{ }
Resource profile / GitHub Actions Efficiency Review
About this skill

Workflow & requirements

GitHub Actions Efficiency

Use this skill as a lean entrypoint for GitHub Actions efficiency work. Inspect the repo, identify the waste source, and load only the reference material needed for the current task.

If no workflows exist yet, load references/actions.md and define a baseline before proceeding with the steps below.

If shell or gh CLI access is unavailable: ask the user to paste .github/workflows/ contents and gh run list --limit 10 output. If only partial files are provided, note it: "Audit based on provided files only; some insights may be incomplete." Begin responses from files alone with: "Static-only analysis (not confirmed with live runs)."

Use This Skill When

  • The user wants to reduce GitHub Actions runtime, CI cost, or wasted workflow runs.
  • The repo has existing workflows in .github/workflows/ or explicit GitHub Actions configuration questions.
  • The user asks for caching, concurrency, path filters, matrix reduction, job optimization, or workflow-specific fixes.
  • The user needs help creating a new GitHub Actions workflow or CI baseline from scratch.

Load Only What You Need

Core Workflow

1. Measure first

rg -n "on:|concurrency:|paths:|paths-ignore:|strategy:|matrix:|cache:" .github/workflows
gh run list --limit 10
run_id=$(gh run list --limit 1 --json databaseId --jq '.[0].databaseId')
gh run view "$run_id" --log-failed

Look for: missing dependency caches, missing concurrency cancellation, over-broad triggers, duplicate workflow coverage, and expensive jobs that run on every change regardless of scope.

2. Apply guardrails

Check each proposed fix against these rules before recommending it:

  1. Does not hide required validation — drop any fix that removes release, schema, migration, or shared-library checks.
  2. Does not reduce parallelism without justification — drop unless the user prioritised cost over latency and the new critical path stays within 1.25× the original.
  3. Preserves only documented matrix legs — drop matrix legs with no explicit version or platform commitment.
  4. Write-back jobs use opt-in triggers — flag (do not drop) formatter or bot jobs that run automatically; recommend an opt-in trigger instead.
  5. Repo changes stay separate from org settings — split any fix that mixes repo-editable YAML with org-level or GitHub-account settings into two distinct recommendations.

3. Select the top 3 fixes

From the six candidates below, keep only those supported by audit evidence from step 1 and passing all guardrails from step 2. Rank survivors by estimated daily CI minutes saved (per-run savings × runs per day). Select all candidates that meet both criteria, up to a maximum of 3.

  1. Add dependency caching with lockfile-based keys
  2. Add or correct concurrency cancellation
  3. Remove duplicate workflow coverage before merging jobs
  4. Narrow workflow or job triggers safely
  5. Reduce matrix breadth to match risk and event type
  6. Parallelize independent jobs on the critical path

4. Verify

  • If gh CLI access is available, validate path-gating and concurrency cancellation with a live test push on a non-protected branch.
  • If live validation is not possible, state that explicitly in the output.
  • Treat unexpected live behavior as a real bug even when the YAML looks correct.

Required Output

  1. Waste sources — top cost or latency drivers found in step 1
  2. Proposed fixes — top 3 (or all remaining) with supporting audit evidence
  3. Validation — what was proven live, what was checked locally only, and any remaining risk
  4. Impact — expected savings vs. measured savings; separate PR wall-clock time from total runner time

References

PACKAGE TRANSPARENCY

Inspect before installing

Source: GitHub community · MIT · SHA-256 shown alongside the download.

8 files9402 ZIP bytes0 script/code files

License file included. A license and checksum are not a security certification. Review package instructions and scripts before running them.

View files and uncompressed sizes
Machine-readable installation guide →
CATALOG REVIEW NOTES

Know what you need before installing

Source and packaging checks recorded on 2026-10-04. These notes are not safety certification or measured task performance.

Requirements

Workflow YAML and documented CI requirements; a local agent is separate. Optional gh CLI and an authorized GitHub account for live run data. No executable or credentials are bundled; installation grants no push or workflow dispatch authority.

Costs, access & practical limits

MIT instruction files are free to acquire and redistribute with the notice. Our recorded actionlint fixture checks run locally without a GitHub login or cloud jobs. Client/model plans and GitHub runner usage may have separate costs. No purchase, workflow run or paid account is activated by downloading the package.

View the recorded checks
  • Pinned upstream Git objects and complete MIT notice verified
  • Original SKILL.md and all four reference files preserved
  • All local reference links resolve inside the package
  • Community source and independent packaging disclosed
  • Static lint scope distinguished from live CI savings and agent execution
  • Required-check and branch-protection caveats documented

Upstream commit: 143a3d976b3c1603cc8932984d5e1f28501cb5fc

Runtime status: not tested by this catalog. Configure your client and test the skill in your own environment.

SCENARIOS

Inputs, criteria and recorded outcomes

Records are supplied by the site administrator and bound to a specific package. They are not third-party safety certification. This page does not execute skills.

Workflow lint fixture: cache expressions, opt-in jobs and invalid dependencies

Reported passed · v143a3d976b3c.bb1

View input and acceptance criteria

Input

On synthetic workflow YAML, check cache and concurrency expressions, opt-in jobs and a compatibility matrix. Deliberately introduce invalid contexts, matrix references, missing or cyclic dependencies, permission values, conflicting path filters and malformed YAML. Run local actionlint only; do not dispatch cloud jobs.

Acceptance criteria

Twenty named package-integrity and actionlint observations match. This does not evaluate live cache behavior, cancellation, GitHub required-check coverage, CI savings, complete script/security review or AI execution.

Recorded outcome

No AI client or GitHub workflow was run. Twenty named package-integrity and local actionlint observations on synthetic YAML only; this does not prove cache hits, stale-run cancellation, branch-protection coverage, CI minutes saved, complete security or model decisions.

{
  "executed_at": "2026-10-04T02:43:12.679880+00:00",
  "assertions": 20,
  "cases": [
    {
      "name": "package-matches-catalog-sha256",
      "status": "passed"
    },
    {
      "name": "pinned-upstream-github-actions-efficiency/LICENSE.upstream.txt",
      "status": "passed"
    },
    {
      "name": "pinned-upstream-github-actions-efficiency/SKILL.md",
      "status": "passed"
    },
    {
      "name": "pinned-upstream-github-actions-efficiency/references/actions.md",
      "status": "passed"
    },
    {
      "name": "pinned-upstream-github-actions-efficiency/references/patterns.md",
      "status": "passed"
    },
    {
      "name": "pinned-upstream-github-actions-efficiency/references/reporting.md",
      "status": "passed"
    },
    {
      "name": "pinned-upstream-github-actions-efficiency/references/review-rubric.md",
      "status": "passed"
    },
    {
      "name": "review-hashes-and-runtime-limit",
      "status": "passed"
    },
    {
      "name": "all-skill-local-references-resolve",
      "status": "passed"
    },
    {
      "name": "actionlint-release-version",
      "status": "passed"
    },
    {
      "name": "cache-cancellation-and-path-filter-syntax",
      "status": "passed"
    },
    {
      "name": "explicit-manual-maintenance-and-job-gate",
      "status": "passed"
    },
    {
      "name": "compatibility-matrix-and-job-dependencies",
      "status": "passed"
    },
    {
      "name": "unknown-github-context-rejected",
      "status": "passed"
    },
    {
      "name": "undefined-matrix-dimension-rejected",
      "status": "passed"
    },
    {
      "name": "missing-job-dependency-rejected",
      "status": "passed"
    },
    {
      "name": "dependency-cycle-rejected",
      "status": "passed"
    },
    {
      "name": "unsupported-permission-value-rejected",
      "status": "passed"
    },
    {
      "name": "conflicting-path-filters-rejected",
      "status": "passed"
    },
    {
      "name": "malformed-workflow-yaml-rejected",
      "status": "passed"
    }
  ],
  "lint_results": [
    {
      "case": "cache-cancellation-and-path-filter-syntax",
      "fixture_sha256": "62c2f3aba4e3f5fd474bdfc008034ca164f87e4e19601a0ac6ddd7bfbc0c1f36",
      "expected_valid": true,
      "exit_code": 0,
      "diagnostics": ""
    },
    {
      "case": "explicit-manual-maintenance-and-job-gate",
      "fixture_sha256": "880bdb1269a88cc69860a8d2bfa6a819a5f89d2385f5193c6ffc69a85126542c",
      "expected_valid": true,
      "exit_code": 0,
      "diagnostics": ""
    },
    {
      "case": "compatibility-matrix-and-job-dependencies",
      "fixture_sha256": "6c0a0a6f5490ba745e91796eee84343caeba2e46db38034b4cbc71957a7a1c6d",
      "expected_valid": true,
      "exit_code": 0,
      "diagnostics": ""
    },
    {
      "case": "unknown-github-context-rejected",
      "fixture_sha256": "fab232b5a6d7d8f61519f7f121b9a75d6f4a0d141022989b221fcf462a5ae883",
      "expected_valid": false,
      "exit_code": 1,
      "diagnostics": "unknown-github-context-rejected.yml:26:24: property \"bbskills_missing\" is not defined in object type {action: string; action_path: string; action_ref: string; action_repository: string; action_status: string; actor: string; actor_id: string; api_url: string; artifact_cache_size_limit: number; base_ref: string; env: string; event: object; event_name: string; event_path: string; graphql_url: string; head_ref: string; job: string; output: string; path: string; ref: string; ref_name: string; ref_protected: bool; ref_type: string; repository: string; repository_id: string; repository_owner: string; repository_owner_id: string; repository_visibility: string; repositoryurl: string; retention_days: number; run_attempt: string; run_id: string; run_number: string; secret_source: string; server_url: string; sha: string; state: string; step_summary: string; token: string; triggering_actor: string; workflow: string; workflow_ref: string; workflow_sha: string; workspace: string} [expression]"
    },
    {
      "case": "undefined-matrix-dimension-rejected",
      "fixture_sha256": "4809958c77608314fb65e96d9ce04d7d72312a8cdea6735abaf706b8511f97e8",
      "expected_valid": false,
      "exit_code": 1,
      "diagnostics": "undefined-matrix-dimension-rejected.yml:12:24: property \"runtime\" is not defined in object type {node: number} [expression]"
    },
    {
      "case": "missing-job-dependency-rejected",
      "fixture_sha256": "7d68aa477f460fe795fe76e29e6a4f593543fc34ffd904ea77c6481a22cb2883",
      "expected_valid": false,
      "exit_code": 1,
      "diagnostics": "missing-job-dependency-rejected.yml:13:3: job \"report\" needs job \"missing\" which does not exist in this workflow [job-needs]"
    },
    {
      "case": "dependency-cycle-rejected",
      "fixture_sha256": "f16f02c233d9ce8cf4f15d11f8972e079d648b8db2554a7cf9f3617fcfdadb49",
      "expected_valid": false,
      "exit_code": 1,
      "diagnostics": "dependency-cycle-rejected.yml:6:3: cyclic dependencies in \"needs\" job configurations are detected. detected cycle is \"compatibility\" -> \"report\" -> \"compatibility\" [job-needs]"
    },
    {
      "case": "unsupported-permission-value-rejected",
      "fixture_sha256": "0145e21a5acc93fc0ed5dce02444b45d832589882b473a90d7f2c61bcd0963f7",
      "expected_valid": false,
      "exit_code": 1,
      "diagnostics": "unsupported-permission-value-rejected.yml:12:13: \"admin\" is invalid as permission of scope \"contents\". available values are \"read\", \"write\", \"none\" [permissions]"
    },
    {
      "case": "conflicting-path-filters-rejected",
      "fixture_sha256": "7a0342e6b6f68021fa39768e44220ab1314b038510a2f49d15cfa89f2c4bed95",
      "expected_valid": false,
      "exit_code": 1,
      "diagnostics": "conflicting-path-filters-rejected.yml:9:5: both \"paths\" and \"paths-ignore\" filters cannot be used for the same event \"push\". note: use '!' to negate patterns [events]"
    },
    {
      "case": "malformed-workflow-yaml-rejected",
      "fixture_sha256": "4a512a7e992d838626f7256e7b96e8284bde92ecf861ad599d407bcd1c5830cd",
      "expected_valid": false,
      "exit_code": 1,
      "diagnostics": "malformed-workflow-yaml-rejected.yml:1:4: could not parse as YAML: did not find expected ',' or ']' [syntax-check]"
    }
  ],
  "actionlint_version": "1.7.12\ninstalled by downloading from release page\nbuilt with go1.26.1 compiler for linux/amd64",
  "checker_sha256": "c872d6db8c6bf83a8eaa704fc93999f027d55dffbc63b8a6abdccb47df5f4cd4",
  "checker_release_archive_sha256": "8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8",
  "probe_sha256": "08b9945c94105b615cc0fe95873517cd48701592cf24ddb48443d5cc0e5f1613",
  "batch_sha256": "4098ec6af057dfcea60064ac3160d3817917eed1b2880b50658c0002bcd8fdc9",
  "package_sha256": "43651931984fd91647ecfecf8a6aad6d6dcf1eeeae9c2a11f43b391cd840e108",
  "package_file_sha256": {
    "github-actions-efficiency/BB-SKILLS-REVIEW.json": "0c8473bd7bdd4d90a56b093f87c9aa952d625eb4ebecdebc905961df9d56f74d",
    "github-actions-efficiency/LICENSE.upstream.txt": "e32449d23085399adc1222f7a17408b730550258e51627c153cb108ca9955823",
    "github-actions-efficiency/SKILL.md": "9c41e860468e5c88d83ab6eec70c585b0f122facec2632ea65497b3389139e43",
    "github-actions-efficiency/SOURCE.md": "18dc6366bdc5fb7212547e7472b7e8321bcaa0db9b07b50907bc4a860dde73b9",
    "github-actions-efficiency/references/actions.md": "9f24153e0b743a978ec84e08bc64047616d18504965708cc7507437203689fdb",
    "github-actions-efficiency/references/patterns.md": "a9fb61ee95b5f2f4cb372064f5de9d04ca749da1b78d050e42e909e9e97228dd",
    "github-actions-efficiency/references/reporting.md": "18eec5acd0d9e52b450f86b8232e9994c5c5b7760240bcb2e97417f8a847508c",
    "github-actions-efficiency/references/review-rubric.md": "f2fd2bbd34f15f68664e30ea62468f8a5b19bc9b49929dcd082a4c87316b3ce2"
  },
  "source_commit": "143a3d976b3c1603cc8932984d5e1f28501cb5fc",
  "scope": "No AI client or GitHub workflow was run. Twenty named package-integrity and local actionlint observations on synthetic YAML only; this does not prove cache hits, stale-run cancellation, branch-protection coverage, CI minutes saved, complete security or model decisions.",
  "isolation": "Non-root UID 10001, network disabled, read-only container root, writable temporary /work and /tmp, 256 MiB memory, 1 CPU, no host repositories or credentials mounted.",
  "uid": 10001,
  "network_interfaces": [
    "lo"
  ],
  "image_id": "sha256:2e7d655c703892e5ec2d9913e58a973001d5cb88402c99f1e2fd3c541abcfff2"
}

Environment

Non-root UID 10001, network disabled, read-only container root, writable temporary /work and /tmp, 256 MiB memory, 1 CPU, no host repositories or credentials mounted. actionlint 1.7.12; image sha256:2e7d655c703892e5ec2d9913e58a973001d5cb88402c99f1e2fd3c541abcfff2.

Package SHA-256: 43651931984fd91647ecfecf8a6aad6d6dcf1eeeae9c2a11f43b391cd840e108

Outcome recorded: 2026-10-04 02:43 UTC

Community reviews

★ New

Be the first to share your experience.

Sign in to leave a review →

Guides using this resource

All guides →
Practical guide

Choose development skills by task, source and evidence

Choose development skills by the task you need to complete. A catalog category can narrow a search, but the original instructions, required tools and evidence for the current…

By BB Skills · Read guide →
Practical guide

Review GitHub Actions changes with an agent skill

Review GitHub Actions changes with an agent skill, preserve required checks, and separate local syntax evidence from measured CI improvements.

By BB Skills · Read guide →

More to explore

View all ↗