python-ci-setup

A setup guide for continuous integration and delivery (CI/CD), automated checks that run when Python code changes.

In plain words
What is it for?
Use it to create or repair a Python workflow, including checks across supported Python versions and optional publishing to PyPI.
Why use it?
It catches formatting, code-quality, type, test, security, build, and publishing problems before code is merged or released.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/woliveiras/geremmyas/python-ci-setup
Any agent
npx skills add woliveiras/geremmyas --skill python-ci-setup
Clone the repo
git clone --depth 1 https://github.com/woliveiras/geremmyas

Made for: Claude Code, Codex.

Per session 56 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,410 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00056 $0.01410
Opus 5 $0.00028 $0.00705
Sonnet 5 $0.00011 $0.00282
Haiku 4.5 $0.00006 $0.00141

Measured 2d ago against content hash e86f78b02901, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

python-ci-setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

content/skills/python-ci-setup/SKILL.md · 203 lines

How it starts

The opening of the file, as written. The whole thing — 203 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Python CI Setup

Multi-step workflow to create a production-grade Python CI pipeline.

When to Use

  • New Python project needs CI from scratch
  • Existing project has incomplete or fragile CI
  • Adding security scanning, multi-version testing, or Trusted Publishing

Pipeline Layers (in order)

Each layer gates the next. If a layer fails, the pipeline stops.

  1. Formatruff format --check . (or black --check .) must pass
  2. Lintruff check . (or flake8) must pass
  3. Type checkmypy src (or Pyright) must pass
  4. Testpytest with coverage threshold
  5. Security scanbandit -r src + pip-audit
  6. Buildpython -m build produces valid sdist/wheel
  7. Publish (optional) — Trusted Publishing to PyPI via OIDC

Steps

1. Choose CI Platform

Default to GitHub Actions for GitHub-hosted repositories. Ensure matrix testing across supported Python versions (3.11, 3.12, 3.13, 3.14).

2. Create Quality Workflow

For GitHub Actions: .github/workflows/ci.yml

name: CI
on:
  push:
    branches: [main]
  pull_request:
    branches: [main]

jobs:
  quality:
    runs-on: ubuntu-latest
    strategy:
      matrix:
        python-version: ["3.11", "3.12", "3.13", "3.14"]
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-python@v5
        with:
          python-version: ${{ matrix.python-version }}

      - run: python -m pip install -U pip
      - run: python -m pip install -e ".[dev]"

      - run: ruff format --check .
      - run: ruff check .
      - run: mypy src
      - run: pytest --tb=short
      - run: coverage run -m pytest && coverage report --fail-under=85
      - run: bandit -r src
      - run: pip-audit

3. Configure Tools in pyproject.toml

All tool configuration lives in pyproject.toml:

[tool.ruff]
line-length = 100
target-version = "py311"

[tool.ruff.lint]
select = ["E", "F", "I", "B", "UP"]

[tool.pytest.ini_options]
testpaths = ["tests"]
addopts = "-ra"

[tool.coverage.run]
branch = true
source = ["src/my_package"]

[tool.coverage.report]
fail_under = 85

[tool.mypy]
python_version = "3.11"
strict = true
mypy_path = ["src"]

[tool.bandit]
exclude_dirs = ["tests"]

Read the full file on GitHub · 203 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 203 lines · 56 tokens per session scan A e86f78b02901

Subscribe to this mod's changes

python-ci-setup is a skill published in the GitHub repository woliveiras/geremmyas (10 stars, last pushed 1mo ago), licensed MIT. It adds 56 tokens to every session and 1,410 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

simple-modern-uv

Start, selectively modernize, fully migrate, or update Python projects using simple-modern-uv practices: uv, ruff, BasedPyright, pytest, GitHub Actions CI, and tag-driven PyPI publishing. Use when creating a Python project; adding selected tooling or repository practices to an existing project; migrating from Poetry…

jlevy/simple-modern-uv · 98 tokens

scaffold-python

Scaffold a complete Python project with CI/CD, release pipeline, justfile, sr.yaml, pyproject.toml, .envrc, and standard files. Uses uv, ruff, and justfile (Python lacks a native task runner like pnpm scripts, so just fills that gap). Loads on top of scaffold-project (run that first for cross-language standard files).…

urmzd/dotfiles · 135 tokens

publish-python-package-pypi

Configure or troubleshoot PyPI publication for PDM packages with GitHub Actions and Trusted Publishing. Use this skill for the Python package in a mixed-language repository. Do not use it for applications or repositories without a Python distribution. Do not use it for generic CI, containers, or token uploads unless…

btfranklin/skills · 71 tokens

setup-python-project

Scaffold a new Python project with uv, ruff, pytest, and GitHub Actions CI. Use when the user says "set up a new Python project", "scaffold a project", "create a new Python app", or similar.

phobologic/claude_code_helpers · 53 tokens

python-project-workflow

Set up, inspect, preserve, and verify Python project workflows, including greenfield scaffolding, packaging, dependency and tool configuration, CI, compatibility contracts, mature automation repositories, and project-native validation. Use when the task affects repository-wide Python structure or workflow. Do not use…

CodeSigils/python-project-workflow-skill · 90 tokens

python-pip-ci

GitHub Actions workflow steps for Python projects using pip. Use this skill when generating CI workflows that need pip-based dependency installation with virtual environment.

DataRecce/recce-claude-plugin · 33 tokens