Create production-ready GitHub Actions workflows for automated testing, building, and deploying applications. Use when setting up CI/CD with GitHub Actions, automating development workflows, or creating reusable workflow templates.
87
82%
Does it follow best practices?
Impact
93%
1.02xAverage score across 3 eval scenarios
Passed
No known issues
Node.js matrix CI testing
Pinned action versions
100%
100%
checkout@v4
100%
100%
setup-node@v4
100%
100%
npm cache enabled
100%
100%
npm ci used
100%
100%
Matrix node versions
100%
100%
PR trigger included
100%
100%
Push trigger included
66%
100%
Codecov action used
100%
100%
Codecov lcov file path
100%
100%
Linter step present
100%
100%
Test step present
100%
100%
Docker build and push workflow
Pinned action versions
100%
100%
ghcr.io registry
100%
100%
github.repository image name
100%
100%
docker/login-action@v3
100%
100%
github.actor username
100%
100%
GITHUB_TOKEN password
100%
100%
docker/metadata-action@v5
100%
100%
Semver tag patterns
100%
100%
docker/build-push-action@v5
0%
100%
GHA build cache
100%
100%
Minimal permissions
100%
100%
Tag trigger
100%
100%
Main branch trigger
100%
100%
Security scanning and production deployment
Pinned action versions
100%
100%
Trivy action used
100%
100%
Trivy filesystem scan
100%
100%
Trivy SARIF output
100%
100%
Upload SARIF to GitHub Security
100%
70%
Snyk action used
0%
0%
SNYK_TOKEN secret
0%
0%
Production environment gate
100%
100%
Tag-based trigger
100%
100%
Slack notification step
100%
100%
SLACK_WEBHOOK secret
100%
100%
Notification conditional
100%
100%
91fe43e
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.