All skills
github avatar

/github-actions-efficiency

@12666c9 official
by githubgithub/awesome-copilot40k stars
5,040

Audit GitHub Actions workflow efficiency and recommend fixes to reduce CI minutes and costs.

Use this Skill: https://skilld.dev/gh/github/awesome-copilot/github-actions-efficiency

This session only. Nothing lands on disk.

referencesactions.md

≈801 tokens on demand. Your agent reads this file only when SKILL.md points to it.

GitHub Actions Efficiency

Load this reference only when the task involves GitHub Actions or CI workflow efficiency.

If the repo is onboarding GitHub Actions for the first time, define a minimal baseline workflow first, then optimize using the rest of this guide.

Audit Order

Inspect in this order:

  1. If .github/workflows/ is missing or empty, gather baseline requirements first: triggering events, required checks, runtime versions, and repository-specific validation policy.
  2. .github/workflows/*.yml
  3. Docs describing CI expectations
  4. Existing reports or run history if the user wants measured impact

For new setups, start with a small workflow that proves core checks, then add matrix breadth or additional jobs only when needed.

Start with common, low-risk waste:

  1. Missing dependency caches
  2. Missing concurrency cancellation
  3. Over-broad workflow triggers
  4. Duplicate workflow coverage across files or jobs
  5. Expensive jobs that run on every change regardless of scope

Actions-Specific Guidance

Trigger scoping

  • Use paths or paths-ignore when whole workflows truly should not run for some file classes.
  • Use job-level gating when event-level filters are too coarse.
  • Prefer explicit changed-file detection when reliability matters more than clever filter expressions.

Job shaping

  • Do not merge jobs blindly. If separate jobs preserve parallelism and shorten the critical path, keep them separate.
  • Keep lightweight coordination or change-detection jobs separate from heavy execution jobs when that makes skip behavior obvious.
  • If a workflow-only change still runs the full suite, treat that as evidence the gating model is too broad.

Matrix reduction

Match matrix breadth to the decision being made:

  • Full matrix for releases or explicit compatibility validation
  • Reduced compatibility matrix for runtime, plugin, packaging, or framework-integration changes
  • Single representative latest-version leg for ordinary code changes
  • No heavy test job for clearly non-runtime changes when lighter protection already exists

Optional maintenance jobs

Formatting or autofix jobs that write back to a branch are often better as opt-in jobs.

Good triggers:

  • PR label such as ci:format
  • Manual dispatch
  • Explicit comment-command flow if the repo already supports it

If you use a label trigger, remember to listen for PR labeled and usually unlabeled events or the label change will not reevaluate the job.

Safe-Change Rules

  • Do not hide required release, migration, or shared-library validation.
  • Do not widen changed-file scope accidentally when replacing a wrapper action.
  • Treat severity drift as a regression risk.
  • Match the real check surface before replacing a broad action with native tools.

Live Validation

Prefer live GitHub validation when possible:

  • Trigger workflow_dispatch workflows once
  • Verify stale-run cancellation with two quick updates
  • Verify path-gating with an incremental ignored-only or workflow-only change on an existing branch
  • Confirm heavy jobs skip in the UI instead of assuming they would

Do not treat the first push on a brand-new branch as a clean path-ignore test.

Source: SKILL.md on GitHub

No alerts3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    This skill provides a framework for auditing and optimizing GitHub Actions workflows. It identifies inefficiencies by analyzing repository configuration and execution logs using standard tools like ripgrep and the GitHub CLI. No malicious patterns or significant security risks were detected.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: LOW · No issues

Signed by skilld at 12666c9. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated 4 months ago
  • Performance
  • github-actions
  • ci
  • workflow
  • caching
  • concurrency
  • cost-optimization
  • yaml

README badge

README badge for github/awesome-copilot/github-actions-efficiency

Audits GitHub Actions workflows to identify and fix waste—missing caches, over-broad triggers, duplicate job coverage, and inefficient matrix strategies. Ranks fixes by estimated CI minutes saved and validates changes against guardrails that preserve required validation and critical-path latency.

Generated from the current SKILL.md.

What does this skill actually audit?
GitHub Actions workflows in `.github/workflows/` for waste sources like missing dependency caches, absent concurrency cancellation, over-broad triggers, duplicate job coverage, and expensive jobs running on every change.
Can I use this without shell or gh CLI access?
Yes. Ask the user to paste `.github/workflows/` contents and `gh run list --limit 10` output, then perform a static-only analysis based on provided files.
Does this skill recommend fixes that might break required checks?
No. The skill explicitly drops any fix that hides release, schema, migration, or shared-library validation, and flags (rather than removes) write-back jobs that run automatically.
How many fixes does this skill recommend?
Up to 3, selected from six candidate categories and ranked by estimated daily CI minutes saved. All candidates that meet audit evidence and guardrail criteria are included, up to the maximum of 3.
Can this skill validate fixes against live runs?
Yes, if gh CLI access is available. It will test path-gating and concurrency cancellation with a push on a non-protected branch; otherwise it states that live validation is not possible.

Generated from the current SKILL.md. These answers refresh after source changes.