💻 Coding

GitHub Actions Workflow Job Map from YAML Inventory (No Invented Secrets)

Map GitHub Actions workflow jobs from a YAML inventory only. No invented secrets, tokens, or environment credentials beyond the inventory.

0.0
0Reviews
P
September 8, 2026

Prompt

Act as a GitHub Actions CI aide who only uses a pasted workflow YAML inventory. You write a workflow job map the inventory already supports. You do not invent secrets, PATs, deploy keys, or environment credentials. This is not a live workflow dispatch and not a security audit opinion.
You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs.

Inputs:
- Workflow YAML inventory I lock (job labels, step stubs, runner notes): [Inventory]
- Actions / runner version notes I lock: [Version]
- Repository label I may quote (or UNKNOWN): [Repo]
- Required job names I may quote (or UNKNOWN): [JobNames]
- Words I must not use: [Banned]
- What I must never invent (secrets, PATs, deploy keys, environment credentials): [Never]
- Output format: [Format]
- Language: [Lang]

Generate:
1. Honesty ledger: Inventory nouns, Version, Repo, JobNames, Lang. Forbidden: invented secrets, PATs, deploy keys, environment credentials. Banner: not a live workflow dispatch; not a security audit opinion.
2. Workflow job map table: one row per Inventory job or step stub. Missing runner notes write NOT IN INPUTS.
3. Job name set: only names in JobNames. Unnamed jobs stay NOT IN INPUTS. Never print secret VALUES or token strings.
4. Version lock: print Version. Refuse Actions objects newer than Version if Version is named.
5. Refuse list: inventing secrets, inventing PATs, inventing deploy keys, inventing environment credentials.
6. Compliance pass: quote Banned and Never hits. Cut them. Format as Format.

Constraints:
- Map jobs from Inventory only. No invented secret VALUES.
- Honor Version. No emojis.

Instructions

Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.

Generated Output

This image was generated using the prompt above.

GitHub Actions Workflow Job Map from YAML Inventory (No Invented Secrets) - Result

Examples

Example Input

Inventory: job Harbor Quay Build as pasted step stub checkout as pasted runner note ubuntu-22.04 as pasted; job River Ops Deploy as pasted step stub upload-artifact as pasted. Secret NOT IN INPUTS. PAT NONE.
Version: GitHub Actions as pasted (do not invent unreleased reusable-workflow fields)
Repo: harbor-quay/ops-ci as pasted
JobNames: Harbor Quay Build as pasted; River Ops Deploy as pasted. lint-matrix UNKNOWN.
Banned: guaranteed secret, pat invent, deploy key invent, credential invent
Never: invent secrets, invent PATs, invent deploy keys, invent environment credentials
Format: ledger + table + jobs + version + refuse + compliance
Lang: English

Example Output

1. Ledger. Inventory: job Harbor Quay Build step stub checkout runner note ubuntu-22.04; job River Ops Deploy step stub upload-artifact. Secret NOT IN INPUTS. PAT NONE. Version GitHub Actions. Repo harbor-quay/ops-ci. JobNames Harbor Quay Build; River Ops Deploy; lint-matrix UNKNOWN. Lang English. Banner: not a live workflow dispatch; not a security audit opinion. Forbidden: invented secrets, PATs, deploy keys, environment credentials, guaranteed secret, pat invent, deploy key invent, credential invent.

2. Workflow job map.
1. Harbor Quay Build | step checkout as pasted | runner ubuntu-22.04 as pasted | secret NOT IN INPUTS | PAT NONE.
2. River Ops Deploy | step upload-artifact as pasted | runner NOT IN INPUTS | secret NOT IN INPUTS | PAT NONE.
Deploy keys not printed. Environment credentials not invented.

3. Job name set. Harbor Quay Build; River Ops Deploy as JobNames. lint-matrix UNKNOWN so write lint-matrix NOT IN INPUTS. No secret VALUES printed. No third job invented.

4. Version lock. GitHub Actions as pasted. Unreleased reusable-workflow fields not used. OIDC trust policy NOT IN INPUTS.

5. Refuse. Secret invent: refused. PAT invent: refused. Deploy key invent: refused. Credential invent: refused. Guaranteed secret: refused.

6. Compliance. Banned hits none. Format ledger+table+jobs+version+refuse+compliance. Gaps: runner for River Ops Deploy, lint-matrix decision, environment names, concurrency group, artifact retention if any.

Missing-data policy: if a field was blank, write NOT IN INPUTS rather than guessing. Lock any tool version named in Inputs; if unnamed, write unknown. No invented testimonials, star ratings, or press logos. If legal, clinical, insurance, HR, education-plan, or veterinary content appears, add a one-line not-advice and de-identify banner. Quote banned-word hits and cut them. End with a gaps list of five bullets the user still owes you. Character and byte caps in the job are hard; print counts when relevant. Refuse to backfill DOIs, exam dumps, PHI, PII, or compensation promises not in Inputs.

Reviews (0)

Please login to leave a review.
Loading reviews...