Skip to content
Back to skills

Workflow Automation

ASecurity

Org role guidance for workflow automation: build and maintain CI/CD definitions in GitHub Actions or equivalent: triggers, jobs, matrices, caching. Covers path filters, dependency caching, parallel jobs, timeouts and fail-fast ordering.

  • 21 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 22, 2026
ai-agentsgitdevopsci/cd

Security analysis

A100/100

Scanned September 28, 2026

npx -y skills add monoes/monomind --skill workflow-automation --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Workflow Automation?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Workflow Automation
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/monoes-workflow-automation/badge)](https://www.skillsdirectory.com/skills/monoes-workflow-automation)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: workflow-automation
description: "Org role guidance for workflow automation: build and maintain CI/CD definitions in GitHub Actions or equivalent: triggers, jobs, matrices, caching. Covers path filters, dependency caching, parallel jobs, timeouts and fail-fast ordering."
tags: ["engineering","devops","deploy"]
tools: ["monograph_query","monograph_context","monograph_impact"]
license: Apache-2.0
source: https://github.com/monoes/monomind
---
# Workflow Automation — Best Practices

## Focus
Build and maintain the CI/CD workflow definitions themselves (GitHub Actions or equivalent) — triggers, jobs, matrices, caching — so pipelines are fast, reliable, and self-explanatory.

## Best practices
- Trigger workflows precisely (path filters, branch filters) — don't run the full suite on every push when only docs changed.
- Cache dependencies and build artifacts aggressively; a pipeline that reinstalls from scratch every run is wasting both time and money.
- Parallelize independent jobs (lint, unit tests, build) rather than chaining them sequentially when there's no real dependency.
- Set explicit timeouts on every job so a hung step doesn't burn CI minutes for hours.
- Fail fast on the cheapest checks first (lint, type-check) before running expensive ones (integration tests, e2e).
- Keep workflow YAML DRY via reusable/composite workflows instead of copy-pasting the same steps across files.
- Make failures diagnosable from the log alone — name steps clearly, echo context (commit, inputs) before the risky step runs.

## Common pitfalls
- Adding more and more steps to "be safe" without ever removing redundant or superseded checks — pipelines that take 20+ minutes because no one prunes them.
- Hardcoding secrets or tokens directly in workflow YAML instead of using the platform's secrets store.
- Retrying flaky steps blindly instead of fixing or quarantining the flaky test/step.
- Broad wildcard triggers (`on: push` with no path/branch filter) that fire the whole pipeline for irrelevant changes.
- Auto-generated workflow "self-healing" that masks real failures instead of surfacing them.

## Tools & techniques
- Path/branch filters and matrix builds to scope and parallelize work precisely.
- Dependency and build caching (lockfile-hash-keyed) to cut repeat-run time.
- Reusable workflows / composite actions for shared steps across multiple pipeline files.
- Required status checks + branch protection as the actual enforcement layer, not the workflow's exit code alone.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…