Install
$ agentstack add skill-montimage-skills-devops-pipeline ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
DevOps Pipeline
Implement comprehensive DevOps quality gates adapted to project type.
Repo Sync Before Edits (mandatory)
Before making any changes, sync with the remote to avoid conflicts:
branch="$(git rev-parse --abbrev-ref HEAD)"
git fetch origin
git pull --rebase origin "$branch"
If the working tree is dirty, stash first, sync, then pop. If origin is missing or conflicts occur, stop and ask the user before continuing.
Workflow
0. Create Feature Branch
Before making any changes:
- Check the current branch — if already on a feature branch for this task, skip
- Check the repo for branch naming conventions (e.g.,
feat/,feature/, etc.) - Create and switch to a new branch following the repo's convention, or fallback to:
feat/devops-pipeline
1. Analyze Project
Detect project characteristics.
Use sub-agents for parallel discovery. Launch multiple Agent tool calls concurrently to keep the main context clean:
- Agent 1 — Stack detection: Scan for
package.json,pyproject.toml,Cargo.toml,go.mod,pom.xml,build.gradle,*.csprojand identify the primary language(s), frameworks (React, Next.js, Django, FastAPI, etc.), and build tools (npm, yarn, pnpm, pip, poetry, cargo, go, maven, gradle). Return a structured summary. - Agent 2 — Existing tooling inventory: Check for existing linter/formatter configs (
.eslintrc*,.prettierrc*,tsconfig.json,mypy.ini,setup.cfg,ruff.toml) and existing CI configs (.pre-commit-config.yaml,.github/workflows/*.yml). Return a checklist of what is present vs missing. - Agent 3 — Repository conventions: Inspect the repo for branch naming conventions, commit message style, and any existing contribution guidelines. Return the conventions found.
Collect the results from all three agents before proceeding.
2. Configure Pre-commit Hooks and GitHub Actions
Use sub-agents for parallel file creation. The pre-commit config and GitHub Actions workflow are independent of each other. Dispatch them concurrently using the Agent tool, then collect results:
- Agent A — Pre-commit hooks: Install the pre-commit framework (
pip install pre-commitorbrew install pre-commit). Create.pre-commit-config.yamlbased on the detected stack from Step 1. Use [references/precommit-configs.md](references/precommit-configs.md) for language-specific configurations. Install hooks withpre-commit install. Return the path of the created config file and a summary of hooks configured. - Agent B — GitHub Actions workflow: Create
.github/workflows/ci.ymlmirroring the pre-commit checks. Use [references/github-actions.md](references/github-actions.md) for workflow templates. Follow these key principles: - Mirror pre-commit checks for consistency
- Use caching for dependencies
- Run on push and pull_request
- Add matrix testing for multiple versions if needed
Return the path of the created workflow file and a summary of jobs configured.
Each agent should return the path(s) of files it created or updated.
3. Verify Pipeline
# Test pre-commit locally
pre-commit run --all-files
# Commit and push to trigger CI
git add .pre-commit-config.yaml .github/workflows/ci.yml
git commit -m "ci: add pre-commit hooks and GitHub Actions"
git push
Check GitHub Actions tab for workflow status.
Tool Selection by Language
| Language | Formatter | Linter | Security | Types | |----------|-----------|--------|----------|-------| | JS/TS | Prettier | ESLint | npm audit | TypeScript | | Python | Black/Ruff | Ruff | Bandit | mypy | | Go | gofmt | golangci-lint | gosec | built-in | | Rust | rustfmt | Clippy | cargo-audit | built-in | | Java | google-java-format | Checkstyle | SpotBugs | - |
Resources
- [references/precommit-configs.md](references/precommit-configs.md) - Pre-commit configurations by language
- [references/github-actions.md](references/github-actions.md) - GitHub Actions workflow templates
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Montimage
- Source: Montimage/skills
- License: Apache-2.0
- Homepage: https://www.montimage.eu
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.