Install
$ agentstack add skill-urmzd-dotfiles-setup-ci ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README — it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming — see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps — measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
CI/CD Standards
Universal conventions that apply across all languages. For language-specific CI jobs, build matrices, and caching, see the corresponding scaffold-* skill.
Workflow Naming Convention
| File | Trigger | Purpose | |------|---------|---------| | ci.yml | pull_request: branches: [main] + workflow_call | Quality gate: fmt, lint, test | | release.yml | push: branches: [main] + workflow_dispatch | Automated releases |
- No
build.ymlorpublish.ymlbuild and publish are jobs withinrelease.yml - Specialized workflows allowed for domain-specific needs (e.g.,
experiments.yml) - Exception: Terraform uses a single
terraform.yml(seescaffold-terraform)
Pipeline Flow
PR -> ci.yml (fmt -> lint -> test)
Push main -> release.yml:
fsrc -> ci -> sr release -> build -> publish -> teasr -> lock sync
Release Config
- Canonical filename:
sr.yaml(not.urmzd.sr.yml) floating_tags: truein all configstag_prefix: "v"and Angular commit pattern- See
sync-releasefor full sr.yaml reference
Concurrency
# CI workflows: cancel stale runs
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
# Release workflows: never cancel mid-release
concurrency:
group: release
cancel-in-progress: false
Bot Skip
Prevent infinite loops from bot commits:
if: github.actor != 'sr[bot]'
CI Reuse Pattern
ci.yml exposes workflow_call so release.yml can gate on it:
# ci.yml
on:
pull_request:
branches: [main]
workflow_call:
# release.yml
jobs:
ci:
uses: ./.github/workflows/ci.yml
release:
needs: ci
App Token Pattern
Release workflows use a GitHub App for bot commits that can trigger further workflows:
- name: Generate app token
id: app-token
uses: actions/create-github-app-token@v1
with:
app-id: ${{ secrets.SR_RELEASER_APP_ID }}
private-key: ${{ secrets.SR_RELEASER_PRIVATE_KEY }}
repositories: ${{ github.event.repository.name }}
- uses: actions/checkout@v4
with:
fetch-depth: 0
token: ${{ steps.app-token.outputs.token }}
fsrc Step (Optional)
Sync code snippets into README before release:
- uses: urmzd/fsrc@v4
with:
files: "README.md"
commit-message: "chore: sync embedded files [skip ci]"
teasr Step (Post-Release, Optional)
Capture terminal demo after release:
- uses: urmzd/teasr/.github/actions/teasr@main
Force Re-release
All release workflows support manual dispatch with a force flag for partial failures:
workflow_dispatch:
inputs:
force:
description: "Re-release the current tag (use when a previous release partially failed)"
type: boolean
default: false
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: urmzd
- Source: urmzd/dotfiles
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.