All skills
akin-ozer avatar

/github-actions-validator

@1b2342a

Validate, lint, audit, fix GitHub Actions workflows (.github/workflows).

Use this Skill: https://skilld.dev/gh/akin-ozer/cc-devops-skills/github-actions-validator

This session only. Nothing lands on disk.

examplesREADME.md

≈556 tokens on demand. Your agent reads this file only when SKILL.md points to it.

GitHub Actions Validator - Example Workflows

This directory contains example workflow files for testing the GitHub Actions Validator skill.

Files

valid-ci.yml

A complete, valid CI pipeline that passes all validation checks.

Purpose: Test successful validation flow

Usage:

bash scripts/validate_workflow.sh examples/valid-ci.yml

Expected Result: All validations pass


with-errors.yml

A workflow containing common intentional errors for testing error detection.

Purpose: Test error detection and reference file consultation

Errors included (4 total, all caught by actionlint):

  1. Invalid CRON expression (day 8 doesn't exist) — [events]
  2. Typo in runner label (ubuntu-lastest instead of ubuntu-latest) — [runner-label]
  3. Script injection vulnerability (untrusted input in script) — [expression]
  4. Undefined job dependency (biuld instead of build) — [job-needs]

Usage:

bash scripts/validate_workflow.sh examples/with-errors.yml

Expected Result: Multiple errors reported by actionlint


outdated-versions.yml

A workflow using older action versions to test version validation.

Purpose: Test action version checking

Version issues included:

  1. actions/checkout@v4 - OUTDATED (current: v6)
  2. actions/setup-node@v4 - OUTDATED (current: v6)
  3. actions/upload-artifact@v3 - DEPRECATED (minimum: v4)
  4. docker/build-push-action@v5 - OUTDATED (current: v6)

Usage:

bash scripts/validate_workflow.sh --check-versions examples/outdated-versions.yml

Expected Result: Version warnings for outdated actions


Testing Workflow

  1. Test successful validation:

    bash scripts/validate_workflow.sh examples/valid-ci.yml
  2. Test error detection:

    bash scripts/validate_workflow.sh examples/with-errors.yml
  3. Test version checking:

    bash scripts/validate_workflow.sh --check-versions examples/outdated-versions.yml
  4. Test all examples:

    for file in examples/*.yml; do
      echo "=== Testing: $file ==="
      bash scripts/validate_workflow.sh --lint-only "$file"
      echo ""
    done

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk HIGH
  • Gen Agent Trust Hub16d

    The skill is designed to validate GitHub Actions workflows using actionlint and act. It includes a setup script that downloads and executes remote installation scripts directly via bash piping and process substitution. While these downloads are intended to fetch the official linting and local testing utilities, running unverified remote scripts poses a supply chain risk.

  • Socket16d

    3 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 1b2342a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 7 months ago

README badge

README badge for akin-ozer/cc-devops-skills/github-actions-validator