AgentStack
SKILL verified MIT Self-run

Ci Cd Pipeline Builder

skill-droodotfoo-agent-skills-ci-cd-pipeline-builder · by DROOdotFOO

|

No reviews yet
0 installs
1 views
0.0% view→install

Install

$ agentstack add skill-droodotfoo-agent-skills-ci-cd-pipeline-builder

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Ci Cd Pipeline Builder? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

CI/CD Pipeline Builder

What You Get

  • GitHub Actions or GitLab CI YAML file ready to commit
  • Dependency caching, pinned versions, test + lint + build stages

Philosophy

Start with a minimal reliable pipeline that runs tests on every push. Add complexity only when justified. A pipeline that is fast and trustworthy is better than one that is comprehensive and flaky.

Workflow: 5 Phases

Phase 1: Detect Stack

Scan the repository for manifests, lockfiles, and configuration files. See [stack-detection.md](stack-detection.md) for the full signal table. Identify:

  • Primary language(s) and runtime versions
  • Package manager and lockfile
  • Test framework and test command
  • Linter and formatter
  • Build tool and build command
  • Monorepo structure (if applicable)

Phase 2: Choose Platform

Default to GitHub Actions unless the project already uses GitLab CI or the user requests otherwise. Check for existing pipeline files:

  • .github/workflows/*.yml -- GitHub Actions
  • .gitlab-ci.yml -- GitLab CI

If a pipeline already exists, extend it rather than replacing it.

Phase 3: Generate Pipeline

Start with the minimal reliable baseline from [pipeline-templates.md](pipeline-templates.md):

  1. Install dependencies (with caching)
  2. Run linter/formatter check
  3. Run tests
  4. Build (if applicable)

Use the detected runtime version. Pin action versions to specific SHAs or major versions. Use lockfile-based caching.

Phase 4: Validate

Before presenting the pipeline to the user:

  • Verify all referenced tools are in the project's dependencies
  • Check that test/lint/build commands match the project's configuration
  • Ensure secrets are referenced by name, not hardcoded
  • Confirm the runner OS matches the project's requirements

Phase 5: Add Deployment Stages

Only if the user requests deployment. Add stages for:

  • Staging deployment (on merge to main)
  • Production deployment (on tag or manual trigger)
  • Environment-specific secrets and approvals

Keep deployment stages separate from CI stages. CI should pass before deployment is attempted.

WRONG: floating versions

# WRONG: unpinned action version, no caching, floating runtime
- uses: actions/setup-node@latest
- run: npm ci && npm test

CORRECT: pinned and cached

# CORRECT: pinned action, lockfile cache, explicit runtime
- uses: actions/setup-node@v4
  with:
    node-version-file: '.nvmrc'
    cache: 'npm'
- run: npm ci
- run: npm test

Rules

  • Always cache dependencies. Uncached CI is a waste of compute.
  • Pin versions: actions, runtimes, dependencies. Floating versions cause flaky builds.
  • Keep pipelines under 10 minutes. If slower, parallelize or split.
  • Never store secrets in pipeline files. Use the platform's secrets manager.
  • Run the full test suite, not a subset. Partial CI is worse than no CI.

Sub-files

| File | Topic | |------|-------| | [stack-detection.md](stack-detection.md) | File signals per ecosystem | | [pipeline-templates.md](pipeline-templates.md) | GitHub Actions and GitLab CI scaffolds |

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.