GitHub Actions Manual Trigger Audit
Use this skill to detect workflows that rely too heavily on manual triggers (workflow_dispatch / repository_dispatch) instead of automated CI events.
What this skill does
- Reads GitHub Actions run JSON exports
- Groups runs by repository + workflow (+ branch)
- Measures manual-trigger share vs total run volume
- Tracks recent manual-trigger streaks (latest N runs)
- Scores severity (
ok, warn, critical) for operational risk gating
- Emits text or JSON output for automation
Inputs
Optional:
RUN_GLOB (default: artifacts/github-actions/*.json)
TOP_N (default: 20)
OUTPUT_FORMAT (text or json, default: text)
GROUP_BY (workflow or workflow-branch, default: workflow)
MANUAL_EVENTS (comma-separated, default: workflow_dispatch,repository_dispatch)
RECENT_WINDOW (latest runs inspected for streak, default: 5)
MIN_RUNS (minimum runs required, default: 5)
WARN_MANUAL_RATIO (0..1, default: 0.35)
CRITICAL_MANUAL_RATIO (0..1, default: 0.65)
WARN_MANUAL_RUNS (default: 5)
CRITICAL_MANUAL_RUNS (default: 12)
WARN_RECENT_MANUAL_STREAK (default: 3)
CRITICAL_RECENT_MANUAL_STREAK (default: 5)
WORKFLOW_MATCH / WORKFLOW_EXCLUDE (regex, optional)
BRANCH_MATCH / BRANCH_EXCLUDE (regex, optional)
EVENT_MATCH / EVENT_EXCLUDE (regex, optional)
REPO_MATCH / REPO_EXCLUDE (regex, optional)
FAIL_ON_CRITICAL (0 or 1, default: 0)
Collect run JSON
gh run view <run-id> --json databaseId,workflowName,event,headBranch,conclusion,createdAt,updatedAt,url,repository \
> artifacts/github-actions/run-<run-id>.json
Run
Text report:
RUN_GLOB='artifacts/github-actions/*.json' \
bash skills/github-actions-manual-trigger-audit/scripts/manual-trigger-audit.sh
JSON output + fail gate:
RUN_GLOB='artifacts/github-actions/*.json' \
OUTPUT_FORMAT=json \
FAIL_ON_CRITICAL=1 \
bash skills/github-actions-manual-trigger-audit/scripts/manual-trigger-audit.sh
Run against bundled fixtures:
RUN_GLOB='skills/github-actions-manual-trigger-audit/fixtures/*.json' \
bash skills/github-actions-manual-trigger-audit/scripts/manual-trigger-audit.sh
Output contract
- Exit
0 in report mode (default)
- Exit
1 when FAIL_ON_CRITICAL=1 and one or more groups are critical
- Text mode prints summary + ranked workflow groups
- JSON mode prints summary + ranked groups + critical groups
1---2name: github-actions-manual-trigger-audit3description: Audit manual GitHub Actions trigger dependence by workflow/event to flag automation gaps and intervention risk.4---56# GitHub Actions Manual Trigger Audit78Use this skill to detect workflows that rely too heavily on manual triggers (`workflow_dispatch` / `repository_dispatch`) instead of automated CI events.910## What this skill does11- Reads GitHub Actions run JSON exports12- Groups runs by repository + workflow (+ branch)13- Measures manual-trigger share vs total run volume14- Tracks recent manual-trigger streaks (latest N runs)15- Scores severity (`ok`, `warn`, `critical`) for operational risk gating16- Emits text or JSON output for automation1718## Inputs19Optional:20- `RUN_GLOB` (default: `artifacts/github-actions/*.json`)21- `TOP_N` (default: `20`)22- `OUTPUT_FORMAT` (`text` or `json`, default: `text`)23- `GROUP_BY` (`workflow` or `workflow-branch`, default: `workflow`)24- `MANUAL_EVENTS` (comma-separated, default: `workflow_dispatch,repository_dispatch`)25- `RECENT_WINDOW` (latest runs inspected for streak, default: `5`)26- `MIN_RUNS` (minimum runs required, default: `5`)27- `WARN_MANUAL_RATIO` (0..1, default: `0.35`)28- `CRITICAL_MANUAL_RATIO` (0..1, default: `0.65`)29- `WARN_MANUAL_RUNS` (default: `5`)30- `CRITICAL_MANUAL_RUNS` (default: `12`)31- `WARN_RECENT_MANUAL_STREAK` (default: `3`)32- `CRITICAL_RECENT_MANUAL_STREAK` (default: `5`)33- `WORKFLOW_MATCH` / `WORKFLOW_EXCLUDE` (regex, optional)34- `BRANCH_MATCH` / `BRANCH_EXCLUDE` (regex, optional)35- `EVENT_MATCH` / `EVENT_EXCLUDE` (regex, optional)36- `REPO_MATCH` / `REPO_EXCLUDE` (regex, optional)37- `FAIL_ON_CRITICAL` (`0` or `1`, default: `0`)3839## Collect run JSON4041```bash42gh run view <run-id> --json databaseId,workflowName,event,headBranch,conclusion,createdAt,updatedAt,url,repository \43 > artifacts/github-actions/run-<run-id>.json44```4546## Run4748Text report:4950```bash51RUN_GLOB='artifacts/github-actions/*.json' \52bash skills/github-actions-manual-trigger-audit/scripts/manual-trigger-audit.sh53```5455JSON output + fail gate:5657```bash58RUN_GLOB='artifacts/github-actions/*.json' \59OUTPUT_FORMAT=json \60FAIL_ON_CRITICAL=1 \61bash skills/github-actions-manual-trigger-audit/scripts/manual-trigger-audit.sh62```6364Run against bundled fixtures:6566```bash67RUN_GLOB='skills/github-actions-manual-trigger-audit/fixtures/*.json' \68bash skills/github-actions-manual-trigger-audit/scripts/manual-trigger-audit.sh69```7071## Output contract72- Exit `0` in report mode (default)73- Exit `1` when `FAIL_ON_CRITICAL=1` and one or more groups are critical74- Text mode prints summary + ranked workflow groups75- JSON mode prints summary + ranked groups + critical groups