Skip to content
Back to skills

Create Github Action

ASecurity

Scaffolds a deterministic GitHub Actions CI/CD workflow YAML. NOT for scaffolding interactive agentic workflows (use `create-agentic-workflow`) and NOT for local event-driven hooks (use `create-hook`).

  • 7 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 2, 2026
ai-agentspythonbashgitci/cdsecurity

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned October 3, 2026

npx -y skills add richfrem/agent-plugins-skills --skill create-github-action --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Create Github Action?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Create Github Action
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/richfrem-create-github-action-agent-plugins-skills/badge)](https://www.skillsdirectory.com/skills/richfrem-create-github-action-agent-plugins-skills)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: create-github-action
plugin: agent-scaffolders
description: >
  Scaffolds a deterministic GitHub Actions CI/CD workflow YAML. NOT for scaffolding interactive agentic workflows (use `create-agentic-workflow`) and NOT for local event-driven hooks (use `create-hook`).
argument-hint: "[workflow-type: test|build|deploy|lint|release|security]"
allowed-tools: Bash, Read, Write
---

# Create GitHub Action (create-github-action)

Scaffolds deterministic GitHub Actions CI/CD workflow configurations (`.github/workflows/<name>.yml`) without runtime AI orchestration.

## Contents
- [Critical Constraints](#critical-constraints)
- [Quick start](#quick-start)
- [Workflow](#workflow)
- [Verification](#verification)
- [References](#references)

## Critical Constraints
- **Deterministic Scope**: Traditional CI/CD only (no runtime LLMs). For agentic or prompt-driven automation, use `create-agentic-workflow`. For local tool hooks, use `create-hook`.
- **Least-Privilege Permissions**: Explicitly specify minimal `permissions:` blocks (e.g. `contents: read`) at workflow or job level; never omit or use broad write tokens.
- **Action Pinning & Timeouts**: Pin third-party actions to verified major versions or SHAs. Set explicit `timeout-minutes` on all jobs.
- **Secret Sanitization**: Reference secrets exclusively via `${{ secrets.NAME }}`; never hardcode sensitive values or log secret outputs.

## Quick start

```bash
# Seed discovery for a specific workflow type (test, build, deploy, lint, release)
python3 plugins/agent-scaffolders/scripts/scaffold.py \
  --type workflow \
  --name ci-pipeline \
  --path .github/workflows/ci.yml
```

## Workflow

1. **Phase 1: Pipeline Discovery**: Identify workflow trigger events (`push`, `pull_request`, `workflow_dispatch`), target runner environments (`ubuntu-latest`), matrix strategies, and dependencies.
2. **Phase 2: Scaffolding Generation**: Construct `.github/workflows/<name>.yml` with explicit triggers, concurrency controls, least-privilege permissions, and step caching.
3. **Phase 3: Secrets & Environment Setup**: Document required repository secrets and environment variables without logging actual secrets.
4. **Phase 4: Schema Validation**: Validate the generated YAML syntax and step structure against GitHub Actions schema standards.

## Verification

```bash
# Check YAML syntax and schema formatting
python3 -c "import yaml; yaml.safe_load(open('.github/workflows/<name>.yml'))"

# Audit skill compliance
python3 plugins/agent-scaffolders/scripts/audit_skill.py plugins/agent-scaffolders/skills/create-github-action --mode source
```

## References
- [fallback-tree.md](references/fallback-tree.md) - Procedural fallbacks for generation failures.
- [references/action-types.md](references/action-types.md) - Supported GitHub Action pipeline archetypes.
- [acceptance-criteria.md](references/acceptance-criteria.md) - Quality gates for CI/CD workflows.

Files in this skill

  • SKILL.md1.4 KB
  • acceptance-criteria.md457 B
  • evals/evals.json923 B
  • evals/results.tsv417 B
  • fallback-tree.md1.4 KB
  • references/acceptance-criteria.md42 B
  • references/action-types.md35 B
  • references/fallback-tree.md36 B
  • references/hitl-interaction-design.md46 B
  • references/pattern-decision-matrix.md46 B
  • references/patterns/action-forcing-output-with-deadline-attribution.md82 B
  • references/patterns/adversarial-objectivity-constraint.md69 B
  • references/patterns/anti-pattern-vaccination.md59 B
  • references/patterns/anti-symptom-triage.md54 B
  • references/patterns/artifact-embedded-execution-audit-trail.md74 B
  • references/patterns/artifact-generation-xss-compliance-gate.md74 B
  • references/patterns/artifact-lifecycle.md53 B
  • references/patterns/artifact-state-interrogative-routing.md71 B
  • references/patterns/asynchronous-benchmark-metric-capture.md72 B
  • references/patterns/audience-segmented-information-filtering.md75 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…