CI/CD Agent Skills

CI/CD

307 skills
github
acreadiness-policy
Create, apply, and manage AgentRC policies to customize readiness scoring, disable checks, override impact levels, set pass-rate thresholds, and enforce CI gating.
36.2k
github
copilot-pr-autopilot
Automates repeated rounds of Copilot code review on GitHub pull requests: triggers review, triages threads, dispatches parallel fix agents, commits, replies, and loops until convergence.
36.2k · bundle
github
azure-static-web-apps
Create, configure, and deploy Azure Static Web Apps using the SWA CLI, including local development, runtime configuration, and CI/CD setup.
36.2k
github
github-copilot-starter
Generates a complete GitHub Copilot configuration for a new project, including instructions, reusable skills, and agent definitions tailored to the technology stack.
36.2k
github
bigquery-pipeline-audit
Audits Python + BigQuery pipelines for cost safety, idempotency, and production readiness, returning a structured report with exact patch locations.
36.2k
github
github-actions-hardening
Reviews and hardens GitHub Actions workflows against injection, privilege escalation, supply-chain, and token-scoping risks that pattern matchers miss.
36.2k · bundle
github
agentic-workflows
Routes requests to design, create, update, debug, or upgrade GitHub Agentic Workflows by loading the appropriate workflow prompt or skill file.
36.2k
github
github-actions-efficiency
Audit GitHub Actions workflow efficiency and recommend fixes to reduce CI minutes and costs.
36.2k · bundle
github
python-pypi-package-builder
Build, test, lint, version, and publish production-grade Python libraries to PyPI with support for multiple build backends, versioning strategies, and CI/CD.
36.2k · bundle
github
acreadiness-generate-instructions
Generate tailored AI agent instruction files for VS Code Copilot and other coding agents, using AgentRC to analyze your codebase and produce flat or nested instruction files with optional per-area scoping.
36.2k
github
create-github-action-workflow-specification
Creates a formal, AI-optimized specification for an existing GitHub Actions CI/CD workflow, focusing on behavior and requirements rather than implementation details.
36.2k
trailofbits
semgrep
Run Semgrep static analysis scans with automatic language detection, parallel subagent execution, and merged SARIF output. Supports full ruleset coverage or high-confidence security vulnerability filtering.
6k · bundle
trailofbits
sarif-parsing
Parse, analyze, and process SARIF files from static analysis tools like CodeQL and Semgrep, including filtering, deduplication, aggregation, and CI/CD integration.
6k · bundle
trailofbits
audit-prep-assistant
Prepares codebases for security review using Trail of Bits' checklist by setting review goals, running static analysis, increasing test coverage, removing dead code, and generating documentation.
6k · bundle
composiohq
codacy-automation
Automate Codacy code quality operations through Composio's Codacy toolkit via Rube MCP.
66.9k
composiohq
prisma-automation
Automate Prisma database operations through Composio's Prisma toolkit via Rube MCP, including tool discovery, connection management, and execution.
66.9k
composiohq
seqera-automation
Automate Seqera operations through Composio's Seqera toolkit via Rube MCP, with tool discovery and connection management.
66.9k
composiohq
appveyor-automation
Automate Appveyor CI/CD operations through Composio's toolkit via Rube MCP, including tool discovery, connection management, and workflow execution.
66.9k
composiohq
conveyor-automation
Automate Conveyor operations by discovering and executing tools through Rube MCP and Composio's Conveyor toolkit.
66.9k
composiohq
signpath-automation
Automate Signpath operations through Composio's Signpath toolkit via Rube MCP, including tool discovery, connection management, and execution.
66.9k
composiohq
appcircle-automation
Automate Appcircle CI/CD operations through Composio's Appcircle toolkit via Rube MCP, with tool discovery and connection management.
66.9k
composiohq
buildkite-automation
Automate Buildkite CI/CD operations through Composio's toolkit via Rube MCP, including pipeline management and job execution.
66.9k
composiohq
fluxguard-automation
Automate Fluxguard operations through Composio's Fluxguard toolkit via Rube MCP, with dynamic tool discovery and connection management.
66.9k
dimillian
github
Interact with GitHub repositories using the `gh` CLI to manage issues, pull requests, CI runs, and query the GitHub API.
3.8k · bundle
k-dense-ai
arbor
Run autonomous optimization loops that iteratively improve artifacts against evaluators using hypothesis tree refinement, without overfitting.
30.2k · bundle
k-dense-ai
nextflow
Build, run, and debug Nextflow data pipelines and nf-core workflows end to end, covering processes, channels, operators, configuration, testing, and deployment to HPC or cloud.
30.2k · bundle
k-dense-ai
pacsomatic
Validates inputs, generates samplesheets and launch scripts, and optionally executes nf-core/pacsomatic matched tumor-normal workflows from BAM files, supporting local runs and scheduler submission (LSF/Slurm/PBS/SGE).
30.2k · bundle
mcollina
octocat
Handles git and GitHub operations using the gh CLI, triggered by any github.com URL. Covers creating and reviewing PRs, watching CI checks, interactive rebasing, branch cleanup, submodule management, and repository archaeology.
1.9k · bundle
mcollina
nodejs-core
Provides deep expertise in Node.js internals: V8 engine, libuv event loop, native addon development, build systems, and performance debugging.
1.9k · bundle
mukul975
generating-and-analyzing-sboms
Generate CycloneDX and SPDX SBOMs from container images and filesystems, scan them for vulnerabilities with Grype, and sign attestations with Cosign for supply-chain trust.
24.6k · bundle
mukul975
detecting-typosquatting-packages
Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation using edit-distance, keyboard-proximity, and known-target corpus matching with typomania, OSSGadget, and pypi-scan.
24.6k · bundle
mukul975
scanning-docker-images-with-trivy
Scan Docker images for vulnerabilities, misconfigurations, secrets, and license violations using Trivy, with CI/CD integration and policy enforcement.
24.6k · bundle
mukul975
securing-github-actions-workflows
Hardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation by pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, preventing script injection, and implementing workflow change controls.
24.6k · bundle
mukul975
scanning-iac-and-images-with-trivy
Scan container images, IaC, and SBOMs for vulnerabilities and misconfigurations in CI/CD with Trivy.
24.6k · bundle
mukul975
securing-container-registry-images
Scan container images for vulnerabilities with Trivy and Grype, generate SBOMs, sign images with Cosign and Sigstore, configure registry access controls, and enforce security gates in CI/CD pipelines.
24.6k · bundle
mukul975
implementing-gcp-binary-authorization
Enforce deploy-time security controls that ensure only trusted, attested container images are deployed to Google Kubernetes Engine and Cloud Run.
24.6k · bundle