What Does the Skill-Review Automated Check in CI/CD Verify?

The skill-review automated check verifies that every SKILL.md file contains mandatory structural fields, passes quality-bar rules for trigger specificity and command safety, and includes proper security metadata before allowing a pull request to merge.

The skill-review automated check serves as a critical quality gate in the sickn33/antigravity-awesome-skills repository. Triggered automatically for every pull request that adds or modifies a SKILL.md file, this GitHub Actions workflow enforces the Skill Quality Bar to ensure that only well-defined, secure skills are published.

How the Skill-Review Check Works in GitHub Actions

Workflow Trigger and Execution

The check is defined in .github/workflows/skill-review.yml and executes automatically when PRs add or modify any SKILL.md file. According to the repository documentation in README.md (lines 179-180), this ensures that skill-specific validation runs only when relevant content changes.

The Tesslio Skill-Review Action

At line 14 of the workflow file, the pipeline invokes the tesslio/skill-review action. This reusable component parses the changed SKILL.md files and runs a series of static analyses against the quality-bar criteria defined in docs/contributors/quality-bar.md.

What the Skill-Review Automated Check Verifies

Required Section Validation

The check ensures that every SKILL.md contains mandatory top-level fields including description, trigger, author, and version. As documented in docs/users/faq.md (lines 245-251), missing required sections are reported as hard errors that block merging.

Quality-Bar Rule Enforcement

The automated check validates that triggers are specific enough to avoid overly broad patterns like "*" that could match unintended inputs. It also verifies that example commands are safe and do not contain risky patterns such as uncontrolled rm -rf or curl | sh pipes.

Security and Risk Assessment

For skills that execute system commands or access sensitive resources, the check verifies the presence of a proper risk label and security-review metadata. This ensures that high-risk skills receive appropriate scrutiny before publication.

Anti-Pattern Detection

The workflow flags common structural issues including empty description fields, missing license declarations, duplicate sections, or malformed YAML front-matter that would prevent proper parsing.

Viewing and Debugging Skill-Review Results

When the check runs, it produces a concise job summary that appears under the Checks tab of the pull request. The tesslio/skill-review action generates output similar to this:

Checks ▶ skill‑review
────────────────────────────────────────────────────────────────
❌ Missing required field: “description”
⚠️ Trigger pattern too generic: “*”
✅ No risky commands detected
────────────────────────────────────────────────────────────────

To debug issues locally before submitting a PR, you can run the same validation logic using the action's Docker image:

docker run --rm \
  -v $(pwd)/skills/my‑skill/SKILL.md:/workspace/SKILL.md \
  ghcr.io/tesslio/skill-review:latest \
  /workspace/SKILL.md

This local execution produces output comparable to the CI job, allowing you to fix validation errors such as missing descriptions:


# Before: Missing description

name: my‑skill
trigger: |
  - "my‑skill"

# After: Valid SKILL.md

description: |
  A short description of what the skill does.
name: my‑skill
trigger: |
  - "my‑skill"

Summary

  • The skill-review automated check runs automatically on every PR that modifies SKILL.md files in the sickn33/antigravity-awesome-skills repository.
  • Defined in .github/workflows/skill-review.yml (line 14), it invokes the tesslio/skill-review action to enforce the Skill Quality Bar.
  • The check validates required sections (description, trigger, author, version), enforces trigger specificity, blocks risky command patterns, and requires security metadata for high-risk skills.
  • Results appear in the GitHub Checks tab, and contributors can reproduce validation locally using the Docker image to fix issues before submission.

Frequently Asked Questions

What triggers the skill-review automated check in CI/CD?

The check triggers automatically for any pull request that adds or modifies a SKILL.md file. This is configured in the workflow file .github/workflows/skill-review.yml to ensure skill-specific validation only runs when relevant content changes, as documented in the repository README (lines 179-180).

Which specific quality-bar rules does the skill-review check enforce?

According to the FAQ documentation (lines 245-251) and the quality-bar specification, the check enforces rules including mandatory field presence (description, trigger, author, version), trigger specificity (blocking overly broad patterns like "*"), command safety (detecting risky patterns like rm -rf or curl | sh), and required security metadata for high-risk skills.

How can I run the skill-review check locally before submitting a PR?

You can run the same validation logic locally using the tesslio/skill-review Docker image. Mount your SKILL.md file into the container and execute the review command. This produces output identical to the CI check, allowing you to fix validation errors such as missing descriptions or overly broad triggers before creating a pull request.

What happens if the skill-review check fails on my pull request?

If the check fails, it reports specific errors in the GitHub Checks tab under the skill-review job. Common failures include missing required fields, overly generic trigger patterns, or unsafe command examples. The PR cannot be merged until you edit the SKILL.md file to address all reported issues and the check re-runs successfully.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →