All skills
bitwarden avatar

/force-multiplier

@71bbb4f official
by bitwardenbitwarden/ai-plugins155 stars
20

Apply one intent across many targets at once — a fleet of repositories across the Bitwarden ecosystem, or many projects inside a monorepo — as N consistent, idempotent, reviewable draft PRs.

Use this Skill: https://skilld.dev/gh/bitwarden/ai-plugins/force-multiplier

This session only. Nothing lands on disk.

examplesworkflow-edit.md

≈720 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Example — Retire a deprecated GitHub Actions workflow across the fleet

A worked campaign showing a deterministic recipe and the reference-check that a destructive change requires. Read it for shape, then generalize.

Recipe type: deterministic (remove a file). Signal type: file-existence (.github/workflows/<name>.yml present). Destructive: yes — so a reference-check pre-step runs before anything is removed.

Campaign spec

intent: "Remove the deprecated <name>.yml workflow from every repo that still has it."
scope: multi-repo
target_selector:
  enumerate: "gh repo list bitwarden --no-archived --limit 1000 --json name,defaultBranchRef"
  applicability_filter:
    signal: ".github/workflows/<name>.yml present"
    detect: "gh api repos/bitwarden/<repo>/contents/.github/workflows/<name>.yml --jq .sha"
recipe:
  type: deterministic
  body: "git rm .github/workflows/<name>.yml"
  idempotency: "the file is absent → already done, no-op"
validation: "repo lint of remaining workflows (e.g. actionlint if defined) + Skill(perform-preflight)"
pr_spec:
  branch: "force-multiplier/retire-<name>-workflow"
  title: "[PM-XXXXX] ci: Remove deprecated <name> workflow"
  body: "<filled from the repo's PULL_REQUEST_TEMPLATE.md>"
  labels: ["ai-review"]
  draft: true
safety_policy:
  max_targets_per_run: 10
  destructive: true
  dry_run: false
  pilot: required

How the pipeline plays out

  • SELECT — keep repos where the workflow file exists.
  • CHECK YOURSELF — destructive, so the reference-check pre-step is mandatory before any removal: across the selected repos, is <name> a required status check on the default branch, or is it referenced by another workflow via uses: / workflow_call? Removing a required check blocks every future merge on that repo; removing a called workflow breaks its caller. Any repo where the workflow is depended on is pulled out for a human decision — it does not get auto-removed.
  • PILOT — remove the file on one repo, show the one-line diff, run the remaining-workflow lint. Confirm nothing else changed. Lock the PR shape, confirm, fan out over the cleared subset.
  • FAN-OUT — per repo: branch, git rm the file, second-pass (the diff should be exactly one deleted file — anything more is a red flag), validate, secrets-scan, commit, draft PR.
  • REPORT — repo → applied / already-compliant / skipped-not-applicable / held-back / failed → PR URL, with the reference-check hold-outs recorded as held-back (and why) so the reconciliation selected = applied + already-compliant + skipped-not-applicable + held-back + failed closes. The held-back repos are not failures; they are decisions pending.
  • REMEDIATE — after the human resolves the held-back repos (e.g. the required-check setting is cleared first), re-run on just those.

Source: SKILL.md on GitHub

1 warning2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    The skill is highly secure, designed with security-by-default principles for bulk repository management. It features mandatory pilot runs, automated secret scanning, and explicit instructions to ignore prompt injection attempts within target codebases.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: MEDIUM · 1 issue

Signed by skilld at 71bbb4f. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last week
What it can do
Runs commands Reads files Edits files
argument-hint
<natural-language intent> [--scope multi-repo|monorepo] [--dry-run] [--no-pilot]
All 11 allowed tools
BashReadWriteEditGlobGrepAgentSkill(perform-preflight)Skill(committing-changes)Skill(applying-pr-conventions)Skill(labeling-changes)
Other metadata
when_to_use
Use when the user wants the same change made everywhere — phrasings like "across all repos", "every repo", "for every project", "fleet-wide", "org-wide", "enterprise-wide", "company-wide", "in bulk", "mass update", or "roll this out everywhere".

README badge

README badge for bitwarden/ai-plugins/force-multiplier