Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/woliveiras/geremmyas/python-ci-setupnpx skills add woliveiras/geremmyas --skill python-ci-setupgit clone --depth 1 https://github.com/woliveiras/geremmyasWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00056 | $0.01410 |
| Opus 5 | $0.00028 | $0.00705 |
| Sonnet 5 | $0.00011 | $0.00282 |
| Haiku 4.5 | $0.00006 | $0.00141 |
Grade A, and why
python-ci-setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 203 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Python CI Setup
Multi-step workflow to create a production-grade Python CI pipeline.
When to Use
- New Python project needs CI from scratch
- Existing project has incomplete or fragile CI
- Adding security scanning, multi-version testing, or Trusted Publishing
Pipeline Layers (in order)
Each layer gates the next. If a layer fails, the pipeline stops.
- Format —
ruff format --check .(orblack --check .) must pass - Lint —
ruff check .(orflake8) must pass - Type check —
mypy src(or Pyright) must pass - Test —
pytestwith coverage threshold - Security scan —
bandit -r src+pip-audit - Build —
python -m buildproduces valid sdist/wheel - Publish (optional) — Trusted Publishing to PyPI via OIDC
Steps
1. Choose CI Platform
Default to GitHub Actions for GitHub-hosted repositories. Ensure matrix testing across supported Python versions (3.11, 3.12, 3.13, 3.14).
2. Create Quality Workflow
For GitHub Actions: .github/workflows/ci.yml
name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
quality:
runs-on: ubuntu-latest
strategy:
matrix:
python-version: ["3.11", "3.12", "3.13", "3.14"]
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: ${{ matrix.python-version }}
- run: python -m pip install -U pip
- run: python -m pip install -e ".[dev]"
- run: ruff format --check .
- run: ruff check .
- run: mypy src
- run: pytest --tb=short
- run: coverage run -m pytest && coverage report --fail-under=85
- run: bandit -r src
- run: pip-audit
3. Configure Tools in pyproject.toml
All tool configuration lives in pyproject.toml:
[tool.ruff]
line-length = 100
target-version = "py311"
[tool.ruff.lint]
select = ["E", "F", "I", "B", "UP"]
[tool.pytest.ini_options]
testpaths = ["tests"]
addopts = "-ra"
[tool.coverage.run]
branch = true
source = ["src/my_package"]
[tool.coverage.report]
fail_under = 85
[tool.mypy]
python_version = "3.11"
strict = true
mypy_path = ["src"]
[tool.bandit]
exclude_dirs = ["tests"]
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 203 lines · 56 tokens per session scan A e86f78b02901
python-ci-setup is a skill published in the GitHub repository woliveiras/geremmyas (10 stars, last pushed 1mo ago), licensed MIT. It adds 56 tokens to every session and 1,410 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
simple-modern-uv
Start, selectively modernize, fully migrate, or update Python projects using simple-modern-uv practices: uv, ruff, BasedPyright, pytest, GitHub Actions CI, and tag-driven PyPI publishing. Use when creating a Python project; adding selected tooling or repository practices to an existing project; migrating from Poetry…
scaffold-python
Scaffold a complete Python project with CI/CD, release pipeline, justfile, sr.yaml, pyproject.toml, .envrc, and standard files. Uses uv, ruff, and justfile (Python lacks a native task runner like pnpm scripts, so just fills that gap). Loads on top of scaffold-project (run that first for cross-language standard files).…
publish-python-package-pypi
Configure or troubleshoot PyPI publication for PDM packages with GitHub Actions and Trusted Publishing. Use this skill for the Python package in a mixed-language repository. Do not use it for applications or repositories without a Python distribution. Do not use it for generic CI, containers, or token uploads unless…
setup-python-project
Scaffold a new Python project with uv, ruff, pytest, and GitHub Actions CI. Use when the user says "set up a new Python project", "scaffold a project", "create a new Python app", or similar.
python-project-workflow
Set up, inspect, preserve, and verify Python project workflows, including greenfield scaffolding, packaging, dependency and tool configuration, CI, compatibility contracts, mature automation repositories, and project-native validation. Use when the task affects repository-wide Python structure or workflow. Do not use…
python-pip-ci
GitHub Actions workflow steps for Python projects using pip. Use this skill when generating CI workflows that need pip-based dependency installation with virtual environment.