github-actions-efficiency
Audit GitHub Actions workflow efficiency and recommend fixes to reduce CI minutes and costs.
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
GitHub Actions Efficiency
Use this skill as a lean entrypoint for GitHub Actions efficiency work. Inspect the repo, identify the waste source, and load only the reference material needed for the current task.
If no workflows exist yet, load [references/actions.md](./references/actions.md) and define a baseline before proceeding with the steps below.
If shell or gh CLI access is unavailable: ask the user to paste .github/workflows/ contents and gh run list --limit 10 output. If only partial files are provided, note it: "Audit based on provided files only; some insights may be incomplete." Begin responses from files alone with: "Static-only analysis (not confirmed with live runs)."
Use This Skill When
- The user wants to reduce GitHub Actions runtime, CI cost, or wasted workflow runs.
- The repo has existing workflows in
.github/workflows/or explicit GitHub Actions configuration questions. - The user asks for caching, concurrency, path filters, matrix reduction, job optimization, or workflow-specific fixes.
- The user needs help creating a new GitHub Actions workflow or CI baseline from scratch.
Load Only What You Need
- [
references/actions.md](./references/actions.md) — audits, job gating, matrix reduction, live validation, and workflow-specific fixes. - [
references/reporting.md](./references/reporting.md) — when the user asks for a before/after efficiency report. - [
references/patterns.md](./references/patterns.md) — full YAML examples when inline audit commands are not enough.
Core Workflow
1. Measure first
rg -n "on:|concurrency:|paths:|paths-ignore:|strategy:|matrix:|cache:" .github/workflows
gh run list --limit 10
run_id=$(gh run list --limit 1 --json databaseId --jq '.[0].databaseId')
gh run view "$run_id" --log-failed
Look for: missing dependency caches, missing concurrency cancellation, over-broad triggers, duplicate workflow coverage, and expensive jobs that run on every change regardless of scope.
2. Apply guardrails
Check each proposed fix against these rules before recommending it:
- Does not hide required validation — drop any fix that removes release, schema, migration, or shared-library checks.
- Does not reduce parallelism without justification — drop unless the user prioritised cost over latency and the new critical path stays within 1.25× the original.
- Preserves only documented matrix legs — drop matrix legs with no explicit version or platform commitment.
- Write-back jobs use opt-in triggers — flag (do not drop) formatter or bot jobs that run automatically; recommend an opt-in trigger instead.
- Repo changes stay separate from org settings — split any fix that mixes repo-editable YAML with org-level or GitHub-account settings into two distinct recommendations.
3. Select the top 3 fixes
From the six candidates below, keep only those supported by audit evidence from step 1 and passing all guardrails from step 2. Rank survivors by estimated daily CI minutes saved (per-run savings × runs per day). Select all candidates that meet both criteria, up to a maximum of 3.
- Add dependency caching with lockfile-based keys
- Add or correct
concurrencycancellation - Remove duplicate workflow coverage before merging jobs
- Narrow workflow or job triggers safely
- Reduce matrix breadth to match risk and event type
- Parallelize independent jobs on the critical path
4. Verify
- If
ghCLI access is available, validate path-gating and concurrency cancellation with a live test push on a non-protected branch. - If live validation is not possible, state that explicitly in the output.
- Treat unexpected live behavior as a real bug even when the YAML looks correct.
Required Output
- Waste sources — top cost or latency drivers found in step 1
- Proposed fixes — top 3 (or all remaining) with supporting audit evidence
- Validation — what was proven live, what was checked locally only, and any remaining risk
- Impact — expected savings vs. measured savings; separate PR wall-clock time from total runner time
References
- [
references/actions.md](./references/actions.md) - [
references/reporting.md](./references/reporting.md) - [
references/patterns.md](./references/patterns.md) - [
references/review-rubric.md](./references/review-rubric.md) — load when reviewing completed efficiency work
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。