More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    ci cd Pipeline Validator

    3

    A junior dev pushes a workflow file with `uses: some-org/deploy-action@main` and `secrets.GITHUB_TOKEN` exposed.

    Free

    21 installsSecurity scanned
    ci-cd-pipeline-validator

    ci-cd-pipeline-validator

    Example session with this skill installed

    "Audit .github/workflows/deploy.yml for security and best practices"

    • Read your context and instructions
    • Compiled the ci-cd-pipeline-validator
    • Generated the document

    CI/CD PIPELINE AUDIT REPORT
    ═══════════════════════════

    Platform: GitHub Actions
    File: .github/workflows/deploy.yml

    Category Check Status Detail

    ─ ───────────── ────────────────────── ────── ─────────────────────────────────
    1 Security No hardcoded secrets PASS -
    2 Security Action versions pinned FAIL some-org/deploy@main → pin to SHA
    3 Security Script injection safe FAIL ${{ CI_ACCESS_TOKEN }} in run:
    4 Performance Cache configured WARN No dependency caching
    5 Best Practice Concurrency group WARN Parallel deploys can race
    6 Best Practice Timeout set WARN No timeout-minutes

    Top 3 fixes:

    1. [FAIL] Replace ${{ CI_ACCESS_TOKEN }} with env variable reference
    2. [FAIL] Pin deploy-action to commit SHA
    3. [WARN] Add concurrency group with cancel-in-progress

    ci-cd-pipeline-validator.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    About this skill

    The Problem

    A junior dev pushes a workflow file with uses: some-org/deploy-action@main and secrets.GITHUB_TOKEN exposed. The PR merges. Now any fork can read your deploy secrets. You don't find out until a crypto-miner spins up on your runner. Or worse: the pipeline works for three months, then ubuntu-latest migrates from 22.04 to 24.04, and every build breaks on a Wednesday morning with no one knowing why.

    What You Get

    • Auto-detect the CI platform from file content — GitHub Actions, GitLab CI, CircleCI, or Jenkins — and apply platform-specific validation rules without manual selection
    • Scan for critical security anti-patterns — unpinned action references (@main/@master), script injection via ${{ github.event.* }}, pull_request_target misuse, hardcoded secrets, and overly permissive permissions: write-all
    • Validate YAML correctness before content — catch silent gotchas like unquoted version: 3.10 parsing as float 3.1, on: push vs on: [push] boolean parsing, and block scalar | vs > behavior differences
    • Optimize pipeline performance with dependency caching patterns (actions/cache@v4 with hashFiles keys), matrix build parallelism, and concurrency groups that prevent deploy pile-ups
    • Produce a prioritized audit report with PASS/WARN/FAIL status per check, a fix list ordered by exploitability, and before/after code snippets for every finding
    • Verify fixes don't break semantics — re-run the checklist post-fix, confirm no permissions were over-tightened, and validate the YAML still parses cleanly

    Why This Beats Prompting It Yourself

    Telling an agent "check my workflow file" produces surface-level feedback: "add caching" or "pin your actions." This skill runs a structured 5-category checklist (Syntax → Security → Performance → Best Practices → Platform-Specific) with exact pattern matching. It catches the compound vulnerabilities — like pull_request_target + checkout of PR head + secrets available — that a casual review misses entirely.

    Example Session

    You: "Audit .github/workflows/deploy.yml for security and best practices"

    Agent:

    CI/CD PIPELINE AUDIT REPORT
    ═══════════════════════════
    
    Platform: GitHub Actions
    File: .github/workflows/deploy.yml
    
    #  Category       Check                   Status  Detail
    ─  ─────────────  ──────────────────────  ──────  ─────────────────────────────────
    1  Security       No hardcoded secrets    PASS    -
    2  Security       Action versions pinned  FAIL    some-org/deploy@main → pin to SHA
    3  Security       Script injection safe   FAIL    ${{ CI_ACCESS_TOKEN }} in run:
    4  Performance    Cache configured        WARN    No dependency caching
    5  Best Practice  Concurrency group       WARN    Parallel deploys can race
    6  Best Practice  Timeout set             WARN    No timeout-minutes
    
    Top 3 fixes:
    1. [FAIL] Replace ${{ CI_ACCESS_TOKEN }} with env variable reference
    2. [FAIL] Pin deploy-action to commit SHA
    3. [WARN] Add concurrency group with cancel-in-progress
    

    Use Cases

    • Pre-merge review of PRs that modify CI/CD pipeline configurations
    • Security audit of workflows before enabling pull_request_target triggers
    • Migration checklist when moving from ubuntu-20.04 to ubuntu-24.04 runner images
    • Initial pipeline setup for new projects to avoid the 10 most common pitfalls
    • Post-incident review after a pipeline vulnerability is discovered
    • Standardizing CI/CD conventions across a team of 10+ repositories

    Known Limitations

    The validator is static — it cannot detect runtime failures (flaky tests, network-dependent steps, secret rotation needs). YAML syntax checking catches structural errors but not semantic issues like incorrect environment variable names. Multi-file pipeline configs (reusable workflows, includes, orbs) require scanning sibling files, not just the file the user pointed at.

    Upgrade to Pro

    Free flags unpinned actions, secret leaks, and YAML gotchas in a single workflow file. CI/CD Pipeline Validator Pro ($5) auto-fixes common findings with review-ready patches, estimates wasted CI spend in dollars, tracks pipeline maturity across 5 dimensions, and adds pre-commit hooks plus Azure DevOps support — the Pro version is currently under review and will be linked here once approved.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    21 installs

    Downloaded by developers to date

    Free forever

    No account required to browse

    Trust & safety

    Security scanned

    Verified clean 4 months ago

    • Free to download with an account

    Listed4 months ago
    Updated9 days ago

    What's inside

    Frequently Asked Questions