---
title: "protect-ci-workflows"
description: "Guard against an agent weakening the automated checks that review its own work. CI/CD workflow files (.github/workflows/), the composite actions they call (.github/actions/) and the dependency-update automation (.github/"
canonical: https://agentpluginsdirectory.com/plugins/protect-ci-workflows--open-coder-ai-3
last-updated: 2026-10-01
---

# protect-ci-workflows
Guard against an agent weakening the automated checks that review its own work. CI/CD workflow files (.github/workflows/), the composite actions they call (.github/actions/) and the dependency-update automation (.github/dependabot.yml) define what must pass before a change lands, so rewriting or deleting them is the agent removing the gate that would catch it. The guard refuses shell write-commands targeting those paths; reads pass, and tool-driven regeneration (chock sync) passes. Best-effort and deliberately coarse: the command line is parsed, and a write (a `>`/`>>` redirect, a writer verb like rm/mv/tee/sed -i, cp into the path, git checkout/restore, a PowerShell Set-Content/Add-Content/Out-File) must actually target the protected path; reading it passes. The 'chock: approved-config-change' marker is friction plus an audit trail, not authentication; the check an agent cannot self-approve is server-side branch protection.
- Slug: protect-ci-workflows--open-coder-ai-3
- Publisher: chock-core
- Repository: https://github.com/open-coder-ai/chock-copilot-plugins
- Manifest: agent-plugins/protect-ci-workflows/plugin.json
- Version: 0.1.0
- License: Apache-2.0
- Category (editorial): security
- Skills: 1 (protect-ci-workflows)
- MCP servers: 0
- Stars: 2
- Repository created: 2026-08-23
- Repository last pushed: 2026-09-30
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/protect-ci-workflows--open-coder-ai-3
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## Skills

- protect-ci-workflows: Guard against an agent weakening the automated checks that review its own work. CI/CD workflow files (.github/workflows/), the composite actions they call (.github/actions/) and the dependency-update automation (.github/dependabot.yml) define what must pass before a change lands, so a shell comma…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
