MCAF: CI/CD
Trigger On
- adding or changing CI workflows
- defining release flow or rollback policy
- tightening pipeline quality gates
- writing or reviewing AI-assisted pipeline YAML
Value
- produce a concrete project delta: code, docs, config, tests, CI, or review artifact
- reduce ambiguity through explicit planning, verification, and final validation skills
- leave reusable project context so future tasks are faster and safer
Do Not Use For
- feature-level testing with no pipeline or release impact
- general source-control policy without CI/CD changes
Inputs
- the current pipeline and release flow
- real build, test, analyze, and deploy steps
- environment and rollback constraints
Quick Start
- Read the nearest
AGENTS.md and confirm scope and constraints.
- Run this skill's
Workflow through the Ralph Loop until outcomes are acceptable.
- Return the
Required Result Format with concrete artifacts and verification evidence.
Workflow
- Define the target flow first:
- PR validation
- integration-branch gates
- non-production deployment
- production promotion or release
- Keep pipelines reviewable:
- explicit build, test, and analyze steps
- least-privilege secrets and permissions
- rollback or fail-safe strategy
- Treat AI-generated YAML as draft content until it is reviewed and validated.
- For .NET repositories, make the quality gate explicit:
- formatting ownership
- analyzer ownership
- coverage and report generation
- runner model (
VSTest or Microsoft.Testing.Platform)
- Pull only the references that match the current delivery problem.
Deliver
- CI/CD changes that are explicit, reproducible, and reviewable
- release documentation with rollback thinking
- pipeline rules aligned with MCAF verification
Validate
- every stage has a clear purpose and failure signal
- rollback or safe failure is explicit
- secrets and permissions are minimized
- the pipeline matches the repo’s actual verification model
Ralph Loop
Use the Ralph Loop for every task, including docs, architecture, testing, and tooling work.
- Plan first (mandatory):
- analyze current state
- define target outcome, constraints, and risks
- write a detailed execution plan
- list final validation skills to run at the end, with order and reason
- Execute one planned step and produce a concrete delta.
- Review the result and capture findings with actionable next fixes.
- Apply fixes in small batches and rerun the relevant checks or review steps.
- Update the plan after each iteration.
- Repeat until outcomes are acceptable or only explicit exceptions remain.
- If a dependency is missing, bootstrap it or return
status: not_applicable with explicit reason and fallback path.
Required Result Format
status: complete | clean | improved | configured | not_applicable | blocked
plan: concise plan and current iteration step
actions_taken: concrete changes made
validation_skills: final skills run, or skipped with reasons
verification: commands, checks, or review evidence summary
remaining: top unresolved items or none
For setup-only requests with no execution, return status: configured and exact next commands.
Load References
- read
references/ci-cd.md first
- for .NET quality gates, use
mcaf-dotnet-quality-ci
Example Requests
- "Design CI for this repo."
- "Tighten our deployment gates and rollback story."
- "Review this GitHub Actions YAML before we trust it."
1---2name: mcaf-ci-cd3description: Design or refine CI/CD workflows, quality gates, release flow, and safe AI-assisted pipeline authoring. Use when adding or changing build pipelines, release stages, IaC-driven environments, or deployment rollback policy.4---56# MCAF: CI/CD78## Trigger On910- adding or changing CI workflows11- defining release flow or rollback policy12- tightening pipeline quality gates13- writing or reviewing AI-assisted pipeline YAML1415## Value1617- produce a concrete project delta: code, docs, config, tests, CI, or review artifact18- reduce ambiguity through explicit planning, verification, and final validation skills19- leave reusable project context so future tasks are faster and safer2021## Do Not Use For2223- feature-level testing with no pipeline or release impact24- general source-control policy without CI/CD changes2526## Inputs2728- the current pipeline and release flow29- real build, test, analyze, and deploy steps30- environment and rollback constraints3132## Quick Start33341. Read the nearest `AGENTS.md` and confirm scope and constraints.352. Run this skill's `Workflow` through the `Ralph Loop` until outcomes are acceptable.363. Return the `Required Result Format` with concrete artifacts and verification evidence.3738## Workflow39401. Define the target flow first:41 - PR validation42 - integration-branch gates43 - non-production deployment44 - production promotion or release452. Keep pipelines reviewable:46 - explicit build, test, and analyze steps47 - least-privilege secrets and permissions48 - rollback or fail-safe strategy493. Treat AI-generated YAML as draft content until it is reviewed and validated.504. For .NET repositories, make the quality gate explicit:51 - formatting ownership52 - analyzer ownership53 - coverage and report generation54 - runner model (`VSTest` or `Microsoft.Testing.Platform`)555. Pull only the references that match the current delivery problem.5657## Deliver5859- CI/CD changes that are explicit, reproducible, and reviewable60- release documentation with rollback thinking61- pipeline rules aligned with MCAF verification6263## Validate6465- every stage has a clear purpose and failure signal66- rollback or safe failure is explicit67- secrets and permissions are minimized68- the pipeline matches the repo’s actual verification model6970## Ralph Loop7172Use the Ralph Loop for every task, including docs, architecture, testing, and tooling work.73741. Plan first (mandatory):75 - analyze current state76 - define target outcome, constraints, and risks77 - write a detailed execution plan78 - list final validation skills to run at the end, with order and reason792. Execute one planned step and produce a concrete delta.803. Review the result and capture findings with actionable next fixes.814. Apply fixes in small batches and rerun the relevant checks or review steps.825. Update the plan after each iteration.836. Repeat until outcomes are acceptable or only explicit exceptions remain.847. If a dependency is missing, bootstrap it or return `status: not_applicable` with explicit reason and fallback path.8586### Required Result Format8788- `status`: `complete` | `clean` | `improved` | `configured` | `not_applicable` | `blocked`89- `plan`: concise plan and current iteration step90- `actions_taken`: concrete changes made91- `validation_skills`: final skills run, or skipped with reasons92- `verification`: commands, checks, or review evidence summary93- `remaining`: top unresolved items or `none`9495For setup-only requests with no execution, return `status: configured` and exact next commands.9697## Load References9899- read `references/ci-cd.md` first100- for .NET quality gates, use `mcaf-dotnet-quality-ci`101102## Example Requests103104- "Design CI for this repo."105- "Tighten our deployment gates and rollback story."106- "Review this GitHub Actions YAML before we trust it."