alchemy-ci-integration
Gate Alchemy integration changes with deterministic unit, contract, fork, secret, and negative-path checks
Install / Use
npx skills add jeremylongshore/tons-of-skills-marketplace --skill alchemy-ci-integrationInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
AutomationSupported Platforms
Our assessment of alchemy-ci-integration
alchemy-ci-integration scores 80/100 on our quality scale, 1977th of 2,607 Automation skills we index.
Its SKILL.md is 4.8 KB long, well organised into 13 sections and no code examples: a solid amount of guidance for an agent.
With 2,785 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 6 days ago, so alchemy-ci-integration is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
alchemy-ci-integration compared with similar skills
All 4 of these similar skills score higher than alchemy-ci-integration; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| alchemy-ci-integration (this skill)by jeremylongshore | 80 | 2.8k | 6d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 86.3k | 14d ago | CLAUDE.md |
| rufloby ruvnet | 100 | 73.6k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 84.6k | today | MCP Server |
| algorithmic-artby anthropics | 100 | 177.9k | 7d ago | SKILL.md |
Frequently asked questions
- How do I install alchemy-ci-integration?
- Run
npx skills add jeremylongshore/tons-of-skills-marketplace --skill alchemy-ci-integration. The install tabs above show the steps for each supported agent. - Which AI agents does alchemy-ci-integration work with?
- It is written for Claude Code, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is alchemy-ci-integration safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is alchemy-ci-integration still maintained?
- The repository was last updated 6 days ago, so alchemy-ci-integration is actively maintained.
Skill content
View source on GitHubname: alchemy-ci-integration description: >- Gate Alchemy integration changes with deterministic unit, contract, fork, secret, and negative-path checks. Use when adding Alchemy to CI or hardening an existing pipeline. Trigger with "Alchemy CI", "Alchemy GitHub Actions", or "test Alchemy in CI". allowed-tools: Read,Glob,Grep,Write,Edit argument-hint: "<ci-provider> <test-layers> <deployment-boundary>" version: 2.0.0 license: MIT author: Jeremy Longshore jeremy@intentsolutions.io tags: [saas, alchemy, ci-cd, testing] model: inherit effort: high compatibility: "Designed for Claude Code; live Alchemy access requires network access, an appropriate credential, account capacity, and explicit approval"
Alchemy Continuous Integration Gate
Overview
Gate Alchemy integration changes with deterministic unit, contract, fork, secret, and negative-path checks. This workflow produces a reviewable artifact and negative-path evidence before any live side effect.
Prerequisites
- Current first-party Alchemy documentation for the selected product, chain, feature, client, authentication method, limit, and lifecycle.
- Named product, application, security, data/privacy, budget, release, and operations owners appropriate to the requested scope.
- Synthetic or approved non-production fixtures, a credential canary, explicit success criteria, and a tested rollback boundary.
Current Contract
CI should keep most provider behavior deterministic through fixtures and contract tests. A live read or pinned-chain fork is a separately labeled integration gate with a scoped non-production key, bounded usage, and an unavailable-provider policy. Pull-request testing never implies authorization to deploy or transact.
Authentication
Use a least-privilege CI environment secret with no write or wallet-signing authority. Prevent fork-origin workflows from receiving repository secrets and scan logs, artifacts, bundles, source maps, and built assets for canaries.
Instructions
- Inventory unit, adapter-contract, fixture, fork, live-read, deployment, and transaction tests and assign each to a trust boundary.
- Pin runtime and dependencies; validate fixtures against current documented schemas without requiring live credentials for ordinary pull requests.
- Run secret and deprecated-import gates, including a ban on new
alchemy-sdkimports and credential-bearing endpoint literals. - Run a scoped live read or pinned-block fork only in an approved trusted context, assert chain identity, cap duration/usage, and retain a redacted receipt.
- Keep testnet deployment or transaction simulation in a separate protected job with environment approval and no automatic production promotion.
- Prove invalid-key, wrong-chain, provider-unavailable, rate-limited, partial-response, and secret-canary failures before making the gate required.
Tool Discipline
Use Read, Glob, and Grep to inspect current documentation, configuration, code, fixtures, and evidence. Use Write and Edit only for approved repository artifacts. Skill invocation alone does not authorize network access, credentials, wallet addresses, customer data, plan changes, spend, key creation or rotation, webhook changes, deployment, replay, transaction construction, signing, broadcast, or deletion.
Approval Boundaries
Repository/security owners approve secret-bearing CI contexts. Release owners approve protected deployment jobs. External fork pull requests never gain secrets solely because a maintainer runs tests.
Error Handling
- A provider outage must produce the documented gate result; do not silently skip a required live contract.
- Do not expose secret values in command lines, process dumps, cache keys, or build scans.
- Do not combine a read-only CI gate with testnet deployment in the same implicit authority boundary.
Output
Return the test-layer map, workflow/config change, secret and fork policy, deterministic fixtures, live-gate budget, negative-path receipts, required/advisory decision, and rollback. Mark assumptions, observations, source dates, environment-specific behavior, owners, and unresolved gaps explicitly.
Examples
- Run fixture-backed adapter tests on every fork PR and a single chain-ID-asserted live read only after the trusted environment gate.
- Fail a build that reintroduces
alchemy-sdkor embeds an Alchemy endpoint credential in a source map.
Validation
Exercise and record expected and observed results for:
- fork PR without secrets
- invalid key
- wrong chain
- provider unavailable
- HTTP 200 partial error
- secret canary in artifact
Resources
- Current first-party evidence map — recheck dated Alchemy sources before execution.
- Treat observed account, application, network, indexer, chain, or provider behavior as environment-specific evidence, never a universal guarantee.
Related Skills
Agent-Reach
86.3kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
ruflo
73.6k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
Scrapling
84.6k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
