Install
$ agentstack add skill-cruxexperts-localsetup-ls-github-actions-builder ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
GitHub Actions
Use this skill when authoring or reviewing GitHub Actions workflows.
Workflow
- Inspect existing triggers, permissions, concurrency, secrets, environments, and repository rules before editing.
- Define the smallest job permissions, cache key/restore strategy, artifact retention, and validation needed for the change.
- Resolve every third-party action release to its full 40-character commit SHA. Keep the human-readable release tag only as an adjacent comment; never use a mutable
@vN, branch, or tag as the executable ref. - Verify the owner, release tag, and commit provenance before accepting a new or updated SHA. Advance pins only through the repository's controlled dependency-update or reviewed maintenance process.
- Validate YAML, changed workflow paths, and representative local or CI commands before relying on automation.
Immutable action references
# actions/checkout v4.2.2
uses: actions/checkout@
- The SHA is the executed supply-chain boundary. A major-version tag such as
@v4is a mutable Git ref and is not a safe default for credential-bearing CI. - Do not copy a SHA from an unverified issue, example, or third-party workflow. Resolve the intended official release, review its provenance, and record the release tag in the comment.
- Treat third-party action pin changes as dependency updates: review the diff and release notes, run the workflow's relevant validation, and retain the review evidence.
Boundaries
- Inspect the target repository before making changes.
- Prefer existing project patterns, declared package managers, and documented validation commands.
- Do not expose secrets, credentials, private user data, or production account identifiers in source, examples, or logs.
- When external APIs or current vendor behavior matter, verify against official docs before implementation.
Provenance
- Source classification:
official-docs-reference - This is a LocalSetup-native skill written from project workflow requirements and public/official documentation routing.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: CruxExperts
- Source: CruxExperts/localsetup
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.