workflow-fix

Aplica correcciones para los hallazgos del linter de flujos de trabajo identificados por la habilidad workflow-audit. Aplica correcciones mecánicas automáticamente, se detiene para decisiones de criterio, verifica…

npx skills add https://github.com/bitwarden/ai-plugins --skill workflow-fix

Rules

  • No mutating API calls without confirmation. gh api GET requests are allowed freely. Any call using -X POST, -X PUT, -X PATCH, or -X DELETE must be shown to the user and approved before execution.
  • Never force-push, delete branches, or delete repositories.
  • Only modify files under .github/. Do not touch application code, scripts, or configuration outside of workflow files.
  • Show a diff and get confirmation before handing off for commit.
  • All PRs must be created as drafts.
  • Flag uncertainty. If a finding is ambiguous or a fix could break a workflow, stop and ask rather than guessing.

Step 1: Verify Prerequisites

Check if bwwl is available:

bwwl --version

If the command is not found, stop and inform the user that bwwl must be installed before continuing. Do not attempt to install it.

Step 2: Determine Scope

Parse the user's request to determine what to fix:

  • Single file or directory: Operate on the current repo only.
  • Multiple repos (e.g., "server, clients, android"): Operate on each repo sequentially. Ask the user for the base directory where their repos are cloned. For each repo, look for its local clone at <base-dir>/<repo>. If a clone is not found, inform the user and skip that repo.
  • No specific target: Fix all findings in .github/workflows/ of the current directory.

If the user has not run the workflow-audit skill first, run the linter now to identify findings before proceeding.

Step 3: For Each Repo in Scope

Repeat Steps 4–7 for each repo. Announce which repo is being worked on.

Step 4: Create a Fix Branch

Only create the fix branch if there are findings to fix:

git checkout -b fix/workflow-linter-findings

Step 5: Apply Fixes

Consult the bitwarden-workflow-linter-rules skill for the correct fix for each rule.

For mechanical findings: Apply all fixes without prompting.

Exception — step_pinned: Before applying each hash pin, follow the step_pinned fix procedure from the bitwarden-workflow-linter-rules skill (resolve SHA via gh api, show verification link, wait for user confirmation).

For judgment findings: For each one, pause and present the finding clearly. Ask the user which option they want (per the bitwarden-workflow-linter-rules skill), then apply their choice.

Step 6: Verify Fixes

Re-run the linter to confirm all findings are resolved:

bwwl lint -f .github/workflows/

If errors remain, analyze and fix them. Repeat until clean.

Step 7: Review and Create PR

After all fixes are applied:

  1. Show a git diff of all changes made.
  2. Ask the user to confirm they want to proceed with a PR.
  3. Do not run the staging, commit, or push commands yourself. Present the block below for the user to run manually as a suggestion:
git add .github/workflows/
git commit -m "Fix workflow linter findings"
git push -u origin fix/workflow-linter-findings
  1. Once the user confirms the push, create the draft PR:
gh pr create \
  --title "Fix workflow linter findings" \
  --body "Automated fixes for findings from the Bitwarden workflow linter (bwwl)." \
  --draft

Step 8: Summary

After processing all repos, output a summary table:

RepoFindings FixedPRs CreatedSkipped / Notes
............

Más skills de bitwarden

analyzing-git-sessions
bitwarden
Analiza los commits y cambios de git dentro de un período de tiempo o rango de commits, proporcionando resúmenes estructurados para revisión de código, retrospectivas, registros de trabajo o sesiones…
official
figma-to-angular
bitwarden
Esta habilidad convierte una especificación de diseño de Figma en un componente Angular completamente implementado con historias de Storybook en el monorepo de Bitwarden Clients. El resultado debe coincidir visualmente con el diseño, siguiendo todas las convenciones del código base.
official
agent-access
bitwarden
Recuperar credenciales de inicio de sesión, claves de API y secretos (nombre de usuario, contraseña, TOTP) del vault de Bitwarden del usuario a través de aac. Usar cuando necesites credenciales para iniciar sesión…
official
action-audit
bitwarden
Auditar el uso de acciones de GitHub Actions en una organización. Busca una acción específica (modo incidente) o examina todos los archivos de workflow en busca de acciones no conformes…
official
action-remediate
bitwarden
Remediate GitHub Actions action findings identified by the action-audit skill. Applies the appropriate fix per action type — `@main` ref for internal…
official
analyzing-code-security
bitwarden
Esta habilidad debe utilizarse cuando el usuario solicita "analizar código en busca de problemas de seguridad", "verificar vulnerabilidades OWASP", "revisar código contra CWE Top 25", "encontrar…
official
applying-bitwarden-branding
bitwarden
Aplicar los estándares de marca de Bitwarden — uso del logotipo, paleta de colores, tipografía, iconografía y reglas de capitalización — basados en bitwarden.com/brand y el…
official
architecting-solutions
bitwarden
Arquitectura de soluciones a nivel de equipo manteniendo coherencia con la arquitectura holística de Bitwarden. Abarca la mentalidad de seguridad, el criterio arquitectónico,…
official