All skills
bitwarden avatar

/workflow-audit

@4ac996f official
by bitwardenbitwarden/ai-plugins155 stars
20

Run the Bitwarden workflow linter (bwwl) against one or more repos and report findings. Strictly read-only — does not modify any files. Categorizes findings as mechanical or judgment using the bitwarden-workflow-linter-rules skill. Supports single repo, multiple repos, or single file/directory scope. <example> User: Run the workflow linter on the server repo Action: Trigger workflow-audit for that repo </example> <example> User: Lint the workflows across server, clients, and android Action: Trigger workflow-audit in multi-repo mode </example>

Use this Skill: https://skilld.dev/gh/bitwarden/ai-plugins/workflow-audit

This session only. Nothing lands on disk.

SKILL.md

≈142 tokens always: the name and description. ≈528 when used: this file.

Rules

  • This skill is strictly read-only. Do not modify, create, or delete any files.
  • Flag uncertainty. If a finding is ambiguous, note it in the report rather than guessing.

Step 1: Verify Prerequisites

Check if bwwl is available:

bwwl --version

If the command is not found, stop and inform the user that bwwl must be installed before continuing. Do not attempt to install it.

Step 2: Determine Scope

Parse the user's request to determine what to lint:

  • Single file or directory (e.g., .github/workflows/build.yml or .github/workflows/): Operate on the current repo only.
  • Multiple repos (e.g., "server, clients, android"): Operate on each repo sequentially. Ask the user for the base directory where their repos are cloned. For each repo, look for its local clone at <base-dir>/<repo>. If a clone is not found, inform the user and skip that repo.
  • No specific target: Lint all files in .github/workflows/ of the current directory.

Step 3: Run the Linter

For each repo in scope, run:

bwwl lint -f .github/workflows/

Capture both stdout and stderr. If operating on multiple repos, announce which repo is being linted.

Step 4: Parse and Categorize Findings

From the linter output, produce a structured list of findings. Group by file and rule. Consult the bitwarden-workflow-linter-rules skill to categorize each finding:

Mechanical (can be auto-fixed):

  • name_capitalized, permissions_exist, pinned_job_runner, step_pinned, underscore_outputs, job_environment_prefix, check_pr_target
  • Simple run_actionlint findings (single-line shell fixes)

Judgment (requires user input):

  • name_exists, step_approved, complex run_actionlint findings

Step 5: Report

Output a summary table per repo:

File Finding Rule Category
... ... ... ...

Include totals: mechanical findings, judgment findings, and repos with no issues.

Inform the user that they can use the workflow-fix skill to apply fixes based on these findings.

Source: SKILL.md on GitHub

No alerts14d3 checks · Risk SAFE
  • Gen Agent Trust Hub14d

    The skill is a read-only audit tool designed to lint GitHub workflows using the Bitwarden-specific 'bwwl' command-line tool. It follows security best practices by explicitly forbidding automatic installation of dependencies and restricting command execution to the specific linter tool via platform-level configuration.

  • Socket14d

    No alerts

  • Snyk14d

    Risk: LOW · No issues

Signed by skilld at 4ac996f. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated 6 months ago
What it can do
Reads files Runs commands
All 5 allowed tools
ReadGlobGrepSkillBash(bwwl:*)
  • bitwarden
  • workflow
  • linting
  • ci-cd
  • github-actions
  • read-only
  • audit

README badge

README badge for bitwarden/ai-plugins/workflow-audit

Runs the Bitwarden workflow linter (bwwl) against GitHub Actions workflows in one or more repos and categorizes findings as mechanical (auto-fixable) or judgment (requiring review). Read-only; integrates with the bitwarden-workflow-linter-rules skill to classify violations.

Generated from the current SKILL.md.

Does this skill modify any files?
No. The skill is strictly read-only and only reports findings from the Bitwarden workflow linter (bwwl). It does not create, modify, or delete any files.
What is bwwl and how do I install it?
bwwl is the Bitwarden workflow linter. The skill requires it to be pre-installed and will stop with an error message if the command is not found. Installation is not handled by the skill itself.
Can this skill lint multiple repos at once?
Yes. The skill supports single repo, multiple repos, or a single file/directory scope. For multiple repos, you must provide the base directory where they are cloned.
What does the skill do with the linter findings?
It parses and categorizes findings as either mechanical (auto-fixable, like capitalization or pinned runner issues) or judgment (requiring user input, like approval checks). Results are displayed in a summary table per repo.

Generated from the current SKILL.md. These answers refresh after source changes.