore-style globs: `*`, `**`, leading `/` anchors to root, trailing `/` matches a directory.
- Owners are `@username`, `@org/team`, or an email tied to a GitHub account. Teams must have write access and be visible to the repo.
- `#` starts a comment. Blank lines ignored.
- A pattern with **no owner** removes ownership for that path — usually a mistake unless intentional.

Example:
```
# General
*                       @acme/maintainers
# More specific overrides (must come AFTER the general rule)
/src/auth/**            @acme/security
/.github/workflows/     @acme/platform
/CODEOWNERS             @acme/security
```

## Critical paths that should always be owned

Auth/identity, security config, `/.github/workflows/` (CI/CD), infra/IaC (Terraform, k8s, Helm), dependency manifests (package.json, requirements, go.mod, Cargo.toml), DB migrations, secrets/env templates, and the CODEOWNERS file itself. Load `reference/codeowners-syntax.md` for the full critical-path checklist and pattern recipes.

## Validation checklist (quick)

1. File is in a valid location.
2. Every rule has at least one owner (unless intentionally clearing).
3. No rule is fully shadowed by a later, broader match.
4. All critical paths resolve to an owner.
5. Patterns actually match files present in the repo (flag dead patterns).

## Going deeper

Full pattern-matching rules, ordering pitfalls, common recipes, and the complete critical-path list are in `reference/codeowners-syntax.md`. Load it when scaffolding a real file or debugging match behavior.

Files in this skill

  • SKILL.md2.3 KB
  • reference/codeowners-syntax.md3.3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…