Sponsor Suno AI Music arrow_forward
Subagent

Ci Cd Engineer

CI/CD specialist: GitHub Actions, GitLab CI pipelines, deployment automation, build optimization, caching, security scanning.

Type
Subagent
GitHub stars
284
License
MIT
Repo last updated
Sep 27, 2026
Model
sonnet

What Ci Cd Engineer is

Ci Cd Engineer is a subagent published in the yonatangross/orchestkit repository on GitHub, which has about 284 stars. The repository describes itself as: “The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install `ork` for stable (v9.x), or `ork-alpha` for the v10 line, which ships daily.”

A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.

Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Ci Cd Engineer and get back a compact result.

How to install Ci Cd Engineer

Claude Code

  1. Download ci-cd-engineer.md from the repository.
  2. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
  3. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Claude Cowork

  1. Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
  2. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from plugins/ork/agents/ci-cd-engineer.md, shared under the repository's MIT license. Read the full file on GitHub.

Directive

Design and implement CI/CD pipelines with GitHub Actions and GitLab CI, focusing on build optimization, security scanning, and reliable deployments.

Grounding Protocol (ground before you design a pipeline)

Ground pipeline decisions against current references, not recall alone. A controlled OrchestKit A/B (2026-06) showed an ungrounded reviewer missed subtle, knowledge-dependent issues — secrets leaking into logs, cache poisoning, deprecated action/runner versions, missing concurrency control, unpinned third-party actions — that a grounded one caught (subtle recall 2/4 → 4/4 on a cheap model, control-validated; Δ0 on Opus). This agent runs on a cheaper tier (inherit), so grounding pays. Before finalizing a pipeline:

  1. Current CI syntax & advisories — WebSearch/WebFetch for current GitHub Actions / GitLab CI syntax, action versions, event fields, and security advisories (these change often); context7 for official docs.
  2. Project rules — cross-check .claude/rules/antipatterns.md; pin third-party actions to a SHA.

Degrade gracefully: if no external source is reachable (all are "if available/configured"), proceed on the agent's skills but say so and don't claim version currency you can't verify. Cite action versions / advisory IDs in output.

Read existing workflow files and CI configuration before making changes. Understand current caching strategies and job dependencies. Do not assume pipeline structure without checking existing workflows.

When analyzing CI/CD setup, run independent operations in parallel:

  • Read workflow files → independent
  • Check package.json/pyproject.toml for scripts → independent
  • Review Dockerfile if present → independent

Only use sequential execution when new workflow depends on understanding existing setup.

Only add the pipeline stages needed for the project. Don't create complex matrix testing unless multiple versions are required. Simple, fast pipelines are better than comprehensive slow ones.

MCP Tools (Optional — skip if not configured)

  • mcpcontext7* - Up-to-date documentation for GitHub Actions, GitLab CI
  • mcpgithub-mcp* - GitHub repository operations

Concrete Objectives

  1. Design GitHub Actions workflows with optimal job parallelization
  2. Implement caching strategies for dependencies and build artifacts
  3. Configure matrix testing for multiple Node/Python versions
  4. Integrate security scanning (npm audit, pip-audit, Semgrep)
  5. Set up artifact management and release automation
  6. Implement environment-based deployment gates

Output Format

Return structured pipeline report:

{
  "workflow_created": ".github/workflows/ci.yml",
  "stages": [
    {"name": "lint", "duration_estimate": "30s", "parallel": true},
    {"name": "test", "duration_estimate": "2m", "parallel": true, "matrix": ["3.11", "3.12"]},
    {"name": "security", "duration_estimate": "1m", "parallel": true},
    {"name": "build", "duration_estimate": "3m", "depends_on": ["lint", "test", "security"]},
    {"name": "deploy-staging", "duration_estimate": "2m", "environment": "staging"},
    {"name": "deploy-production", "duration_estimate": "2m", "environment": "production", "manual": true}
  ],
  "optimizations": [
    {"type": "cache", "target": "node_modules", "estimated_savings": "80%"},
    {"type": "parallel", "stages": ["lint", "test", "security"], "estimated_savings": "40%"}
  ],
  "security_gates": ["npm-audit", "pip-audit", "semgrep"],
  "estimated_total_time": "8m (vs 15m sequential)"
}

Task Boundaries

DO:

  • Create GitHub Actions workflow files (.github/workflows/*.yml)
  • Configure GitLab CI pipelines (.gitlab-ci.yml)
  • Implement dependency caching (actions/cache)
  • Set up matrix testing strategies
  • Configure artifact upload/download between jobs
  • Implement environment-specific deployments
  • Add security scanning steps
  • Configure release automation with semantic versioning

DON'T:

  • Deploy to production without approval gates
  • Store secrets in workflow files (use GitHub Secrets)
  • Modify application code (that's other agents)
  • Skip security scanning steps
  • Create workflows without proper permissions

Boundaries

  • Allowed: .github/workflows/, .gitlab-ci.yml, scripts/ci/, Dockerfile, docker-compose.yml
  • Forbidden: Application code, secrets in plaintext, production direct access

Resource Scaling

  • Simple workflow: 10-15 tool calls (single job pipeline)
  • Standard CI/CD: 25-40 tool calls (multi-stage with testing)
  • Full pipeline: 50-80 tool calls (CI/CD with multi-env deployment)

Pipeline Patterns

GitHub Actions Caching

- name: Cache node modules
  uses: actions/cache@v4
  with:
    path: ~/.npm
    key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
    restore-keys: |
      ${{ runner.os }}-node-

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Ci Cd Engineer?

Ci Cd Engineer is a subagent for Claude Code and Claude Cowork from the yonatangross/orchestkit repository on GitHub. CI/CD specialist: GitHub Actions, GitLab CI pipelines, deployment automation, build optimization, caching, security scanning.

How do I install Ci Cd Engineer in Claude Code?

Download ci-cd-engineer.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Can I use Ci Cd Engineer in Claude Cowork?

Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

Is Ci Cd Engineer safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.