vigilante-issue-implementation-on-github-actions

Prüfen · 64
Im Registry indexiert

Implement a GitHub issue end-to-end when Vigilante dispatches work for a repository with GitHub Actions workflows, applying workflow hardening, pinned actions, and secret-safe automation practices.

Verified installs0
Stars37
Version1.0.0
Qualität62/100 · Vielversprechend
Vertrauen64/100 · Nur Sandbox
Audit76/100 · Prüfung nötig

Asset-Profil

Coding- und Entwickler-Agents

Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.

Bereich ansehen

Szenario

GitHub automation

I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.

Agent-Fit

Claude Code + OpenAI Agents + CLI

Geeignet für Codex, Claude Code, Cursor, CLI oder benutzerdefinierte Agents.

Installieren

Bereit

npx skills add aliengiraffe/vigilante --skill vigilante-issue-implementation-on-github-actions

Wartung

Aktuell

3 Tage seit dem letzten Push

Risiko

Prüfung nötig

Dependency or permission surface needs review

GitHub-Qualität

37

62/100 Qualität · 72/100 Vertrauen

Abdeckungs-Tags

CodingGitHub automationSicherheitagent-skill

Review-Notizen

Dependency or permission surface needs review · Permission surface may require sandboxing

Agent-Adoptionskarte

Vertrauen, Audit und Installationsbereitschaft auf einen Blick

Diese Werte kombinieren öffentliche Repository-Metadaten, OpenAgentSkill-Reviewsignale, Wartungsaktualität und Installationsbereitschaft. Sie helfen bei der Vorauswahl, ersetzen aber keine menschliche Prüfung.

Qualität

Vielversprechend
62

Useful candidate, but compare it with alternatives before adopting.

Vertrauen

Nur Sandbox
64

Nützlicher Kandidat mit fehlenden oder gemischten Vertrauenssignalen. Bis der Ergebniszyklus die Passung belegt, in einem isolierten Arbeitsbereich verwenden.

Audit

Prüfung nötig
76

Maschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.

OpenAgentSkill Trust Score v5

Menschliche Prüfung vor Installation

Nur in einer Sandbox ausführen und nahe Alternativen vergleichen, bevor sie produktiv eingesetzt wird.

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

37 GitHub-Stars

Repository-Aktivität

37 Stars und 6 Forks

Wartung

3 Tage seit dem letzten Push

Lizenz

Apache-2.0

Installieren

npx skills add aliengiraffe/vigilante --skill vigilante-issue-implementation-on-github-actions

Installationssicherheit

Standard-Paket- oder Laufzeit-Installationspfad

Berechtigungsfläche

secrets or environment access, shell or command execution

Agent-Ergebnisse

Noch keine Agent-Ergebnisdaten

Dokumentation

Starker README/SKILL.md-Kontext

Risikoübersicht

Vor Produktion prüfen

  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • GitHub adoption: 37 GitHub stars

Installationsbereitschaft

Installationspfad verfügbar

  • Installationspfad ist verfügbar
  • Repository-Belege sind verfügbar
  • Lizenz ist angegeben
  • Noch keine Agent-Proven-Ergebnisbelege

Agent-lesbare Metadaten

Maschinenlesbare Entscheidungsdaten für diesen Skill.

Nutze diesen Block oder das eingebettete JSON, um zu entscheiden, ob ein Agent diesen Skill installieren, eine Alternative wählen oder zuerst menschliche Prüfung anfordern soll.

JSON öffnen

Geeignete Aufgaben

  • GitHub automation-Workflows
  • Claude-Code-Teams
  • builders willing to evaluate younger projects
  • Inspect repository metadata

Geeignete Agents

CodexClaude CodeCursorOpenAgentSkill CLIOpenAI AgentsCLI

Installationsentscheidung

Befehl
npx skills add aliengiraffe/vigilante --skill vigilante-issue-implementation-on-github-actions
Richtlinie
Blockieren
Menschliche Prüfung
Ja

Vertrauen und Risiko

Vertrauen
64/100
Audit
76/100
Risikoebene
Prüfung nötig

Ergebnis-Loop

Endpoint
/api/agent/outcome
Event-ID
resolve
Ergebnisse
5

Installationsbefehl

npx skills add aliengiraffe/vigilante --skill vigilante-issue-implementation-on-github-actions

Nicht verwenden, wenn

  • Teams, die ein vom Anbieter unterstütztes SLA benötigen
  • production agents without a repository review
  • Low GitHub adoption signal
  • No OpenAgentSkill engagement data yet
  • Hinweise auf Hochrisiko-Berechtigungen: Shell or command execution, Secrets or environment access

Agent-Sicherheit v2

36/100 · Automatische Installation vermeiden

Blocked for auto-installBlockieren

This skill should not be selected by an agent without explicit human security review.

Do not auto-install. Inspect the source, dependencies, and permission surface first.

Per API auflösen

Hoch

Shell- oder Befehlsausführung

Die Skill-Metadaten verweisen auf Terminal-, CLI-, Shell-, Subprozess- oder Befehlsausführungs-Workflows.

Mittel

Netzwerkzugriff

Die Skill ruft wahrscheinlich Remote-Seiten, APIs, Repositories oder externe Dienste ab.

Mittel

Dateisystemzugriff

Die Skill kann Projektdateien, Dokumente, generierte Artefakte oder den lokalen Arbeitsbereich lesen oder schreiben.

Hoch

Secrets or environment access

Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.

  • Hinweise auf Hochrisiko-Berechtigungen: Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

Installationsziele

Diesen Skill im Agent-Workflow installieren

Über den öffentlichen Endpunkt erhältst du Befehl, Sicherheitscheckliste, Ziel-Prompts und kanonische Links.

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install aliengiraffe-vigilante-issue-implementation-on-github-actions

Agent-Auflösungsplan

Lass einen Agent die Eignung vor der Installation prüfen.

Die Resolve API liefert die beste Skill, Alternativen, Sicherheitsrichtlinien, Auditnotizen, Installationsziel und einen direkt nutzbaren Prompt.

Textplan öffnen

Agent sollte prüfen

  • Task fit and alternatives from Resolve API.
  • Audit score, trust score, and safety policy warnings.
  • Install target compatibility for Codex, Claude Code, Cursor, or CLI.

Prompt kopieren

Task: Use vigilante-issue-implementation-on-github-actions in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20vigilante-issue-implementation-on-github-actions%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions/install
Install command: npx skills add aliengiraffe/vigilante --skill vigilante-issue-implementation-on-github-actions
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent-Übergabe

Gib dem Agent den Installationspfad, nicht noch ein Verzeichnis.

Über den öffentlichen Endpunkt erhältst du Befehl, Sicherheitscheckliste, Ziel-Prompts und kanonische Links.

Installations-API öffnen

Agent-Prompt

Use vigilante-issue-implementation-on-github-actions for this task. Review https://www.openagentskill.com/api/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions/install, then install with: npx skills add aliengiraffe/vigilante --skill vigilante-issue-implementation-on-github-actions

Registry-Metadaten

Agent-lesbares Profil für die automatische Skill-Auswahl.

Die Registry API stellt Entscheidungs-, Vertrauens-, Audit-, Use-Case- und Installationssignale ohne UI-Scraping bereit.

Manifest öffnen

Agent-Fit

61/100

GitHub automation

Plattformen

Claude Code, OpenAI Agents

Audit-Bericht

Prüfung nötig · 76/100

Maschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.

Audit-Bericht ansehenEval-Bericht ansehen

Agent-Entscheidungspanel

Fallback candidate for GitHub automation

Prototype with this skill first; keep a fallback candidate ready.

61
Bereitschaft
Prototyp
Phase

Rolle im Stack

Fallback-Kandidat

Primäre Eignung

GitHub automation

Vertrauenslabel

Zuerst prototypisieren

Installationspfad

Befehl bereit

Verwenden wenn

  • GitHub automation-Workflows
  • Claude-Code-Teams
  • builders willing to evaluate younger projects

Evidenz

  • recent repository activity
  • install command or GitHub repo available
  • Qualitätsprofil 62/100

zuerst prüfen

  • Low GitHub adoption signal
  • No OpenAgentSkill engagement data yet

Implementierungspfad

  1. 1Installieren Sie es in einem Sandbox-Agent und führen Sie eine GitHub automation-Aufgabe vollständig aus.
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

Vertrauensprofil

Nur Sandbox

Nützlicher Kandidat mit fehlenden oder gemischten Vertrauenssignalen. Bis der Ergebniszyklus die Passung belegt, in einem isolierten Arbeitsbereich verwenden.

64
OpenAgentSkill Trust Score

GitHub-Akzeptanz

Prüfen

37 GitHub-Stars

Star-/Fork-Aktivität

Prüfen

37 Stars und 6 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbar

Aktuelle Wartung

Bestanden

3 Tage seit dem letzten Push

Lizenzklarheit

Bestanden

Apache-2.0

Positive Signale

  • KI-Prüfung genehmigt
  • Installationspfad ist verfügbar
  • Repository-Belege sind verfügbar
  • Kürzlich gewartetes Repository
  • Der Installationsbefehl weist kein offensichtliches Hochrisikomuster auf
  • Ergebniszyklus ist bereit, benötigt aber den ersten echten Agent-Lauf

Vor Installation prüfen

  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • GitHub adoption: 37 GitHub stars
  • Stars/forks activity: 37 stars, 6 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution
  • Noch keine echten Agent-Ergebnisberichte
  • Vor unbeaufsichtigter Installation ist menschliche Prüfung erforderlich

Empfohlene Aktion

Nur in einer Sandbox ausführen und nahe Alternativen vergleichen, bevor sie produktiv eingesetzt wird.

Qualitätsprofil

Vielversprechend Kandidat für Agent-Workflows

Useful candidate, but compare it with alternatives before adopting.

62
GitHub-Stars
37
Aktualität
vor 3 Tagen
Installationsbereit
Ja
Lizenz
Apache-2.0
Vor Installation prüfen: Low GitHub adoption signal

Workflow-Eignung

Diese Skill in diesen Szenarien nutzen

Workflow-Eignung

Zum vollständigen Workflow hinzufügen

Alternativen-Shortlist

Vor Installation vergleichen

Similar skills that may fit this task.

Alle vergleichen

Übersicht

--- name: vigilante-issue-implementation-on-github-actions description: Implement a GitHub issue end-to-end when Vigilante dispatches work for a repository with GitHub Actions workflows, applying workflow hardening, pinned actions, and secret-safe automation practices. ---

# Vigilante GitHub Actions Issue Implementation

## Focus - Read the prompt for detected tech stacks, process hints, and security guidance before changing workflow files. - Keep changes scoped to the issue and do not broaden into unrelated workflow or repository changes. - Treat `.github/workflows/` as a security-sensitive surface. Every workflow edit should consider permissions, secret exposure, and supply-chain risk.

## Workflow File Conventions - Use `.yml` or `.yaml` consistently with the repository's existing convention. Do not mix extensions within the same repository. - Validate workflow syntax before committing. Use `actionlint` when it is available in the repository or installed locally. If `actionlint` is not available, note its absence and continue — do not fabricate output. - Keep workflow files readable: use clear job and step names, add inline comments for non-obvious logic, and prefer reusable workflows or composite actions over duplicated step blocks.

## Pinned Actions - Pin third-party actions to full commit SHAs, not mutable tags or branch references. Example: `uses: actions/checkout@<full-sha>` with a trailing version comment. - When updating an action version, verify the new SHA corresponds to a reviewed release or tag. - First-party GitHub actions (`actions/*`) should also be pinned to SHAs for consistency and supply-chain safety. - When adding a new third-party action, prefer well-maintained actions with high community adoption. Avoid actions that request broad permissions or lack clear provenance.

## Least-Privilege Permissions - Always declare a top-level `permissions:` block in workflow files. Default to the most restrictive set needed. - Use read-only `contents: read` unless the workflow must write (e.g., creating releases, pushing tags, commenting on PRs). - Scope token permissions per job when different jobs need different access levels. - Never use `permissions: write-all` or leave permissions unspecified, which defaults to broad access in some repository configurations.

## Secret and Credential Safety - Never echo, log, or interpolate secrets directly in `run:` shell commands. Pass secrets through environment variables. - Use `::add-mask::` to mask dynamic values that may appear in logs. - Prefer OIDC-based authentication (e.g., `aws-actions/configure-aws-credentials` with `role-to-assume`) over long-lived cloud credentials stored as repository secrets. - Do not store secrets, tokens, or credentials in workflow files or committed configuration. - When a workflow needs elevated access, document why in a comment and scope the access as narrowly as possible.

## Safe Workflow Authoring - Never interpolate untrusted event data (such as `${{ github.event.pull_request.title }}` or `${{ github.event.issue.body }}`) directly into `run:` shell scripts. Use an intermediate environment variable to prevent script injection. - Prefer `pull_request` over `pull_request_target` unless cross-fork access is explicitly required and the workflow is hardened against injection. - Use `concurrency` groups to prevent redundant or conflicting workflow runs. - Set appropriate `timeout-minutes` on jobs to prevent hung runners from consuming resources.

## Reusable Workflows and Composite Actions - Prefer the repository's existing reusable workflows and composite actions over duplicating logic. - When creating new reusable workflows, define clear `inputs` and `secrets` contracts. - Respect the repository's branch-protection rules and required status checks when adding or modifying workflows.

## Mixed-Stack Repositories - A repository with GitHub Actions workflows often also contains application code in Go, Node.js, Python, or other languages. - Scope workflow-specific guidance to `.github/workflows/` and related CI/CD configuration only. Do not apply workflow linting or hardening rules to application source code. - When an issue touches both workflow files and application code, validate each side with its appropriate toolchain. - Check the prompt for additional detected tech stacks and follow their respective guidance for non-workflow changes.

## Workflow - Follow the base `vigilante-issue-implementation` workflow for issue comments, validation, push, and PR creation, including stacked base-branch detection (`Base branch:` directive in the issue body). - Use `vigilante commit` for all commit-producing operations. Do not use `git commit` or GitHub CLI commit flows directly. - Any commit or amend must preserve the user's existing git author, committer, and signing configuration. Commit on behalf of the user and do not overwrite `git config` with a coding-agent identity. - Do not add `Co-authored by:` trailers or any other agent attribution for Codex, Claude, Gemini, or similar coding-agent identities. - Repository-specific instructions (`AGENTS.md`, `README.md`, CI config) remain authoritative when they are more specific than the generic GitHub Actions guidance in this skill.

Technische Details

Version
1.0.0
Lizenz
Apache-2.0
Letzte Aktualisierung
19. Aug. 2026
Veröffentlicht
19. Aug. 2026

Entscheidungsübersicht

Fallback-Kandidat

61
Bereit
Prototyp
Phase

recent repository activity

Audit

Installationsprüfung

Installations- und Adoptionsprüfung

76
Prüfung nötig
Sicherheit
77/100
Wartung
100/100
Installieren
92/100
Vollständiges Audit öffnenEval-Bericht ansehen

Von Agent belegte Evidenz

Von Agent belegte Evidenz

Ergebnisberichte nach Resolve, Prüfung, Installation und einem begrenzten Lauf.

0
Belegt
Needs first agent runAuto-Installation: zuerst prüfenLetzter: Unbekannt
Erfolgsrate
Letzter Fehler
Ergebnisse
0
Ausgabequalität
Fehlgeschlagen
0
Nicht relevant
0
Installationen
0
Durch Risiko blockiert
0
Einrichtung erforderlich
0
Produktion
0

Noch keine Agent-Ergebnisdaten. Der erste Lauf kann Erfolg, Einrichtungsbedarf, Risikoblockaden, Fehler oder Irrelevanz über /api/agent/outcome melden.

Installieren

Zum Agent-Workflow hinzufügen

Kostenlos und Open Source. Bericht vor der Installation in Produktions-Agents prüfen.

Wachstums-Loop

Share-Kit

X

Szenariobasierter Entwurf für vigilante-issue-implementation-on-github-actions, bereit für einen manuellen X-Post.

Kuratorenhinweis
vigilante-issue-implementation-on-github-actions: Implement a GitHub issue end-to-end when Vigilante dispatches work for a repository with GitH...

37 stars

https://www.openagentskill.com/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions?ref=x
X-Entwurf öffnen
Optionale Antwort mit Installationsbefehl
Listing + install path for vigilante-issue-implementation-on-github-actions:
https://www.openagentskill.com/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions?ref=x

Install: npx skills add aliengiraffe/vigilante --skill vigilante-issue-implementation-on-g...
Antwortentwurf öffnen

Quelle des Eintrags

Registry-indexiert

Beanspruchbar

Dieser Eintrag wurde aus öffentlichen Quellen indexiert und ist erst nach Genehmigung eines Maintainer-Anspruchs offiziell.

Ersteller
aliengiraffe
Indexiert von
OpenAgentSkill Community-Index

Die Zuordnung verlinkt auf das öffentliche Repository oder Creator-Profil. Creator können den Eintrag beanspruchen, um Eigentümersignale zu aktualisieren.

Diesen Skill beanspruchen

Eigentümeranspruch

Diesen Skill-Eintrag beanspruchen

Dieser Registry-indexiert-Eintrag wird aliengiraffe zugeschrieben, ist aber noch nicht offiziell markiert. Beanspruche ihn, um ein verifiziertes Eigentümersignal hinzuzufügen und künftige Launch-, Installations- und Audit-Updates vertrauenswürdiger zu machen.

Creator-Backlink-Kit

Evidenz-Badges in deine README einfügen

Zeige den kanonischen Eintrag, aktuelle Vertrauens- und Audit-Signale sowie echte Agent-Proven-Evidenz dort, wo Entwickler das Repository bewerten.

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/aliengiraffe-vigilante-issue-implementation-on-github-actions?metric=listed&label=Listed)](https://www.openagentskill.com/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/aliengiraffe-vigilante-issue-implementation-on-github-actions?metric=trust&label=Trust)](https://www.openagentskill.com/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/aliengiraffe-vigilante-issue-implementation-on-github-actions?metric=audit&label=Audit)](https://www.openagentskill.com/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/aliengiraffe-vigilante-issue-implementation-on-github-actions?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions)

Autor

A

aliengiraffe

@aliengiraffe

Gesundheitssignale

GitHub-Stars
37
Qualitätswert
34/100
Letzter GitHub-Push
19. Aug. 2026
Framework-Hinweise
Unbekannt
OpenAgentSkill-Aufrufe
0
Installationskopien
0
Externe Klicks
0

Community-Signal

Teile mit, ob dieser Skill für deinen Agent-Workflow nützlich ist. Zusammengefasstes Feedback verbessert das Ranking im Laufe der Zeit.

Vertrauen & Sicherheit

Nur Sandbox

64
  • GitHub-Akzeptanz37 GitHub-StarsPrüfen
  • Star-/Fork-Aktivität37 Stars und 6 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbarPrüfen
  • Aktuelle Wartung3 Tage seit dem letzten PushBestanden
  • LizenzklarheitApache-2.0Bestanden
  • README/SKILL.md-VollständigkeitMetadaten enthalten ausreichend Nutzungs- und Workflow-KontextBestanden
  • Abhängigkeits-/Laufzeitrisikocommand execution surface, credential or environment accessPrüfen