npx skills add ...
npx skills add bitwarden/ai-plugins --skill workflow-audit
npx skills add bitwarden/ai-plugins --skill workflow-audit
Run the Bitwarden workflow linter (bwwl) against one or more repos and report findings. Strictly read-only — does not modify any files. Categorizes findings as mechanical or judgment using the bitwarden-workflow-linter-rules skill. Supports single repo, multiple repos, or single file/directory scope.
Check if bwwl is available:
If the command is not found, stop and inform the user that bwwl must be installed before continuing. Do not attempt to install it.
Parse the user's request to determine what to lint:
.github/workflows/build.yml or .github/workflows/): Operate on the current repo only.<base-dir>/<repo>. If a clone is not found, inform the user and skip that repo..github/workflows/ of the current directory.For each repo in scope, run:
Capture both stdout and stderr. If operating on multiple repos, announce which repo is being linted.
From the linter output, produce a structured list of findings. Group by file and rule. Consult the bitwarden-workflow-linter-rules skill to categorize each finding:
Mechanical (can be auto-fixed):
name_capitalized, permissions_exist, pinned_job_runner, step_pinned, underscore_outputs, job_environment_prefix, check_pr_targetrun_actionlint findings (single-line shell fixes)Judgment (requires user input):
name_exists, step_approved, complex run_actionlint findingsOutput a summary table per repo:
| File | Finding | Rule | Category |
|---|---|---|---|
| ... | ... | ... | ... |
Include totals: mechanical findings, judgment findings, and repos with no issues.
Inform the user that they can use the workflow-fix skill to apply fixes based on these findings.