Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Integrate CAST AI policy validation and cost checks into CI/CD pipelines. Use when adding CAST AI savings verification to GitHub Actions, validating Terraform plans, or gating deployments on cost thresholds. Trigger with phrases like "cast ai CI", "cast ai github actions", "cast ai terraform CI", "cast ai pipeline".
.claude/skills/jeremylongshore-castai-ci-integration/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | -4% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 2% | 0% |
| case-05 | ✗→✓ | ▲ Improved | 23% | 0% |
| case-08 | ✗→✓ | ▲ Improved | 32% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 14% | 0% |
Keep pull-request checks local and credential-free. Validate syntax, rendered Kubernetes objects, policy invariants, and destructive change boundaries before allowing a separately protected job to inspect a real CAST AI environment.
Use Read and Grep to identify fork execution, secret references, Terraform backends, generated plans, Helm values, kubeconfig use, and direct CAST AI calls. Classify each check as offline, protected read-only, or prohibited.
Use Bash(terraform:_) for formatting, initialization without applying, validation, and a saved plan. Use Bash(helm:_) to lint or template the pinned chart and Bash(kubectl:\) only for client-side schema validation against rendered manifests. Treat unexpected resource deletion, provider replacement, cluster disconnect, automation enablement, or HPA ownership transfer as review-blocking changes.
Use Write or Edit to add deterministic checks for approved regions, cluster identifiers, policy names, node-template bounds, workload automation modes, protected namespaces, disruption budgets, and maximum CPU limits. Reject deprecated cluster minimum CPU settings and unreviewed wildcard scope.
If live evidence is required, place it in an independent protected-environment job that cannot run for forks. Use a dedicated read-only organization-scoped identity, a pinned CAST AI region, a fixed cluster allowlist, a short timeout, and redacted output. Prefer a documented status read; never enable automation or apply infrastructure from the probe.
Run the workflow with missing and sentinel credentials. Confirm the offline lane stays green, the live lane skips safely, logs contain no key or raw cluster inventory, and plan artifacts have restricted retention.
Use Read and Grep for workflow and configuration inspection. Use Write and Edit for checks and workflow changes. Use Bash(terraform:_), Bash(helm:_), Bash(kubectl:_), and Bash(castctl:_) only for their documented validation or dry-run operations; do not apply, connect, disconnect, or mutate a live cluster without a separate approved change window.
A pull request renders the pinned CAST AI chart, validates Terraform, and rejects a new HPA ownership transfer. A release job may inspect one approved cluster only after environment approval and records status classes rather than raw API payloads.
| Failure | Meaning | Response | | ----------------------------------------- | --------------------------------- | ----------------------------------------------------- | | A fork can read a CAST AI key | CI trust boundary failed | Disable the live job and rotate the exposed identity | | A plan enables automation unexpectedly | Change exceeds reviewed intent | Block and require an explicit policy review | | Offline checks need the network | Required lane is nondeterministic | Pin fixtures and local schemas | | A rendered object transfers HPA ownership | Workload control may change | Require workload-owner approval and rollback evidence |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 16,293 | 11,583 | -29% | 1 | 1 | 0% | 3,455 | 3,326 | -4% | 0 | 0 | — |
case-02 | fail→fail | 14,607 | 9,367 | -36% | 1 | 1 | 0% | 2,467 | 2,674 | +8% | 0 | 0 | — |
case-03 | fail→pass | 13,161 | 8,298 | -37% | 1 | 1 | 0% | 2,610 | 2,668 | +2% | 0 | 0 | — |
case-04 | fail→fail | 13,588 | 18,573 | +37% | 1 | 1 | 0% | 2,596 | 4,863 | +87% | 0 | 0 | — |
case-05 | fail→pass | 15,230 | 14,547 | -4% | 1 | 1 | 0% | 2,946 | 3,637 | +23% | 0 | 0 | — |
case-06 | fail→fail | 16,185 | 13,117 | -19% | 1 | 1 | 0% | 3,312 | 3,836 | +16% | 0 | 0 | — |
case-07 | pass→pass | 4,547 | 3,397 | -25% | 1 | 1 | 0% | 829 | 1,574 | +90% | 0 | 0 | — |
case-08 | fail→pass | 21,540 | 4,166 | -81% | 1 | 1 | 0% | 1,135 | 1,497 | +32% | 0 | 0 | — |
case-09 | fail→pass | 13,325 | 8,732 | -34% | 1 | 1 | 0% | 1,977 | 2,250 | +14% | 0 | 0 | — |
case-10 | pass→pass | 3,940 | 2,830 | -28% | 1 | 1 | 0% | 718 | 1,495 | +108% | 0 | 0 | — |
case-11 | pass→pass | 6,395 | 2,898 | -55% | 1 | 1 | 0% | 1,185 | 1,428 | +21% | 0 | 0 | — |
case-12 | fail→pass | 3,232 | 3,244 | +0% | 1 | 1 | 0% | 402 | 1,441 | +258% | 0 | 0 | — |
case-13 | pass→pass | 3,539 | 2,508 | -29% | 1 | 1 | 0% | 588 | 1,278 | +117% | 0 | 0 | — |
case-14 | pass→pass | 4,537 | 2,614 | -42% | 1 | 1 | 0% | 702 | 1,300 | +85% | 0 | 0 | — |
case-15 | pass→pass | 7,272 | 2,000 | -72% | 1 | 1 | 0% | 1,071 | 1,323 | +24% | 0 | 0 | — |
case-16 | pass→pass | 9,662 | 2,551 | -74% | 1 | 1 | 0% | 1,579 | 1,325 | -16% | 0 | 0 | — |
case-17 | pass→pass | 6,532 | 2,338 | -64% | 1 | 1 | 0% | 1,128 | 1,391 | +23% | 0 | 0 | — |
case-18 | fail→pass | 7,413 | 2,166 | -71% | 1 | 1 | 0% | 1,226 | 1,363 | +11% | 0 | 0 | — |
case-19 | pass→pass | 4,541 | 2,222 | -51% | 1 | 1 | 0% | 824 | 1,311 | +59% | 0 | 0 | — |
case-20 | fail→pass | 6,847 | 2,510 | -63% | 1 | 1 | 0% | 1,086 | 1,332 | +23% | 0 | 0 | — |
case-21 | pass→pass | 10,029 | 4,006 | -60% | 1 | 1 | 0% | 1,744 | 1,642 | -6% | 0 | 0 | — |
case-22 | fail→fail | 12,918 | 9,555 | -26% | 1 | 1 | 0% | 2,079 | 2,705 | +30% | 0 | 0 | — |
case-23 | pass→pass | 10,991 | 8,258 | -25% | 1 | 1 | 0% | 2,074 | 2,439 | +18% | 0 | 0 | — |
case-24 | pass→pass | 6,886 | 2,340 | -66% | 1 | 1 | 0% | 1,144 | 1,365 | +19% | 0 | 0 | — |
case-25 | pass→pass | 9,246 | 1,606 | -83% | 1 | 1 | 0% | 1,609 | 1,249 | -22% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 25 cases were attempted, and 24 counted toward the lift figure. The other 1 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +32 percentage points is the difference between those two pass rates over the 24 comparable cases.
The publisher has shipped newer versions since this run, so these numbers describe v1, not the version currently listed.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.