vigilante-issue-implementation-on-github-actions
Implement a GitHub issue end-to-end when Vigilante dispatches work for a repository with GitHub Actions workflows, applying workflow hardening, pinned actions, and secret-safe automation practices.
Profil aset
Agent pemrograman dan pengembangan
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Skenario
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Kecocokan Agent
Claude Code + OpenAI Agents + CLI
Cocok untuk Codex, Claude Code, Cursor, CLI, atau Agent khusus.
Pasang
Siap
npx skills add aliengiraffe/vigilante --skill vigilante-issue-implementation-on-github-actions
Pemeliharaan
Terkini
3 hari sejak push
Risiko
Perlu ditinjau
Dependency or permission surface needs review
Kualitas GitHub
37
62/100 Kualitas · 72/100 Kepercayaan
Tag cakupan
Catatan ulasan
Dependency or permission surface needs review · Permission surface may require sandboxing
Kartu adopsi Agent
Kepercayaan, audit, dan kesiapan pemasangan dalam sekali lihat
Skor ini menggabungkan metadata repositori publik, sinyal ulasan OpenAgentSkill, kebaruan pemeliharaan, dan kesiapan pemasangan. Ini adalah sinyal shortlist, bukan pengganti peninjauan manusia.
Kualitas
MenjanjikanUseful candidate, but compare it with alternatives before adopting.
Kepercayaan
Hanya sandboxKandidat berguna dengan sinyal kepercayaan yang kurang atau bercampur. Gunakan di ruang kerja terisolasi hingga loop hasil membuktikan kecocokan tugas.
Audit
Perlu ditinjauTinjauan yang dapat dibaca mesin tentang kesiapan pemasangan, metadata keamanan, pemeliharaan, dan risiko adopsi.
Trust Score OpenAgentSkill v5
Tinjauan manusia sebelum pemasangan
Jalankan hanya dalam sandbox dan bandingkan alternatif terdekat sebelum digunakan untuk kerja nyata.
Star
37 star GitHub
Aktivitas repositori
37 star dan 6 fork
Pemeliharaan
3 hari sejak push
Lisensi
Apache-2.0
Pasang
npx skills add aliengiraffe/vigilante --skill vigilante-issue-implementation-on-github-actions
Keamanan pemasangan
Jalur pemasangan paket atau runtime standar
Cakupan izin
secrets or environment access, shell or command execution
Hasil Agent
Belum ada data hasil Agent
Dokumentasi
Konteks README/SKILL.md kuat
Ringkasan risiko
Tinjau sebelum produksi
- Low GitHub adoption signal
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- GitHub adoption: 37 GitHub stars
Kesiapan pemasangan
Jalur pemasangan tersedia
- Jalur pemasangan tersedia
- Bukti repositori tersedia
- Lisensi dinyatakan
- Belum ada bukti hasil Agent-Proven
Metadata yang dapat dibaca Agent
Data keputusan yang dapat dibaca mesin untuk skill ini.
Gunakan blok ini atau JSON tersemat untuk memutuskan apakah Agent perlu memasang skill ini, memilih alternatif, atau meminta tinjauan manusia terlebih dahulu.
Tugas yang sesuai
- alur kerja GitHub automation
- Tim Claude Code
- builders willing to evaluate younger projects
- Inspect repository metadata
Agent yang sesuai
Keputusan pemasangan
- Perintah
- npx skills add aliengiraffe/vigilante --skill vigilante-issue-implementation-on-github-actions
- Kebijakan
- Blokir
- Tinjauan manusia
- Ya
Kepercayaan dan risiko
- Kepercayaan
- 64/100
- Audit
- 76/100
- Tingkat risiko
- Perlu ditinjau
Lingkar hasil
- Endpoint
- /api/agent/outcome
- ID event
- resolve
- Hasil
- 5
Perintah pemasangan
npx skills add aliengiraffe/vigilante --skill vigilante-issue-implementation-on-github-actionsJangan gunakan ketika
- Tim yang membutuhkan SLA dengan dukungan vendor
- production agents without a repository review
- Low GitHub adoption signal
- No OpenAgentSkill engagement data yet
- Petunjuk izin berisiko tinggi: Shell or command execution, Secrets or environment access
Keamanan Agent v2
36/100 · Hindari pemasangan otomatis
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
Tinggi
Eksekusi shell atau perintah
Metadata skill merujuk terminal, CLI, shell, subprocess, atau alur kerja eksekusi perintah.
Sedang
Akses jaringan
Skill kemungkinan mengambil halaman jarak jauh, API, repositori, atau layanan eksternal.
Sedang
Akses sistem file
Skill dapat membaca atau menulis file proyek, dokumen, artefak yang dihasilkan, atau status workspace lokal.
Tinggi
Secrets or environment access
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
- Petunjuk izin berisiko tinggi: Shell or command execution, Secrets or environment access
- Dependency or permission surface needs review
Target pemasangan
Pasang skill ini di alur Agent Anda
Gunakan endpoint publik untuk mengambil perintah, checklist keamanan, prompt target, dan tautan kanonis.
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install aliengiraffe-vigilante-issue-implementation-on-github-actionsRencana resolusi Agent
Biarkan Agent memverifikasi kecocokan sebelum memasang.
API Resolve mengembalikan skill utama, alternatif, kebijakan keamanan, catatan audit, target pemasangan, dan prompt siap pakai.
Buka JSON
/api/agent/resolve?task=Use%20vigilante-issue-implementation-on-github-actions%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Teks Resolve
/api/agent/resolve?task=Use%20vigilante-issue-implementation-on-github-actions%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Serah-terima pemasangan
/api/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions/install
Agent harus memeriksa
- Task fit and alternatives from Resolve API.
- Audit score, trust score, and safety policy warnings.
- Install target compatibility for Codex, Claude Code, Cursor, or CLI.
Salin prompt
Task: Use vigilante-issue-implementation-on-github-actions in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20vigilante-issue-implementation-on-github-actions%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions/install
Install command: npx skills add aliengiraffe/vigilante --skill vigilante-issue-implementation-on-github-actions
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Serah-terima Agent
Berikan jalur pemasangan kepada Agent, bukan direktori lain.
Gunakan endpoint publik untuk mengambil perintah, checklist keamanan, prompt target, dan tautan kanonis.
Serah-terima pemasangan
/api/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions/install
Format teks LLM
/api/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions/install?format=text
Cari alternatif
/api/skills/search?q=vigilante-issue-implementation-on-github-actions&limit=3
Prompt Agent
Use vigilante-issue-implementation-on-github-actions for this task. Review https://www.openagentskill.com/api/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions/install, then install with: npx skills add aliengiraffe/vigilante --skill vigilante-issue-implementation-on-github-actionsMetadata Registry
Profil yang dapat dibaca Agent untuk pemilihan skill otomatis.
API Registry menyediakan sinyal keputusan, kepercayaan, audit, use case, dan pemasangan tanpa mengikis UI.
Manifest
/api/registry/manifest/aliengiraffe-vigilante-issue-implementation-on-github-actions
Teks LLM
/api/registry/manifest/aliengiraffe-vigilante-issue-implementation-on-github-actions?format=text
Alias pemasangan
/api/registry/install/aliengiraffe-vigilante-issue-implementation-on-github-actions
Rekomendasikan
/api/registry/recommend?task=Use%20vigilante-issue-implementation-on-github-actions%20in%20an%20agent%20workflow&limit=3
Kecocokan Agent
GitHub automation
Tag use case
Platform
Claude Code, OpenAI Agents
Laporan audit
Perlu ditinjau · 76/100
Tinjauan yang dapat dibaca mesin tentang kesiapan pemasangan, metadata keamanan, pemeliharaan, dan risiko adopsi.
Panel keputusan Agent
Fallback candidate for GitHub automation
Prototype with this skill first; keep a fallback candidate ready.
Peran di stack
Kandidat cadangan
Kecocokan utama
GitHub automation
Label kepercayaan
Buat prototipe dulu
Jalur pemasangan
Perintah siap
Gunakan saat
- alur kerja GitHub automation
- Tim Claude Code
- builders willing to evaluate younger projects
Bukti
- recent repository activity
- install command or GitHub repo available
- profil kualitas 62/100
tinjau dulu
- Low GitHub adoption signal
- No OpenAgentSkill engagement data yet
Jalur implementasi
- 1Pasang di Agent sandbox dan jalankan satu tugas GitHub automation dari awal hingga akhir.
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
Profil kepercayaan
Hanya sandbox
Kandidat berguna dengan sinyal kepercayaan yang kurang atau bercampur. Gunakan di ruang kerja terisolasi hingga loop hasil membuktikan kecocokan tugas.
Adopsi GitHub
Periksa37 star GitHub
Aktivitas star/fork
Periksa37 star dan 6 fork; aktivitas issue tidak tersedia dalam metadata saat ini
Pemeliharaan terbaru
Lulus3 hari sejak push
Kejelasan lisensi
LulusApache-2.0
Sinyal positif
- Tinjauan AI disetujui
- Jalur pemasangan tersedia
- Bukti repositori tersedia
- Repositori yang baru dipelihara
- Perintah pemasangan tidak memiliki pola berisiko tinggi yang jelas
- Loop hasil siap tetapi membutuhkan eksekusi Agent nyata pertama
Tinjau sebelum memasang
- Low GitHub adoption signal
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- GitHub adoption: 37 GitHub stars
- Stars/forks activity: 37 stars, 6 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
- Belum ada laporan hasil Agent nyata
- Tinjauan manusia diperlukan sebelum pemasangan tanpa pengawasan
Tindakan yang disarankan
Jalankan hanya dalam sandbox dan bandingkan alternatif terdekat sebelum digunakan untuk kerja nyata.
Profil kualitas
Menjanjikan kandidat untuk alur kerja Agent
Useful candidate, but compare it with alternatives before adopting.
Kecocokan alur kerja
Gunakan skill ini pada skenario berikut
Manage repositories
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Build and ship code
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
Operate local tools
Local desktop
I need my agent to operate local files and desktop apps in a repeatable workflow.
Kecocokan alur kerja
Tambahkan ke alur kerja lengkap
Inspect, patch, and verify code
Coding review agent
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Turn skills into distribution
Content growth agent
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Daftar alternatif
Bandingkan sebelum memasang
Similar skills that may fit this task.
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
Ringkasan
--- name: vigilante-issue-implementation-on-github-actions description: Implement a GitHub issue end-to-end when Vigilante dispatches work for a repository with GitHub Actions workflows, applying workflow hardening, pinned actions, and secret-safe automation practices. ---
# Vigilante GitHub Actions Issue Implementation
## Focus - Read the prompt for detected tech stacks, process hints, and security guidance before changing workflow files. - Keep changes scoped to the issue and do not broaden into unrelated workflow or repository changes. - Treat `.github/workflows/` as a security-sensitive surface. Every workflow edit should consider permissions, secret exposure, and supply-chain risk.
## Workflow File Conventions - Use `.yml` or `.yaml` consistently with the repository's existing convention. Do not mix extensions within the same repository. - Validate workflow syntax before committing. Use `actionlint` when it is available in the repository or installed locally. If `actionlint` is not available, note its absence and continue — do not fabricate output. - Keep workflow files readable: use clear job and step names, add inline comments for non-obvious logic, and prefer reusable workflows or composite actions over duplicated step blocks.
## Pinned Actions - Pin third-party actions to full commit SHAs, not mutable tags or branch references. Example: `uses: actions/checkout@<full-sha>` with a trailing version comment. - When updating an action version, verify the new SHA corresponds to a reviewed release or tag. - First-party GitHub actions (`actions/*`) should also be pinned to SHAs for consistency and supply-chain safety. - When adding a new third-party action, prefer well-maintained actions with high community adoption. Avoid actions that request broad permissions or lack clear provenance.
## Least-Privilege Permissions - Always declare a top-level `permissions:` block in workflow files. Default to the most restrictive set needed. - Use read-only `contents: read` unless the workflow must write (e.g., creating releases, pushing tags, commenting on PRs). - Scope token permissions per job when different jobs need different access levels. - Never use `permissions: write-all` or leave permissions unspecified, which defaults to broad access in some repository configurations.
## Secret and Credential Safety - Never echo, log, or interpolate secrets directly in `run:` shell commands. Pass secrets through environment variables. - Use `::add-mask::` to mask dynamic values that may appear in logs. - Prefer OIDC-based authentication (e.g., `aws-actions/configure-aws-credentials` with `role-to-assume`) over long-lived cloud credentials stored as repository secrets. - Do not store secrets, tokens, or credentials in workflow files or committed configuration. - When a workflow needs elevated access, document why in a comment and scope the access as narrowly as possible.
## Safe Workflow Authoring - Never interpolate untrusted event data (such as `${{ github.event.pull_request.title }}` or `${{ github.event.issue.body }}`) directly into `run:` shell scripts. Use an intermediate environment variable to prevent script injection. - Prefer `pull_request` over `pull_request_target` unless cross-fork access is explicitly required and the workflow is hardened against injection. - Use `concurrency` groups to prevent redundant or conflicting workflow runs. - Set appropriate `timeout-minutes` on jobs to prevent hung runners from consuming resources.
## Reusable Workflows and Composite Actions - Prefer the repository's existing reusable workflows and composite actions over duplicating logic. - When creating new reusable workflows, define clear `inputs` and `secrets` contracts. - Respect the repository's branch-protection rules and required status checks when adding or modifying workflows.
## Mixed-Stack Repositories - A repository with GitHub Actions workflows often also contains application code in Go, Node.js, Python, or other languages. - Scope workflow-specific guidance to `.github/workflows/` and related CI/CD configuration only. Do not apply workflow linting or hardening rules to application source code. - When an issue touches both workflow files and application code, validate each side with its appropriate toolchain. - Check the prompt for additional detected tech stacks and follow their respective guidance for non-workflow changes.
## Workflow - Follow the base `vigilante-issue-implementation` workflow for issue comments, validation, push, and PR creation, including stacked base-branch detection (`Base branch:` directive in the issue body). - Use `vigilante commit` for all commit-producing operations. Do not use `git commit` or GitHub CLI commit flows directly. - Any commit or amend must preserve the user's existing git author, committer, and signing configuration. Commit on behalf of the user and do not overwrite `git config` with a coding-agent identity. - Do not add `Co-authored by:` trailers or any other agent attribution for Codex, Claude, Gemini, or similar coding-agent identities. - Repository-specific instructions (`AGENTS.md`, `README.md`, CI config) remain authoritative when they are more specific than the generic GitHub Actions guidance in this skill.
Detail teknis
- Versi
- 1.0.0
- Lisensi
- Apache-2.0
- Pembaruan terakhir
- 19 Agu 2026
- Diterbitkan
- 19 Agu 2026
Ringkasan keputusan
Kandidat cadangan
recent repository activity
Audit
Tinjauan pemasangan
Tinjauan pemasangan dan adopsi
- Keamanan
- 77/100
- Pemeliharaan
- 100/100
- Pasang
- 92/100
Bukti tervalidasi Agent
Bukti tervalidasi Agent
Laporan hasil setelah resolve, tinjau, pasang, dan satu eksekusi terbatas.
- Tingkat sukses
- —
- Kegagalan terbaru
- —
- Hasil
- 0
- Kualitas output
- —
- Gagal
- 0
- Tidak relevan
- 0
- Pemasangan
- 0
- Diblokir risiko
- 0
- Perlu penyiapan
- 0
- Produksi
- 0
Belum ada data hasil Agent. Eksekusi pertama dapat melaporkan keberhasilan, kebutuhan setup, blok risiko, kegagalan, atau tidak relevan melalui /api/agent/outcome.
Pasang
Tambahkan ke alur Agent
Gratis dan sumber terbuka. Tinjau laporan sebelum memasang pada Agent produksi.
Siklus pertumbuhan
Kit berbagi
Draf berbasis skenario untuk vigilante-issue-implementation-on-github-actions, siap untuk posting manual di X.
vigilante-issue-implementation-on-github-actions: Implement a GitHub issue end-to-end when Vigilante dispatches work for a repository with GitH... 37 stars https://www.openagentskill.com/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions?ref=x
Balasan opsional dengan perintah pemasangan
Listing + install path for vigilante-issue-implementation-on-github-actions: https://www.openagentskill.com/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions?ref=x Install: npx skills add aliengiraffe/vigilante --skill vigilante-issue-implementation-on-g...
Sumber listing
Diindeks Registry
Listing ini diindeks dari sumber publik dan belum ditandai resmi hingga klaim pemelihara disetujui.
- Kreator
- aliengiraffe
- Sumber
- aliengiraffe/vigilante
- Diindeks oleh
- Indeks komunitas OpenAgentSkill
Atribusi menautkan ke repositori publik atau profil kreator. Kreator dapat mengklaim listing untuk memperbarui sinyal kepemilikan.
Klaim skill iniKlaim pemilik
Klaim listing skill ini
Listing Diindeks Registry ini dikaitkan dengan aliengiraffe, tetapi belum ditandai resmi. Klaim untuk menambahkan sinyal pemilik terverifikasi dan membuat pembaruan peluncuran, pemasangan, serta audit berikutnya lebih tepercaya.
Kit backlink kreator
Tambahkan badge bukti ke README Anda
Tampilkan listing kanonis, sinyal kepercayaan dan audit saat ini, serta bukti Agent-Proven nyata di tempat pengembang mengevaluasi repositori.
[](https://www.openagentskill.com/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions)
[](https://www.openagentskill.com/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions)
[](https://www.openagentskill.com/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions/audit)
[](https://www.openagentskill.com/skills/aliengiraffe-vigilante-issue-implementation-on-github-actions)Penulis
aliengiraffe
@aliengiraffe
Tag
Kecocokan platform
Sinyal kesehatan
- Star GitHub
- 37
- Skor kualitas
- 34/100
- Push GitHub terakhir
- 19 Agu 2026
- Petunjuk framework
- Tidak diketahui
- Tampilan OpenAgentSkill
- 0
- Salinan pemasangan
- 0
- Klik keluar
- 0
Sinyal komunitas
Bagikan apakah skill ini bermanfaat untuk alur kerja Agent Anda. Masukan gabungan meningkatkan peringkat dari waktu ke waktu.
Kepercayaan & keamanan
Hanya sandbox
- Adopsi GitHub37 star GitHubPeriksa
- Aktivitas star/fork37 star dan 6 fork; aktivitas issue tidak tersedia dalam metadata saat iniPeriksa
- Pemeliharaan terbaru3 hari sejak pushLulus
- Kejelasan lisensiApache-2.0Lulus
- Kelengkapan README/SKILL.mdMetadata memuat konteks penggunaan dan alur kerja yang cukupLulus
- Risiko dependensi/runtimecommand execution surface, credential or environment accessPeriksa
Skill terkait
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K Star