All skills
simota avatar

/pipe

@91d7239
by shingo imotasimota/agent-skills85 stars
15

Designing GitHub Actions workflows in depth: trigger strategy, security hardening, performance optimization, PR automation, and Reusable Workflow design.

Use this Skill: https://skilld.dev/gh/simota/agent-skills/pipe

This session only. Nothing lands on disk.

referenceautomation-recipes.md

≈684 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Automation Recipes

Purpose: Provide practical defaults for PR automation, branch protection, merge queue, environment protection, preview environments, and release workflow automation.

Contents

  • PR automation
  • Branch protection
  • Merge queue
  • Environment protection
  • Preview environments
  • Release automation

PR Automation

Pattern Use it for Notes
Auto-labeler routing reviews and ownership keep rules deterministic and repo-specific
PR size check fast review risk signal do not block docs-only or automation-only changes without intent
Auto-assign default reviewer routing pair with CODEOWNERS rather than replacing it
Stale bot long-idle issue or PR hygiene exempt active milestones and high-priority work
Auto-merge low-risk, fully gated changes require status checks and approval policy first

Branch Protection Defaults

Setting Recommended default
Require pull request enabled
Required approvals 1-2
Dismiss stale reviews enabled
Required status checks enabled and name-matched exactly
Require up-to-date branch enabled when merge health matters
Require conversation resolution enabled
Allow force push disabled
Allow branch deletion disabled

Use CODEOWNERS for .github/** and .github/workflows/**.

Merge Queue

Use merge queue when required checks are expensive and queue order matters.

Defaults from the reference set:

  • add merge_group to the workflow trigger
  • build concurrency: 5
  • minimum group size: 1
  • maximum group size: 5
  • status timeout: 60 min

Required checks must report on merge-group runs, not just PR runs.

Environment Protection

Control Range or rule
Required reviewers 1-6
Wait timer 0-43200 minutes
Branch restrictions allow only intended deploy branches
Self-review prevention enable when separation of duties matters
Custom rules add when org policy requires external approval logic

Secret precedence is: environment > repository > organization.

Preview Environments

  • Deploy preview environments from trusted automation only.
  • Clean them up automatically when the PR closes.
  • Keep preview secrets minimal and environment-scoped.
  • Never treat preview artifacts from untrusted PR code as release artifacts.

Release Automation

Recommended pattern:

  1. Build and verify on trusted code.
  2. Promote artifacts, do not rebuild untrusted PR outputs into release.
  3. Protect production environments with reviewers.
  4. Keep rollback or previous artifact promotion available via controlled manual dispatch.

Source: SKILL.md on GitHub

2 warnings5mo5 checks · Risk SAFE
  • Gen Agent Trust Hub5mo

    The skill 'Pipe' is a specialized instructional framework for GitHub Actions (GHA) workflow architecture. It focuses on security hardening, performance optimization, and automation best practices. It explicitly mandates high-security standards such as SHA pinning for third-party actions, OIDC for cloud authentication, and the principle of least privilege for permissions.

  • Socket5mo

    No alerts

  • Snyk5mo

    Risk: LOW · No issues

  • Runlayer6mo

    8/11 files flagged

  • ZeroLeaks5mo

    1 finding · Score: 69/100

Signed by skilld at 91d7239. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 months ago

README badge

README badge for simota/agent-skills/pipe