prowler-cloud/prowler

prowler-ci

Helps with Prowler repository CI and PR gates (GitHub Actions workflows). conflict marker checks, secret scanning, CODEOWNERS/labeler automation, or anything under .github/workflows.

First seen Jan 20, 2026

Installation

$ npx skills add prowler-cloud/prowler --skill prowler-ci

Also in this package

Other skills from prowler-cloud/prowler · top by installs.

npx skills add prowler-cloud/prowler

Browse all from prowler-cloud/prowler

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 14.8K
License LICENSE
Default branch master
Open issues 142
Status Active

Skill metadata

Parsed from SKILL.md frontmatter.

Version1.0
LicenseApache-2.0
Allowed toolsRead, Edit, Write, Glob, Grep, Bash
More metadata
author
prowler-cloud
version
1.0
scope
["root"]
auto_invoke
["Inspect PR CI checks and gates (.github\/workflows\/*)","Debug why a GitHub Actions job is failing","Understand changelog gate and no-changelog label behavior","Understand PR title conventional-commit validation","Understand CODEOWNERS\/labeler-based automation"]

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 3,138 B
  • docs SUMMARY.md 311 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 69 installs

SKILL.md

What this skill covers

Use this skill whenever you are:

  • Reading or changing GitHub Actions workflows under .github/workflows/
  • Explaining why a PR fails checks (title, changelog, conflict markers, secret scanning)
  • Figuring out which workflows run for UI/API/SDK changes and why
  • Diagnosing path-filtering behavior (why a workflow did/didn't run)

Quick map (where to look)

  • PR template: .github/pullrequesttemplate.md
  • PR title validation: .github/workflows/conventional-commit.yml
  • Changelog gate: .github/workflows/pr-check-changelog.yml (requires a fragment under <component>/changelog.d/)
  • Changelog compile (release time): .github/workflows/compile-changelogs.yml
  • Conflict markers check: .github/workflows/pr-conflict-checker.yml
  • Secret scanning: .github/workflows/find-secrets.yml
  • Auto labels: .github/workflows/labeler.yml and .github/labeler.yml
  • Review ownership: .github/CODEOWNERS

Debug checklist (PR failing checks)

  1. Identify which workflow/job is failing (name + file under .github/workflows/).
  2. Check path filters: is the workflow supposed to run for your changed files?
  3. If it's a title check: verify PR title matches Conventional Commits.
  4. If it's changelog: verify a valid fragment exists under the right <component>/changelog.d/ OR apply no-changelog label.
  5. If it's conflict checker: remove <<<<<<<, =======, >>>>>>> markers.
  6. If it's secrets (TruffleHog): see section below.

TruffleHog Secret Scanning

TruffleHog scans for leaked secrets. Common false positives in test files:

Patterns that trigger TruffleHog:

  • sk-T3BlbkFJ - OpenAI API keys
  • AKIA[A-Z0-9]{16} - AWS Access Keys
  • ghp / gho - GitHub tokens
  • Base64-encoded strings that look like credentials

Fix for test files:

# BAD - looks like real OpenAI key
api_key = "sk-test1234567890T3BlbkFJtest1234567890"

# GOOD - obviously fake
api_key = "sk-fake-test-key-for-unit-testing-only"

If TruffleHog flags a real secret:

  1. Remove the secret from the code immediately
  2. Rotate the credential (it's now in git history)
  3. Consider using .trufflehog-ignore for known false positives (rarely needed)

Notes

  • Keep prowler-pr focused on creating PRs and filling the template.
  • Use prowler-ci for CI policies and gates that apply to PRs.