Skip to content
Security
Skill

/prowler-ci

Helps with Prowler repository CI and PR gates (GitHub Actions workflows). Trigger: When investigating CI checks failing on a PR, PR title validation, changelog gate/no-changelog label, conflict marker checks, secret scanning, CODEOWNERS/labeler automation, or anything under

From plugin
prowler
15k39 skills1 MCP
Install
$ npx -y skills add prowler-cloud/prowler --skill prowler-ci --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/prowler-ci

Context preview

The summary Claude sees to decide when to auto-load this skill.

Helps with Prowler repository CI and PR gates (GitHub Actions workflows). Trigger: When investigating CI checks failing on a PR, PR title validation, changelog gate/no-changelog label, conflict marker checks, secret scanning, CODEOWNERS/labeler automation, or anything under

SKILL.md

prowler-ci.SKILL.md
name: prowler-ci
description: >
  Helps with Prowler repository CI and PR gates (GitHub Actions workflows).
  Trigger: When investigating CI checks failing on a PR, PR title validation, changelog gate/no-changelog label,
  conflict marker checks, secret scanning, CODEOWNERS/labeler automation, or anything under .github/workflows.
license: Apache-2.0
metadata:
  author: prowler-cloud
  version: "1.0"
  scope: [root]
  auto_invoke:
    - "Inspect PR CI checks and gates (.github/workflows/*)"
    - "Debug why a GitHub Actions job is failing"
    - "Understand changelog gate and no-changelog label behavior"
    - "Understand PR title conventional-commit validation"
    - "Understand CODEOWNERS/labeler-based automation"
allowed-tools: Read, Edit, Write, Glob, Grep, Bash

What this skill covers

Use this skill whenever you are:

  • Reading or changing GitHub Actions workflows under `.github/workflows/`
  • Explaining why a PR fails checks (title, changelog, conflict markers, secret scanning)
  • Figuring out which workflows run for UI/API/SDK changes and why
  • Diagnosing path-filtering behavior (why a workflow did/didn't run)

Quick map (where to look)

  • PR template: `.github/pull_request_template.md`
  • PR title validation: `.github/workflows/conventional-commit.yml`
  • Changelog gate: `.github/workflows/pr-check-changelog.yml` (requires a fragment under `<component>/changelog.d/`)
  • Changelog compile (release time): `.github/workflows/compile-changelogs.yml`
  • Conflict markers check: `.github/workflows/pr-conflict-checker.yml`
  • Secret scanning: `.github/workflows/find-secrets.yml`
  • Auto labels: `.github/workflows/labeler.yml` and `.github/labeler.yml`
  • Review ownership: `.github/CODEOWNERS`

Debug checklist (PR failing checks)

1. Identify which workflow/job is failing (name + file under `.github/workflows/`). 2. Check path filters: is the workflow supposed to run for your changed files? 3. If it's a title check: verify PR title matches Conventional Commits. 4. If it's changelog: verify a valid fragment exists under the right `<component>/changelog.d/` OR apply `no-changelog` label. 5. If it's conflict checker: remove `<<<<<<<`, `=======`, `>>>>>>>` markers. 6. If it's secrets (TruffleHog): see section below.

TruffleHog Secret Scanning

TruffleHog scans for leaked secrets. Common false positives in test files:

**Patterns that trigger TruffleHog:**

  • `sk-*T3BlbkFJ*` - OpenAI API keys
  • `AKIA[A-Z0-9]{16}` - AWS Access Keys
  • `ghp_*` / `gho_*` - GitHub tokens
  • Base64-encoded strings that look like credentials

**Fix for test files:**

# BAD - looks like real OpenAI key
api_key = "sk-test1234567890T3BlbkFJtest1234567890"

# GOOD - obviously fake
api_key = "sk-fake-test-key-for-unit-testing-only"

**If TruffleHog flags a real secret:** 1. Remove the secret from the code immediately 2. Rotate the credential (it's now in git history) 3. Consider using `.trufflehog-ignore` for known false positives (rarely needed)

Notes

  • Keep `prowler-pr` focused on *creating* PRs and filling the template.
  • Use `prowler-ci` for *CI policies and gates* that apply to PRs.
Read more
Ships withprowler

Prowler is the world’s most widely used Open-Source Cloud Security Platform that automates security and compliance across any cloud environment.

Get the whole plugin
Stats
14,557
Stars
2,311
Forks
Active
Maintenance
Python
Language
Apache-2.0
License
33m ago
Last commit
9y ago
Created

Repo: prowler-cloud/prowler