Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/selvarajmurugesan90/ops-engineering-skillsnpx agentmods add skills/selvarajmurugesan90/ops-engineering-skills/gitea-actions-and-ciWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/selvarajmurugesan90/ops-engineering-skills/gitea-actions-and-ci)<a href="https://agentmods.dev/skills/selvarajmurugesan90/ops-engineering-skills/gitea-actions-and-ci"><img src="https://agentmods.dev/badge/skills/selvarajmurugesan90/ops-engineering-skills/gitea-actions-and-ci/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/selvarajmurugesan90/ops-engineering-skills/gitea-actions-and-ci"><img src="https://agentmods.dev/badge/skills/selvarajmurugesan90/ops-engineering-skills/gitea-actions-and-ci.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 3 findings, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Privilege Escalation · line 276 Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.Fix: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths.
- medium Agent Snooping · line 152 Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.Fix: Remove all code or instructions that list or read other skills' files or directories. Skills should operate independently; cross-skill access is a privilege escalation.
- medium Agent Snooping · line 282 Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.Fix: Remove all code or instructions that list or read other skills' files or directories. Skills should operate independently; cross-skill access is a privilege escalation.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00112 | $0.03176 |
| Opus 5 | $0.00056 | $0.01588 |
| Sonnet 5 | $0.00022 | $0.00635 |
| Haiku 4.5 | $0.00011 | $0.00318 |
Grade A, and why
gitea-actions-and-ci scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
and replaces it, where still needed, with a plain `curl` call against How it starts
The opening of the file, as written. The whole thing — 283 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Gitea Actions and CI
Purpose
Gitea Actions gives a self-hosted Gitea (or Forgejo) instance a CI system
that intentionally mirrors GitHub Actions' workflow YAML syntax
(.gitea/workflows/*.yml, on:/jobs:/steps:), executed by a
self-hosted act_runner rather than GitHub's managed runners. This
matters operationally because most GitHub Actions YAML is reusable with
caveats, but the caveats — a smaller set of built-in contexts, no
GitHub-hosted runner equivalent, different marketplace-action
compatibility, and a distinct runner registration/labeling model — cause
real friction when a team assumes full parity. This skill covers Gitea
Actions setup and specifically where it diverges from
github-actions-single-repo-workflows,
which this skill assumes as the baseline syntax reference.
When to use
- A team self-hosts Gitea (or Forgejo, a Gitea fork) and wants to enable built-in CI instead of bolting on an external Jenkins/Drone instance.
- Porting an existing GitHub Actions workflow to run on Gitea and hitting unsupported syntax, contexts, or marketplace actions.
- Setting up and registering a self-hosted
act_runneragainst a Gitea instance, or debugging why a workflow job never picks up a runner. - Deciding which third-party GitHub Actions marketplace actions are safe/ compatible to reuse on Gitea Actions versus needing a local reimplementation.
- Auditing self-hosted runner security posture, since every Gitea Actions runner is self-hosted by definition (no managed-runner option).
Prerequisites & environment
- A Gitea instance (1.19+ for Actions support; check Site Administration → Actions to confirm Actions is enabled instance-wide, since it's opt-in and off by default in older versions) or a Forgejo instance (Forgejo Actions is the same underlying design, forked from Gitea's).
- At least one act_runner binary or container registered against the instance — Gitea does not provide managed/hosted runners; every runner is infrastructure the team stands up and maintains itself.
- Docker (or another supported executor) on the runner host if workflows
use container-based steps/actions, since act_runner's default executor
model relies on Docker to run job containers, similar to
act(the local GitHub Actions runner it's derived from). - Repo or org admin access to enable Actions per-repository (Repository Settings → Actions) and to view/manage registered runners (Site Administration → Actions → Runners, or org/repo-level runner registration for scoped runners).
- Familiarity with GitHub Actions workflow YAML — see github-actions-single-repo-workflows for the baseline syntax this skill assumes.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 283 lines · 112 tokens per session scan A ed58aa9319df
gitea-actions-and-ci is a skill published in the GitHub repository selvarajmurugesan90/ops-engineering-skills (39 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 112 tokens to every session and 3,176 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
import-prom-rule
Bulk import of a Prometheus alert rule YAML file (create a whole set of rules at once). Dedicated to handling a remote URL or local YAML text, automatically parsing the three formats groups / a plain rules array / a single rule. ⚠️ Do not use this skill for single-rule creation — when the user describes a single alert…
chinese-git-workflow
A reference for configuring Git with Chinese code-hosting services such as Gitee, Coding.net, GitLab China, and CNB, including SSH, HTTPS, credentials, CI, and repository mirroring.
configure-env-variables
Configures environment variables for Power Pages site settings to support ALM across environments. Creates environment variable definitions in Dataverse, guides the user through linking site settings to those variables via the Power Pages Management app, adds the variables to the solution, and generates a…
atmos-profiles
Atmos profiles: profile directories, --profile and ATMOSPROFILE activation, profile merge behavior, environment switching, and routing profile-specific auth/toolchain/config overrides.
managing-github-actions-secrets
Creates and updates GitHub Actions secrets for PostHog workflows. Use when adding a new CI secret, rotating an existing secret, wiring a workflow to an API token, package registry credential, deploy key, or any value referenced via ${{ secrets. }} in .github/workflows/.
webhook-management
Configure and validate CCAM webhook targets across supported chat, incident, automation, and generic providers. Use when listing provider requirements, creating or updating a target, scoping it to alert rules, sending a test notification, reviewing delivery history, or deleting a target.