💻 Coding

GitHub Actions Workflow Map from Repo Inventory (No Invented Secrets)

Turn a repo inventory into a GitHub Actions workflow map only. No invented secrets, runner labels, or job IDs beyond the inventory.

0.0
0Reviews
P
September 12, 2026

Prompt

Act as a GitHub Actions CI engineer who only uses a pasted repo inventory. You write a workflow map the inventory already supports. You do not invent secrets, runner labels, job IDs, or artifact URLs. This is not a live GitHub API sync and not a security audit report.
You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs.

Inputs:
- Repo inventory I lock (workflow stubs, job cues, trigger notes): [Inventory]
- Actions / runner version notes I lock: [Version]
- Repo or org label I may quote (or UNKNOWN): [Workspace]
- Required workflow or job names I may quote (or UNKNOWN): [SpecNames]
- Workflow names already present (or UNKNOWN): [WorkflowNames]
- Job labels already present (or UNKNOWN): [JobLabels]
- Trigger labels already present (or UNKNOWN): [TriggerLabels]
- Words I must not use: [Banned]
- What I must never invent (secrets, runner labels, job IDs, artifact URLs): [Never]
- Output format: [Format]
- Language: [Lang]

Generate:
1. Honesty ledger: Inventory nouns, Version, Workspace, SpecNames, WorkflowNames, JobLabels, TriggerLabels, Lang. Forbidden: invented secrets, runner labels, job IDs, artifact URLs. Banner: not a live GitHub API sync; not a security audit report.
2. Workflow map table: one row per Inventory workflow stub or job cue. Missing trigger notes write NOT IN INPUTS. Use GitHub Actions workflows, jobs, steps, and events language when Inventory supports it. Quote WorkflowNames and JobLabels only when present.
3. Spec name set: only names in SpecNames. Unnamed workflows stay NOT IN INPUTS. Never print secret or runner-label VALUES not in Inventory.
4. Version lock: print Version. Refuse Actions features newer than Version if Version is named.
5. Refuse list: inventing secrets, inventing runner labels, inventing job IDs, inventing artifact URLs.
6. Compliance pass: quote Banned and Never hits. Cut them. Format as Format.

Constraints:
- Map from Inventory only. No invented secret VALUES. Teach GitHub Actions workflow mapping, not a generic Jenkins or CircleCI swap.
- Honor Version. No emojis.

Instructions

Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.

Generated Output

This image was generated using the prompt above.

GitHub Actions Workflow Map from Repo Inventory (No Invented Secrets) - Result

Examples

Example Input

Inventory: workflow Harbor Quay Cleat CI as pasted job cue Cleat Lint as pasted trigger note pull_request as pasted; workflow River Ops Gate Deploy as pasted job cue Gate Build as pasted. Secret NOT IN INPUTS. Runner invent NONE.
Version: GitHub Actions ubuntu-22.04 as pasted (do not invent unreleased Actions APIs)
Workspace: Harbor Quay Actions Repo as pasted
SpecNames: Cleat CI as pasted; Gate Deploy as pasted. Nightly UNKNOWN.
WorkflowNames: Cleat CI as pasted; Gate Deploy as pasted. Archive UNKNOWN.
JobLabels: Cleat Lint as pasted; Gate Build as pasted. Hotfix UNKNOWN.
TriggerLabels: pull_request as pasted. schedule UNKNOWN.
Banned: guaranteed secret, runner invent, job id invent, artifact invent
Never: invent secrets, invent runner labels, invent job IDs, invent artifact URLs
Format: ledger + table + specs + version + refuse + compliance
Lang: English

Example Output

1. Ledger. Inventory: workflow Harbor Quay Cleat CI job cue Cleat Lint trigger note pull_request; workflow River Ops Gate Deploy job cue Gate Build. Secret NOT IN INPUTS. Runner invent NONE. Version GitHub Actions ubuntu-22.04 as pasted. Workspace Harbor Quay Actions Repo. SpecNames Cleat CI; Gate Deploy; Nightly UNKNOWN. WorkflowNames Cleat CI; Gate Deploy; Archive UNKNOWN. JobLabels Cleat Lint; Gate Build; Hotfix UNKNOWN. TriggerLabels pull_request; schedule UNKNOWN. Lang English. Banner: not a live GitHub API sync; not a security audit report. Forbidden: invented secrets, runner labels, job IDs, artifact URLs, guaranteed secret, runner invent, job id invent, artifact invent.

2. Workflow map.
1. Harbor Quay Cleat CI | workflow Cleat CI as pasted (WorkflowNames) | Cleat Lint as pasted (JobLabels) | pull_request as pasted (TriggerLabels) | secret NOT IN INPUTS | Runner NONE | GitHub Actions workflow map only.
2. River Ops Gate Deploy | workflow Gate Deploy as pasted (WorkflowNames) | Gate Build as pasted (JobLabels) | trigger note beyond pull_request NOT IN INPUTS | secret NOT IN INPUTS | Runner NONE.
Hotfix not printed beyond JobLabels. schedule not invented beyond TriggerLabels. Archive not invented beyond WorkflowNames.

3. Spec name set. Cleat CI; Gate Deploy as SpecNames. Nightly UNKNOWN so write Nightly NOT IN INPUTS. No secret VALUES beyond Inventory. No third workflow invented.

4. Version lock. GitHub Actions ubuntu-22.04 as pasted. Unreleased features beyond Version not used. Credential path NOT IN INPUTS.

5. Refuse. Secrets invent: refused. Runner labels invent: refused. Job IDs invent: refused. Artifact URLs invent: refused. Guaranteed secret: refused.

6. Compliance. Banned hits none. Format ledger+table+specs+version+refuse+compliance. Gaps: Nightly decision, Archive WorkflowNames, Hotfix JobLabels, schedule TriggerLabels, credential path if any.

Missing-data policy: if a field was blank, write NOT IN INPUTS rather than guessing. Lock any tool version named in Inputs; if unnamed, write unknown. No invented testimonials, star ratings, or press logos. If legal, clinical, insurance, HR, education-plan, or veterinary content appears, add a one-line not-advice and de-identify banner. Quote banned-word hits and cut them. End with a gaps list of five bullets the user still owes you. Character and byte caps in the job are hard; print counts when relevant. Refuse to backfill DOIs, exam dumps, PHI, PII, or compensation promises not in Inputs.

Reviews (0)

Please login to leave a review.
Loading reviews...