Automates and debugs GitHub Actions CI workflows and PR gate policies for Prowler.

Install

mkdir -p .claude/skills/prowler-ci && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/7400" && unzip -o skill.zip -d .claude/skills/prowler-ci && rm skill.zip

Installs to .claude/skills/prowler-ci

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Helps with Prowler repository CI and PR gates (GitHub Actions workflows). Trigger: When investigating CI checks failing on a PR, PR title validation, changelog gate/no-changelog label, conflict marker checks, secret scanning, CODEOWNERS/labeler automation, or anything under .github/workflows.
293 chars · catalog description✓ has a “when” triggerlonger than Claude Code's old 250-char listing cap (fine on current versions)
Intermediate

Key capabilities

  • Read or change GitHub Actions workflows
  • Explain why a PR fails checks
  • Figure out which workflows run for UI/API/SDK changes
  • Diagnose path-filtering behavior
  • Check PR title validation against Conventional Commits
  • Verify changelog fragments or `no-changelog` label

How it works

This skill analyzes GitHub Actions workflows and PR details to explain CI check failures, diagnose path-filtering, and validate PR titles and changelog requirements.

Inputs & outputs

You give it
GitHub Actions workflow files, PR details (title, labels, changed files), or failing CI check information
You get back
Explanation for CI check failures, workflow execution logic, or guidance on resolving PR gate issues

When to use prowler-ci

  • Debug failing GitHub Actions CI jobs
  • Validate PR titles against conventional commits
  • Enforce changelog requirements on pull requests
  • Configure CODEOWNERS and labeler automation

About this skill

What this skill covers

Use this skill whenever you are:

  • Reading or changing GitHub Actions workflows under .github/workflows/
  • Explaining why a PR fails checks (title, changelog, conflict markers, secret scanning)
  • Figuring out which workflows run for UI/API/SDK changes and why
  • Diagnosing path-filtering behavior (why a workflow did/didn't run)

Quick map (where to look)

  • PR template: .github/pull_request_template.md
  • PR title validation: .github/workflows/conventional-commit.yml
  • Changelog gate: .github/workflows/pr-check-changelog.yml (requires a fragment under <component>/changelog.d/)
  • Changelog compile (release time): .github/workflows/compile-changelogs.yml
  • Conflict markers check: .github/workflows/pr-conflict-checker.yml
  • Secret scanning: .github/workflows/find-secrets.yml
  • Auto labels: .github/workflows/labeler.yml and .github/labeler.yml
  • Review ownership: .github/CODEOWNERS

Debug checklist (PR failing checks)

  1. Identify which workflow/job is failing (name + file under .github/workflows/).
  2. Check path filters: is the workflow supposed to run for your changed files?
  3. If it's a title check: verify PR title matches Conventional Commits.
  4. If it's changelog: verify a valid fragment exists under the right <component>/changelog.d/ OR apply no-changelog label.
  5. If it's conflict checker: remove <<<<<<<, =======, >>>>>>> markers.
  6. If it's secrets (TruffleHog): see section below.

TruffleHog Secret Scanning

TruffleHog scans for leaked secrets. Common false positives in test files:

Patterns that trigger TruffleHog:

  • sk-*T3BlbkFJ* - OpenAI API keys
  • AKIA[A-Z0-9]{16} - AWS Access Keys
  • ghp_* / gho_* - GitHub tokens
  • Base64-encoded strings that look like credentials

Fix for test files:

# BAD - looks like real OpenAI key
api_key = "sk-test1234567890T3BlbkFJtest1234567890"

# GOOD - obviously fake
api_key = "sk-fake-test-key-for-unit-testing-only"

If TruffleHog flags a real secret:

  1. Remove the secret from the code immediately
  2. Rotate the credential (it's now in git history)
  3. Consider using .trufflehog-ignore for known false positives (rarely needed)

Notes

  • Keep prowler-pr focused on creating PRs and filling the template.
  • Use prowler-ci for CI policies and gates that apply to PRs.

How it compares

This skill provides targeted debugging and validation for GitHub Actions CI/CD, unlike general CI troubleshooting.

Compared to similar skills

prowler-ci side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
prowler-ci (this skill)16moNo flagsIntermediate
github-actions-templates73moNo flagsIntermediate
security-automation16moReviewAdvanced
bazel-build-optimization142moNo flagsAdvanced

Try saying

Example prompts that trigger this skill in your AI assistant.

Search skills

Search the agent skills registry