CI/CD and Automation
Quality-gate pipelines — lint, type check, tests, build, security audit on every change; shift left, faster is safer
- What
- Quality-gate pipelines — lint, type check, tests, build, security audit on every change; shift left, faster is safer
- Cost
- Free
- Needs
- a project with (or planning) a CI provider (GitHub Actions, GitLab CI, etc.)
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — a CI/CD skill from Addy Osmani's engineering workflow collection: automate quality gates so no change reaches production without passing lint, type check, unit tests, build, integration tests, E2E, security audit, and bundle-size checks. Its two mantras are shift left (a bug caught in linting costs minutes, in production costs hours) and faster is safer (small batches and frequent releases reduce risk — a 3-change deploy is easier to debug than a 30-change one). It covers new pipeline setup, modifying automated checks, deployment strategies, and debugging CI failures. Distinct from the already-published addyosmani skills — none of them cover pipelines; this one is the enforcement mechanism for every other skill. By @addyosmani, listed here with credit to its creator. Honest caveats: pipelines enforce whatever you put in them — a green build with weak tests is theater, not safety; and flaky E2E will teach your team to ignore red, which is worse than no gate at all. Skill Harbor never reviews the code, review it yourself before use.
Version:
Install
Prerequisites: a project with (or planning) a CI provider (GitHub Actions, GitLab CI, etc.) Install "CI/CD and Automation" for me. Quality-gate pipelines — lint, type check, tests, build, security audit on every change; shift left, faster is safer Repository: https://github.com/addyosmani/agent-skills/blob/main/skills/ci-cd-and-automation/SKILL.md 1. Fetch the SKILL.md file for the addyosmani-ci-cd-and-automation skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "addyosmani-ci-cd-and-automation". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. any accounts, API keys, or CLI tools mentioned in the prerequisites above). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.