mit einem Klick
kinko
kinko enthält 10 gesammelte Skills von tacogips, mit Repository-Berufsabdeckung und Skill-Detailseiten auf SkillsMP.
Skills in diesem Repository
Execute kinko release operations end-to-end for Go binaries, including local verification, artifact packaging, and optional GitHub release publishing. Use when users ask to release, publish a version, or build release binaries.
Use when users want to manage encrypted environment variables with the kinko CLI, including init/unlock, shared vs repo scope, set/get/show/delete/move, stale path-scope pruning, export/import, and exec-based runtime injection.
Use when creating or organizing design documents. Provides directory structure, file naming, and content guidelines for design specs and references.
Use when writing, reviewing, or refactoring Go code. Provides error handling patterns, project layout, concurrency, and interface design guidelines.
Use when creating implementation plans from design documents. Provides plan structure, status tracking, and progress logging guidelines.
Use this skill when creating or modifying GitHub Actions workflow files (.github/workflows/*.yml). Ensures all actions are pinned by commit SHA, permissions are minimized, script injection is prevented, and other supply chain security best practices are applied.
Use when writing Go code that interacts with dependencies, handles credentials, executes commands, or manages configuration. Provides supply chain attack countermeasures at the code level including safe dependency usage, credential handling, subprocess hardening, and runtime integrity patterns. Adapted from Shai-Hulud npm attack lessons.
Use when adding, updating, or auditing Go module dependencies. Provides supply chain attack countermeasures including go.sum verification, GOPROXY hardening, govulncheck auditing, and CI/CD pipeline security. Adapted from Shai-Hulud npm attack lessons.
Use when publishing Go modules or managing module repositories. Provides supply chain attack countermeasures including version tagging security, repository access control, and CI/CD publishing pipelines. Adapted from Shai-Hulud npm attack lessons.
Use when updating GitHub authentication token scopes and re-registering the token into kinko shared secrets. Handles gh auth refresh, avoiding GITHUB_TOKEN env precedence, writing shared GITHUB_TOKEN, and hash-based verification.