Generator
Skill pantheon-org/tekhne/skills/ci-cd/github-actions/generator
Generates production-ready GitHub Actions workflows, custom actions, and CI/CD configurations following security and performance standards. Creates CI/CD pipelines, test workflows, deployment configurations, matrix builds, caching strategies, composite actions, Docker actions, JavaScript actions, and reusable workflows. Use when creating or scaffolding GHA resources, writing .github/workflows YAML files, setting up build automation, implementing deployment pipelines, adding security scanning, or building reusable actions — including triggers like 'create a workflow', 'build a pipeline', 'add CI', 'set up GHA', or 'generate a YAML workflow'.From its SKILL.md
npx -y skills add pantheon-org/tekhne --skill generatorAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 9 stars9 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
10.1 KB, ~2.3k tokens by cl100k_base, as published. Nobody here has run it
GitHub Actions Generator
Generate production-ready GitHub Actions workflows and custom actions following current best practices, security standards, and naming conventions. All generated resources are automatically validated using the devops-skills:github-actions-validator skill.
Core Capabilities
1. Generate Workflows
Triggers: "Create a workflow for...", "Build a CI/CD pipeline..."
Process:
- Understand requirements (triggers, runners, dependencies)
- Reference
references/best-practices.mdfor patterns - Reference
references/common-actions.mdfor action versions - Generate workflow with:
- Semantic names, pinned actions (SHA), proper permissions
- Concurrency controls, caching, matrix strategies
- Validate with devops-skills:github-actions-validator skill
- Fix issues and re-validate if needed
Minimal Example:
name: CI Pipeline
on:
push:
branches: [main]
pull_request:
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
- uses: actions/setup-node@2028fbc5c25fe9cf00d9f06a71cc4710d4507903 # v6.0.0
with:
node-version: '20'
cache: 'npm'
- run: npm ci
- run: npm test
2. Generate Custom Actions
Triggers: "Create a composite action...", "Build a Docker action...", "Create a JavaScript action..."
Types:
- Composite: Combine multiple steps → Fast startup
- Docker: Custom environment/tools → Isolated
- JavaScript: API access, complex logic → Fastest
Process:
- Use templates from
assets/templates/action/ - Follow structure in
references/custom-actions.md - Include branding, inputs/outputs, documentation
- Validate with devops-skills:github-actions-validator skill
See references/custom-actions.md for:
- Action metadata and branding
- Directory structure patterns
- Versioning and release workflows
3. Generate Reusable Workflows
Triggers: "Create a reusable workflow...", "Make this workflow callable..."
Key Elements:
workflow_calltrigger with typed inputs- Explicit secrets (avoid
secrets: inherit) - Outputs mapped from job outputs
- Minimal permissions
on:
workflow_call:
inputs:
environment:
required: true
type: string
secrets:
deploy-token:
required: true
outputs:
result:
value: ${{ jobs.build.outputs.result }}
See references/advanced-triggers.md for complete patterns.
4. Generate Security Workflows
Triggers: "Add security scanning...", "Add dependency review...", "Generate SBOM..."
Components:
- Dependency Review:
actions/dependency-review-action@v4 - SBOM Attestations:
actions/attest-sbom@v2 - CodeQL Analysis:
github/codeql-action
Required Permissions:
permissions:
contents: read
security-events: write # For CodeQL
id-token: write # For attestations
attestations: write # For attestations
See references/best-practices.md section on security.
5. Modern Features
Triggers: "Add job summaries...", "Use environments...", "Run in container..."
See references/modern-features.md for:
- Job summaries (
$GITHUB_STEP_SUMMARY) - Deployment environments with approvals
- Container jobs with services
- Workflow annotations
6. Public Action Documentation
When using public actions:
-
Search for documentation:
"[owner/repo] [version] github action documentation" -
Or use Context7 MCP:
mcp__context7__resolve-library-idto find actionmcp__context7__get-library-docsfor documentation
-
Pin to SHA with version comment:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
See references/common-actions.md for pre-verified action versions.
Validation Workflow
CRITICAL: Every generated resource MUST be validated.
- Generate workflow/action file
- Invoke
devops-skills:github-actions-validatorskill - If errors: fix and re-validate
- If success: present with usage instructions
Skip validation only for:
- Partial code snippets
- Documentation examples
- User explicitly requests skip
Mandatory Standards
All generated resources must follow:
| Standard | Implementation |
|---|---|
| Security | Pin to SHA, minimal permissions, mask secrets |
| Performance | Caching, concurrency, shallow checkout |
| Naming | Descriptive names, lowercase-hyphen files |
| Error Handling | Timeouts, cleanup with if: always() |
See references/best-practices.md for complete guidelines.
Common Patterns
Matrix Testing
strategy:
matrix:
os: [ubuntu-latest, windows-latest]
node: [18, 20, 22]
fail-fast: false
Conditional Deployment
deploy:
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
Artifact Sharing
# Upload
- uses: actions/upload-artifact@v4
with:
name: build-${{ github.sha }}
path: dist/
# Download (in dependent job)
- uses: actions/download-artifact@v4
with:
name: build-${{ github.sha }}
Workflow Summary
- Understand requirements
- Reference appropriate docs
- Generate with standards
- Search for public action docs (if needed)
- Validate with devops-skills:github-actions-validator
- Fix any errors
- Present validated result
Anti-Patterns
NEVER use @latest or branch-based action references
- WHY: Mutable references allow the action to change silently between runs, enabling supply chain attacks where a compromised upstream injects malicious code into your workflow.
- BAD:
uses: actions/checkout@main - GOOD:
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
NEVER use secrets: inherit in reusable workflows without justification
- WHY:
secrets: inheritexposes every secret from the caller to the callee even when only one is needed, violating the principle of least privilege and widening the blast radius of a compromised workflow. - BAD:
secrets: inherit - GOOD: Declare only required secrets explicitly —
secrets: deploy-token: required: true
NEVER omit permissions: at the job or workflow level
- WHY:
GITHUB_TOKENdefaults to write permissions in older repositories. Omittingpermissions:means every job can push commits, create releases, or modify issues unintentionally. - BAD: A workflow with no
permissions:block at all. - GOOD: Set
permissions: contents: readas the workflow default and override per-job only where write access is genuinely required.
NEVER set fail-fast: false by default in matrix builds
- WHY:
fail-fast: falsecauses the entire matrix to keep running after the first failure, wasting runner minutes and delaying feedback. It should be an intentional choice, not a default. - BAD:
strategy: fail-fast: falseadded to every matrix without explanation. - GOOD: Omit
fail-fastto use the defaulttrue, or add an explicit comment explaining why all combinations must complete.
NEVER use pull_request_target with actions/checkout checking out PR code
- WHY:
pull_request_targetruns with write permissions and access to secrets. Combining it with a checkout of untrusted PR code enables attackers to exfiltrate secrets or tamper with your repository. - BAD:
on: pull_request_targetcombined withuses: actions/checkout@... with: ref: ${{ github.event.pull_request.head.sha }} - GOOD: Use
pull_requestfor untrusted code, or carefully scope and audit anypull_request_targetworkflow before adding a checkout step.
References
Reference Documents
| Document | Content | When to Use |
|---|---|---|
references/best-practices.md | Security, performance, patterns | Every workflow |
references/common-actions.md | Action versions, inputs, outputs | Public action usage |
references/expressions-and-contexts.md | ${{ }} syntax, contexts, functions | Complex conditionals |
references/advanced-triggers.md | workflow_run, dispatch, ChatOps | Workflow orchestration |
references/custom-actions.md | Metadata, structure, versioning | Custom action creation |
references/modern-features.md | Summaries, environments, containers | Enhanced workflows |
Templates
| Template | Location |
|---|---|
| Basic Workflow | assets/templates/workflow/basic_workflow.yml |
| Composite Action | assets/templates/action/composite/action.yml |
| Docker Action | assets/templates/action/docker/ |
| JavaScript Action | assets/templates/action/javascript/ |
| Capability | When to Use | Reference |
|---|---|---|
| Workflows | CI/CD, automation, testing | references/best-practices.md |
| Composite Actions | Reusable step combinations | references/custom-actions.md |
| Docker Actions | Custom environments/tools | references/custom-actions.md |
| JavaScript Actions | API interactions, complex logic | references/custom-actions.md |
| Reusable Workflows | Shared patterns across repos | references/advanced-triggers.md |
| Security Scanning | Dependency review, SBOM | references/best-practices.md |
| Modern Features | Summaries, environments | references/modern-features.md |
What ships with it: 35 files
237.2 KB alongside SKILL.md, 2 of them executable
assets/
- examples/actions/setup-node-cached/action.yml2.8 KB
- examples/caching/docker-buildkit.yml9.4 KB
- examples/README.md4.2 KB
- examples/security/dependency-review.yml1.6 KB
- examples/security/sbom-attestation.yml4.2 KB
- examples/triggers/chatops-commands.yml15.5 KB
- examples/triggers/repository-dispatch.yml13.3 KB
- examples/triggers/workflow-orchestration.yml11.8 KB
- examples/workflows/docker-build-push.yml2.0 KB
- examples/workflows/go-ci.yml4.3 KB
- examples/workflows/monorepo-ci.yml10.7 KB
- examples/workflows/multi-environment-deploy.yml13.3 KB
- examples/workflows/nodejs-ci.yml3.0 KB
- examples/workflows/python-ci.yml3.9 KB
- examples/workflows/scheduled-tasks.yml14.0 KB
- templates/action/composite/action.yml2.1 KB
- templates/action/docker/action.yml1.0 KB
- templates/action/docker/Dockerfile397 B
- templates/action/docker/entrypoint.shruns479 B
- templates/action/javascript/action.yml824 B
- templates/action/javascript/index.jsruns1.3 KB
- templates/action/javascript/package.json585 B
- templates/workflow/basic_workflow.yml5.7 KB
- templates/workflow/reusable_workflow.yml2.7 KB
evals/
- scenario-01.md3.3 KB
- scenario-02.md3.3 KB
- scenario-03.md3.8 KB
- scenario-04.md4.6 KB
- scenario-05.md3.5 KB
references/
- advanced-triggers.md22.5 KB
- best-practices.md16.2 KB
- common-actions.md17.1 KB
- custom-actions.md7.3 KB
- expressions-and-contexts.md15.9 KB
- modern-features.md10.7 KB