workflow-audit

Verificar se bwwl está disponível:

npx skills add https://github.com/bitwarden/ai-plugins --skill workflow-audit

Rules

  • This skill is strictly read-only. Do not modify, create, or delete any files.
  • Flag uncertainty. If a finding is ambiguous, note it in the report rather than guessing.

Step 1: Verify Prerequisites

Check if bwwl is available:

bwwl --version

If the command is not found, stop and inform the user that bwwl must be installed before continuing. Do not attempt to install it.

Step 2: Determine Scope

Parse the user's request to determine what to lint:

  • Single file or directory (e.g., .github/workflows/build.yml or .github/workflows/): Operate on the current repo only.
  • Multiple repos (e.g., "server, clients, android"): Operate on each repo sequentially. Ask the user for the base directory where their repos are cloned. For each repo, look for its local clone at <base-dir>/<repo>. If a clone is not found, inform the user and skip that repo.
  • No specific target: Lint all files in .github/workflows/ of the current directory.

Step 3: Run the Linter

For each repo in scope, run:

bwwl lint -f .github/workflows/

Capture both stdout and stderr. If operating on multiple repos, announce which repo is being linted.

Step 4: Parse and Categorize Findings

From the linter output, produce a structured list of findings. Group by file and rule. Consult the bitwarden-workflow-linter-rules skill to categorize each finding:

Mechanical (can be auto-fixed):

  • name_capitalized, permissions_exist, pinned_job_runner, step_pinned, underscore_outputs, job_environment_prefix, check_pr_target
  • Simple run_actionlint findings (single-line shell fixes)

Judgment (requires user input):

  • name_exists, step_approved, complex run_actionlint findings

Step 5: Report

Output a summary table per repo:

FileFindingRuleCategory
............

Include totals: mechanical findings, judgment findings, and repos with no issues.

Inform the user that they can use the workflow-fix skill to apply fixes based on these findings.

Mais skills de bitwarden

figma-to-angular
bitwarden
Esta habilidade transforma uma especificação de design do Figma em um componente Angular totalmente implementado, com histórias do Storybook no monorepo do Bitwarden Clients. O resultado deve corresponder visualmente ao design, seguindo todas as convenções do código.
force-multiplier
bitwarden
Aplique uma intenção a muitos alvos de uma só vez — uma frota de repositórios no ecossistema Bitwarden, ou muitos projetos dentro de um monorepo — como N consistentes,…
analyzing-git-sessions
bitwarden
Analisa commits e alterações do git dentro de um período ou intervalo de commits, fornecendo resumos estruturados para revisão de código, retrospectivas, registros de trabalho ou sessões…
coordinating-cross-team-breakdown
bitwarden
Coordene a revisão e aprovação entre equipes para um Bitwarden Tech Breakdown. Use ao identificar equipes afetadas, montar a tabela de aprovação da Parte 3, buscar…
assessing-jira-issue-relevance
bitwarden
Use quando o usuário fornecer uma única chave de issue do Jira e perguntar se ela ainda é relevante, ainda é aplicável, ainda está pendente, ainda é um bug, foi corrigida ou pode…
assessing-test-coverage
bitwarden
Use ao determinar qual cobertura de teste JÁ EXISTE para uma alteração específica (um PR, chave Jira, documento Tech Breakdown, CSV do Testmo, caminhos alterados ou…
retrospecting
bitwarden
Realiza análise abrangente de sessões do Claude Code, examinando histórico do git, registros de conversas, alterações de código e coletando feedback do usuário para gerar…
reviewing-incremental-changes
bitwarden
Use esta habilidade ao revisar novamente um PR que já possui comentários ou ao responder a alterações do desenvolvedor após a revisão inicial. Aplique quando houver discussões no PR ou…