workflow-audit

Periksa apakah bwwl tersedia:

npx skills add https://github.com/bitwarden/ai-plugins --skill workflow-audit

Rules

  • This skill is strictly read-only. Do not modify, create, or delete any files.
  • Flag uncertainty. If a finding is ambiguous, note it in the report rather than guessing.

Step 1: Verify Prerequisites

Check if bwwl is available:

bwwl --version

If the command is not found, stop and inform the user that bwwl must be installed before continuing. Do not attempt to install it.

Step 2: Determine Scope

Parse the user's request to determine what to lint:

  • Single file or directory (e.g., .github/workflows/build.yml or .github/workflows/): Operate on the current repo only.
  • Multiple repos (e.g., "server, clients, android"): Operate on each repo sequentially. Ask the user for the base directory where their repos are cloned. For each repo, look for its local clone at <base-dir>/<repo>. If a clone is not found, inform the user and skip that repo.
  • No specific target: Lint all files in .github/workflows/ of the current directory.

Step 3: Run the Linter

For each repo in scope, run:

bwwl lint -f .github/workflows/

Capture both stdout and stderr. If operating on multiple repos, announce which repo is being linted.

Step 4: Parse and Categorize Findings

From the linter output, produce a structured list of findings. Group by file and rule. Consult the bitwarden-workflow-linter-rules skill to categorize each finding:

Mechanical (can be auto-fixed):

  • name_capitalized, permissions_exist, pinned_job_runner, step_pinned, underscore_outputs, job_environment_prefix, check_pr_target
  • Simple run_actionlint findings (single-line shell fixes)

Judgment (requires user input):

  • name_exists, step_approved, complex run_actionlint findings

Step 5: Report

Output a summary table per repo:

FileFindingRuleCategory
............

Include totals: mechanical findings, judgment findings, and repos with no issues.

Inform the user that they can use the workflow-fix skill to apply fixes based on these findings.

Lebih banyak skill dari bitwarden

analyzing-git-sessions
bitwarden
Menganalisis komit git dan perubahan dalam rentang waktu atau rentang komit, memberikan ringkasan terstruktur untuk tinjauan kode, retrospektif, catatan kerja, atau sesi…
official
figma-to-angular
bitwarden
Skill ini mengubah spesifikasi desain Figma menjadi komponen Angular yang sudah diimplementasikan sepenuhnya dengan cerita Storybook di dalam monorepo Bitwarden Clients. Outputnya harus sesuai secara visual dengan desain sambil mengikuti semua konvensi basis kode.
official
agent-access
bitwarden
Retrieve login credentials, API keys, and secrets (username, password, TOTP) from the user's Bitwarden vault via aac. Use when you need credentials to sign…
official
action-audit
bitwarden
Audit penggunaan aksi GitHub Actions di seluruh organisasi. Mencari aksi tertentu (mode insiden) atau memindai semua file workflow untuk aksi yang tidak sesuai…
official
action-remediate
bitwarden
Remediate GitHub Actions action findings identified by the action-audit skill. Applies the appropriate fix per action type — `@main` ref for internal…
official
analyzing-code-security
bitwarden
Keterampilan ini harus digunakan ketika pengguna meminta untuk "menganalisis kode untuk masalah keamanan", "memeriksa kerentanan OWASP", "meninjau kode terhadap CWE Top 25", "menemukan…
official
applying-bitwarden-branding
bitwarden
Apply Bitwarden brand standards — logo usage, color palette, typography, iconography, and capitalization rules — grounded in bitwarden.com/brand and the…
official
architecting-solutions
bitwarden
Merancang solusi di tingkat tim sambil tetap selaras dengan arsitektur holistik Bitwarden. Mencakup pola pikir keamanan, penilaian arsitektural,…
official