configure-reusable-workflows

v2026.09.24

Pre-built Claude PR scans as claude-*.yml callers of the reusable security, quality and a11y workflows. Use when adding OWASP, secret, code-smell or WCAG review to pull requests.

GitHub
Install command
npx skhub add laurigates/configure-reusable-workflows
Markdown
SKILL.md

/configure:reusable-workflows

Install Claude-powered reusable GitHub Actions workflows from claude-plugins into a project.

When to Use This Skill

Use this skill when...Use another approach when...
Adding Claude-powered reusable workflows for security, quality, or accessibilitySetting up standard CI/CD workflows (use /configure:workflows)
Installing pre-built workflow callers from claude-pluginsWriting custom GitHub Actions workflows from scratch
Automating OWASP, secret scanning, or code smell detection via CIConfiguring local security scanning tools (use /configure:security)
Adding WCAG accessibility checks to pull request pipelinesRunning one-off accessibility audits manually
Bootstrapping a full suite of Claude-powered CI checks across categoriesOnly need to check existing workflow compliance

Context

  • Workflows dir: !find . -maxdepth 1 -type d -name \'.github/workflows\'
  • Existing callers: !find . -path '*/.github/workflows/*' -maxdepth 3 -name 'claude-*'
  • Package files: !find . -maxdepth 1 \( -name 'package.json' -o -name 'pyproject.toml' -o -name 'Cargo.toml' -o -name 'go.mod' \) -print -quit
  • TypeScript files: !find . -maxdepth 2 \( -name '*.ts' -o -name '*.tsx' \) -print -quit
  • Component files: !find . -maxdepth 3 \( -name '*.jsx' -o -name '*.vue' -o -name '*.svelte' \) -print -quit

Parameters

Parse from command arguments:

  • --all: Install all workflows
  • --security: Install security workflows only
  • --quality: Install quality workflows only
  • --a11y: Install accessibility workflows only
  • --list: List available workflows without installing

Available Workflows

Security

WorkflowDescriptionFile
secretsDetect leaked secrets and credentialsreusable-security-secrets.yml
owaspOWASP Top 10 vulnerability scanningreusable-security-owasp.yml
depsDependency vulnerability auditreusable-security-deps.yml

Quality

WorkflowDescriptionFile
typescriptTypeScript strictness analysisreusable-quality-typescript.yml
code-smellCode smell detectionreusable-quality-code-smell.yml
asyncAsync/await pattern issuesreusable-quality-async.yml

Accessibility

WorkflowDescriptionFile
wcagWCAG 2.1 compliance checkingreusable-a11y-wcag.yml
ariaARIA pattern validationreusable-a11y-aria.yml

Execution

Execute this reusable workflow installation:

Step 1: Detect current state

  1. Check for .github/workflows/ directory (create if missing)
  2. List any existing Claude-powered workflow callers
  3. Determine project type from files present

Step 2: Select workflows

If no flags provided, ask the user which categories to install:

Available workflow categories:
  [1] Security (secrets, owasp, deps)
  [2] Quality (typescript, code-smell, async)
  [3] Accessibility (wcag, aria)
  [4] All workflows

Which categories? (comma-separated, e.g., 1,2):

If --list is set, print the Available Workflows tables above and stop.

Step 3: Generate caller workflows

For each selected workflow, create a caller file in .github/workflows/.

Filename convention: claude-<category>-<name>.yml

Example: claude-security-secrets.yml

Display name convention: The workflow's name: follows <Domain>: <Action> [<target>] (quoted because YAML treats : as a key separator). For these reusable callers, Claude: is the right domain. See .claude/rules/workflow-naming.md for the canonical rule and active domains. Example: name: "Claude: Security secrets".

Use the caller workflow template:

name: "Claude: <Action> <target>"

on:
  pull_request:
    branches: [main]
  workflow_dispatch:

permissions:
  contents: read
  pull-requests: write
  id-token: write

jobs:
  check:
    uses: laurigates/.github/.github/workflows/reusable-<category>-<name>.yml@main
    with:
      # Default inputs - customize as needed
      max-turns: 5
    secrets: inherit

For complete caller workflow files per category, see REFERENCE.md.

Step 4: Remind about secrets

After installation, print the required secret configuration:

Required secret: CLAUDE_CODE_OAUTH_TOKEN

To configure:
1. Go to repository Settings > Secrets and variables > Actions
2. Add secret: CLAUDE_CODE_OAUTH_TOKEN
3. Value: Your Claude Code OAuth token

Get token from: https://console.anthropic.com/

Customization

After installation, users can customize:

InputPurposeExample
file-patternsFiles to scan'src/**/*.ts'
max-turnsClaude analysis depth3 (quick) to 10 (thorough)
fail-on-*Block merges on findingstrue / false
wcag-levelAccessibility standard'A', 'AA', 'AAA'

Post-Installation

  1. Configure secret: Add CLAUDE_CODE_OAUTH_TOKEN to repository secrets
  2. Customize patterns: Edit file-patterns to match project structure
  3. Adjust triggers: Modify paths filters for relevant file types
  4. Test manually: Use workflow_dispatch to test before PR triggers

Agentic Optimizations

ContextCommand
List available workflows/configure:reusable-workflows --list
Install all workflows at once/configure:reusable-workflows --all
Security workflows only/configure:reusable-workflows --security
Quality workflows only/configure:reusable-workflows --quality
Accessibility workflows only/configure:reusable-workflows --a11y
Check existing callersfind .github/workflows -name 'claude-*' -type f

Flags

FlagDescription
--allInstall all workflows
--securityInstall security workflows only
--qualityInstall quality workflows only
--a11yInstall accessibility workflows only
--listList available workflows without installing

See Also

  • /configure:workflows - Standard CI/CD workflows (container, release-please)
  • /configure:security - Security tooling configuration
  • ci-workflows skill - Workflow patterns
Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

configure-plugin/skills/configure-reusable-workflows

Default branch

main

Latest commit

1668324

Tree SHA

b2d4cc3