Helps with Prowler repository CI and PR gates (GitHub Actions workflows). Trigger: When investigating CI checks failing on a PR, PR title validation, changelog gate/no-changelog label, conflict marker checks, secret scanning, CODEOWNERS/labeler automation, or anything under .github/workflows.
التثبيت
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.
Helps with Prowler repository CI and PR gates (GitHub Actions workflows). Trigger: When investigating CI checks failing on a PR, PR title validation, changelog gate/no-changelog label, conflict marker checks, secret scanning, CODEOWNERS/labeler automation, or anything under .github/workflows.
license
Apache-2.0
metadata
{"author":"prowler-cloud","version":"1.0","scope":["root"],"auto_invoke":["Inspect PR CI checks and gates (.github/workflows/*)","Debug why a GitHub Actions job is failing","Understand changelog gate and no-changelog label behavior","Understand PR title conventional-commit validation","Understand CODEOWNERS/labeler-based automation"]}
allowed-tools
Read, Edit, Write, Glob, Grep, Bash
What this skill covers
Use this skill whenever you are:
Reading or changing GitHub Actions workflows under .github/workflows/
Auto labels: .github/workflows/labeler.yml and .github/labeler.yml
Review ownership: .github/CODEOWNERS
Debug checklist (PR failing checks)
Identify which workflow/job is failing (name + file under .github/workflows/).
Check path filters: is the workflow supposed to run for your changed files?
If it's a title check: verify PR title matches Conventional Commits.
If it's changelog: verify a valid fragment exists under the right <component>/changelog.d/ OR apply no-changelog label.
If it's conflict checker: remove <<<<<<<, =======, >>>>>>> markers.
If it's secrets (TruffleHog): see section below.
TruffleHog Secret Scanning
TruffleHog scans for leaked secrets. Common false positives in test files:
Patterns that trigger TruffleHog:
sk-*T3BlbkFJ* - OpenAI API keys
AKIA[A-Z0-9]{16} - AWS Access Keys
ghp_* / gho_* - GitHub tokens
Base64-encoded strings that look like credentials
Fix for test files:
# BAD - looks like real OpenAI key
api_key = "sk-test1234567890T3BlbkFJtest1234567890"# GOOD - obviously fake
api_key = "sk-fake-test-key-for-unit-testing-only"
If TruffleHog flags a real secret:
Remove the secret from the code immediately
Rotate the credential (it's now in git history)
Consider using .trufflehog-ignore for known false positives (rarely needed)
Notes
Keep prowler-pr focused on creating PRs and filling the template.
Use prowler-ci for CI policies and gates that apply to PRs.