ai-coding-agents
Comprehensive guide for using Codex CLI (OpenAI) and Claude Code CLI (Anthropic) - AI-powered…
Audit GitHub Actions workflows for correctness, security, and unattended reliability. Use when asked to audit workflows, check CI health, review workflow security, or before committing workflow changes.
$ npx -y skills add xiaolai/vmark --skill workflow-audit --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/workflow-auditContext preview
The summary Claude sees to decide when to auto-load this skill.
Audit GitHub Actions workflows for correctness, security, and unattended reliability. Use when asked to audit workflows, check CI health, review workflow security, or before committing workflow changes.
name: workflow-audit description: >- Audit GitHub Actions workflows for correctness, security, and unattended reliability. Use when asked to audit workflows, check CI health, review workflow security, or before committing workflow changes.
Comprehensive audit of `.github/workflows/*.yml` files against GitHub Actions best practices, security hardening guidelines, and project conventions.
1. **Discover** — Glob `.github/workflows/*.yml` and list all workflow files. 2. **Parse** — Read each file; validate YAML syntax. 3. **Audit** — Run every check in the checklist below against each file. 4. **Cross-check** — Run cross-workflow consistency checks. 5. **Report** — Output a findings table sorted by severity (critical > high > medium > low). 6. **Fix offer** — For each finding, suggest a concrete fix (diff or instruction).
Check every `uses:` line.
| Pattern | Severity | Rule | |---------|----------|------| | `actions/checkout@v4` or lower | **critical** | Upgrade to `@v6`. Node.js 20 actions break June 2, 2026 (forced to Node 24). | | `actions/setup-node@v4` or lower | **critical** | Same — upgrade to `@v6`. | | `actions/cache@v3` or lower | **high** | Upgrade to `@v4`. | | `pnpm/action-setup@v3` or lower | **high** | Upgrade to `@v4`. | | `softprops/action-gh-release@v1` | **medium** | Upgrade to `@v2`. | | `actions/upload-pages-artifact@v2` or lower | **medium** | Upgrade to `@v3`. | | `actions/deploy-pages@v3` or lower | **medium** | Upgrade to `@v4`. | | Any `@main` or `@master` pin | **high** | Pin to a tag or SHA — mutable refs are a supply-chain risk. |
**Node.js deprecation timeline** (reference for findings):
For every `run:` block, check for **untrusted context expressions used inline**:
# DANGEROUS — attacker-controlled input interpreted by shell
run: echo "${{ github.event.issue.title }}"
# SAFE — passed via environment variable
env:
TITLE: ${{ github.event.issue.title }}
run: echo "$TITLE"**Untrusted contexts** (must NEVER appear directly in `run:` blocks):
**Safe contexts** (numeric or system-controlled, OK inline):
| Check | Severity | Rule | |-------|----------|------| | No `permissions:` block at all | **high** | Add explicit permissions — defaults give broad access. | | `permissions: write-all` | **critical** | Never use. Specify individual scopes. | | Unused permission scopes | **medium** | Remove permissions not needed by any step. | | `id-token: write` without OIDC usage | **medium** | Only needed for Bedrock/Vertex/Foundry or cloud OIDC. | | `pull_request_target` trigger | **high** | Grants write access from forks — verify checkout uses PR base, not head. |
| Check | Severity | Rule | |-------|----------|------| | `gh pr merge --auto` without author guard | **high** | Restrict to bot PRs: `if: github.event.pull_request.user.login == 'claude[bot]'` | | `allowed_bots: '*'` in claude-code-action | **medium** | Prefer explicit bot names over wildcard. |
| Check | Severity | Rule | |-------|----------|------| | Job without `timeout-minutes` | **high** | Default is 360 min (6 hours). Always set explicit timeouts. | | Claude Code action jobs | **high** | Must have `timeout-minutes` (recommended: 15 for review, 30 for fix). | | Build jobs | **medium** | Recommended: 30-45 min depending on platform. |
| Check | Severity | Rule | |-------|----------|------| | `git push` to a protected branch | **critical** | Will fail if branch protection requires status checks. Push to unprotected branch or use PR. | | `gh pr merge` without `\|\| true` or `continue-on-error` | **medium** | May fail if PR is not mergeable — handle gracefully. | | Steps after a `continue-on-error` step that depend on its output | **medium** | Check if downstream steps handle the soft failure. | | Network-dependent steps without retry or `continue-on-error` | **low** | CDN downloads, API calls can be flaky. |
| Check | Severity | Rule | |-------|----------|------| | Scheduled workflow without `concurrency` group | **medium** | Overlapping runs waste resources. | | `cancel-in-progress: true` on deploy workflows | **high** | Can corrupt partial deployments. Use `false` for deploys. | | Missing `concurrency` on Claude Code jobs | **medium** | Multiple concurrent AI runs on the same issue/PR waste credits. |
| Check | Severity | Rule | |-------|----------|------| | Workflow pushes to `main` (or default branch) | *
The Plain-Text Workspace Where Humans and AI Collaborate Free. Local-first. Format-aware. VMark is the plain-text workspace where humans and AI collaborate.
Repo: xiaolai/vmark
Comprehensive guide for using Codex CLI (OpenAI) and Claude Code CLI (Anthropic) - AI-powered…
Test-driven CSS design system modifications. Run checks before/after CSS changes to verify…
Build or update MCP server/client integrations for VMark. Use when configuring MCP servers,…
Discover, register, and verify MCP servers. Use when a user asks to…
Audit an implementation against a plan (dev-docs/plans/*). Use when a user asks to check for…
Verify a completed implementation against a plan by running gates and checking acceptance…