Skip to content
Back to skills

Publishing Trigger Check

ASecurity

Verify GitHub Pages publishing remains family-agnostic and fail-closed.

  • 3 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 3, 2026
ai-agentsbashnodegit

Security analysis

A100/100

Pro scans all 4 files and shows the line behind each finding

Scanned September 3, 2026

npx -y skills add OKHP3/skillz --skill publishing-trigger-check --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Publishing Trigger Check?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Publishing Trigger Check
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/okhp3-publishing-trigger-check/badge)](https://www.skillsdirectory.com/skills/okhp3-publishing-trigger-check)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: publishing-trigger-check
description: Verify GitHub Pages publishing remains family-agnostic and fail-closed.
---

# Publishing trigger check

## Use when

Run after changing `.github/workflows/deploy-pages.yml` (the real path GitHub
Actions executes) or family/skill folder conventions. It reuses the
repository's existing `verify-deploy-trigger.mjs`.

## Callable command

```bash
node .agents/skills/publishing-trigger-check/run.mjs
```

The check requires the workflow to contain a family-independent
`**/FAMILY.md` or `**/SKILL.md` glob, rejects hardcoded current family names,
and exits non-zero when the workflow is absent or unsafe. It never pushes,
publishes, force-pushes, or handles tokens.

## Companion-site release audit

From a network-enabled environment, run:

```bash
node .agents/skills/publishing-trigger-check/audit-sites.mjs --strict
```

This independently probes OverKill Hill, Glee-fully Tools, and AskJamie for
home/about/legal/sitemap responses, canonical and OG metadata, OG image
reachability, sitemap samples, CNAME alignment, workflow deploy handoff, and
repository-vs-live freshness. Add `--json` for archival automation output.

`--strict` blocks when a repository has no proven deploy step; this currently
identifies a site as blocked only when neither a repository deploy step nor a
successful GitHub-managed Pages run can be proven. If GitHub manages the
deployment outside repository YAML, the runner reports that limitation
explicitly rather than silently treating validation as publishing. It does not
infer or change DNS, repository settings, or deployment ownership.

Files in this skill

  • RELEASE-CHECKLIST.md1.9 KB
  • SKILL.md1.6 KB
  • audit-sites.mjs8 KB
  • run.mjs1.5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…