跳到主要内容
知仓学习社ZHICANG

devops-workflow-engineer

>

读凭据执行命令联网写文件严重 1 · 高危 0borghei/Claude-Skills

它会碰到什么

扫了多少10 个文本文件,160 KB
它会碰到什么读凭据执行命令联网写文件
命中总数12 处
命中统计严重 1 · 高 0 · 中 6 · 低 0
逐条看命中(1 条严重或高危)
  • 严重 scripts/workflow_generator.py:132cred-paths
    echo "${{ secrets.KUBECONFIG }}" | base64 -d > $HOME/.kube/config

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

DevOps Workflow Engineer

Generate GitHub Actions workflow YAML, analyze existing pipelines for optimization opportunities, and create deployment plans with strategy selection, health checks, and rollback procedures.

Core Capabilities

  • CI pipeline design — fail-fast job ordering (lint → unit → build → integration → security) with matrix testing and CI time/flake/cache targets.
  • CD & multi-environment — dev/staging/prod promotion flows, build-once-deploy-everywhere, environment protection rules, and rollback at every stage.
  • Pipeline optimization — detect missing caching, missing timeouts, serial chains, deprecated actions, leaked secrets, and oversized runners; apply path filtering and concurrency cancellation.
  • Deployment strategies — choose blue-green, canary, or rolling via decision tree; canary traffic-split schedule with promotion gates.
  • GitHub Actions patterns — reusable workflows, OIDC auth, secrets hierarchy, and runner cost estimation.

When to Use

  • Designing a new CI or CD workflow from scratch.
  • Planning a multi-environment (dev/staging/prod) deployment.
  • Optimizing an existing pipeline's cost or runtime.
  • Implementing a blue-green, canary, or rolling deployment strategy.

Clarify First

Before generating the workflow, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • [ ] Workflow type — CI, CD, release, or security-scan (sets workflow_generator.py --type)
  • [ ] Stack — language and test framework (e.g. python/pytest) (drives the generated YAML steps via --language/--test-framework)
  • [ ] Deployment strategy & environments — blue-green, canary, or rolling, and which of dev/staging/prod (drives the deployment_planner.py plan)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.

Tools

| Tool | Purpose | Command |

|------|---------|---------|

| workflow_generator.py | Generate GitHub Actions YAML (ci, cd, release, security-scan, docs-check) | python scripts/workflow_generator.py --type ci --language python --test-framework pytest |

| pipeline_analyzer.py | Analyze workflows for optimization findings, cost estimates, severity ratings | python scripts/pipeline_analyzer.py .github/workflows/ --format json |

| deployment_planner.py | Generate a deployment plan with strategy, health checks, rollback | python scripts/deployment_planner.py --type webapp --environments dev,staging,prod --strategy canary |

All tools support --format json and --output/-o for file writing.

References

Load the reference that matches the task — keep this file lean and pull detail on demand:

  • [references/workflows-and-optimization.md](references/workflows-and-optimization.md) — the CI / CD / optimization workflows with full YAML, deployment-strategy decision tree and canary schedule, GitHub Actions patterns, runner cost table, anti-patterns, and troubleshooting. Read when building or tuning a pipeline.
  • [references/github-actions-patterns.md](references/github-actions-patterns.md) — deep GitHub Actions pattern library. Read when authoring advanced workflow YAML.
  • [references/deployment-strategies.md](references/deployment-strategies.md) — deep deployment strategy guide (blue-green, canary, rolling). Read when planning a release rollout.
  • [references/agentic-workflows-guide.md](references/agentic-workflows-guide.md) — agentic/automated workflow patterns. Read when wiring up AI-driven or autonomous pipeline steps.

Integration Points

| Skill | Integration |

|-------|-------------|

| release-orchestrator | Release workflows align with versioning and changelog |

| senior-devops | Deployment strategies complement infra automation |

| senior-secops | Security scanning steps feed SecOps dashboards |

| senior-qa | CI quality gates map to QA acceptance criteria |

| incident-commander | Rollback procedures connect to incident playbooks |

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。