SkillAgentSearch skills...

alchemy-ci-integration

Gate Alchemy integration changes with deterministic unit, contract, fork, secret, and negative-path checks

Install / Use

npx skills add jeremylongshore/tons-of-skills-marketplace --skill alchemy-ci-integration

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

80/100

Category

Automation

Supported Platforms

Claude Code

Our assessment of alchemy-ci-integration

alchemy-ci-integration scores 80/100 on our quality scale, 1977th of 2,607 Automation skills we index.

Its SKILL.md is 4.8 KB long, well organised into 13 sections and no code examples: a solid amount of guidance for an agent.

With 2,785 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
26/30
Structure
13/20
Description
12/15
Adoption
15/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 6 days ago, so alchemy-ci-integration is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

alchemy-ci-integration compared with similar skills

All 4 of these similar skills score higher than alchemy-ci-integration; compare them before choosing.

SkillScoreStarsUpdatedFormat
alchemy-ci-integration (this skill)by jeremylongshore802.8k6d agoSKILL.md
Agent-Reachby Panniantong10086.3k14d agoCLAUDE.md
rufloby ruvnet10073.6ktodayCLAUDE.md
Scraplingby D4Vinci10084.6ktodayMCP Server
algorithmic-artby anthropics100177.9k7d agoSKILL.md

Frequently asked questions

How do I install alchemy-ci-integration?
Run npx skills add jeremylongshore/tons-of-skills-marketplace --skill alchemy-ci-integration. The install tabs above show the steps for each supported agent.
Which AI agents does alchemy-ci-integration work with?
It is written for Claude Code, as a SKILL.md file. Other agents that read the same format can often use it too.
Is alchemy-ci-integration safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is alchemy-ci-integration still maintained?
The repository was last updated 6 days ago, so alchemy-ci-integration is actively maintained.

name: alchemy-ci-integration description: >- Gate Alchemy integration changes with deterministic unit, contract, fork, secret, and negative-path checks. Use when adding Alchemy to CI or hardening an existing pipeline. Trigger with "Alchemy CI", "Alchemy GitHub Actions", or "test Alchemy in CI". allowed-tools: Read,Glob,Grep,Write,Edit argument-hint: "<ci-provider> <test-layers> <deployment-boundary>" version: 2.0.0 license: MIT author: Jeremy Longshore jeremy@intentsolutions.io tags: [saas, alchemy, ci-cd, testing] model: inherit effort: high compatibility: "Designed for Claude Code; live Alchemy access requires network access, an appropriate credential, account capacity, and explicit approval"

Alchemy Continuous Integration Gate

Overview

Gate Alchemy integration changes with deterministic unit, contract, fork, secret, and negative-path checks. This workflow produces a reviewable artifact and negative-path evidence before any live side effect.

Prerequisites

  • Current first-party Alchemy documentation for the selected product, chain, feature, client, authentication method, limit, and lifecycle.
  • Named product, application, security, data/privacy, budget, release, and operations owners appropriate to the requested scope.
  • Synthetic or approved non-production fixtures, a credential canary, explicit success criteria, and a tested rollback boundary.

Current Contract

CI should keep most provider behavior deterministic through fixtures and contract tests. A live read or pinned-chain fork is a separately labeled integration gate with a scoped non-production key, bounded usage, and an unavailable-provider policy. Pull-request testing never implies authorization to deploy or transact.

Authentication

Use a least-privilege CI environment secret with no write or wallet-signing authority. Prevent fork-origin workflows from receiving repository secrets and scan logs, artifacts, bundles, source maps, and built assets for canaries.

Instructions

  1. Inventory unit, adapter-contract, fixture, fork, live-read, deployment, and transaction tests and assign each to a trust boundary.
  2. Pin runtime and dependencies; validate fixtures against current documented schemas without requiring live credentials for ordinary pull requests.
  3. Run secret and deprecated-import gates, including a ban on new alchemy-sdk imports and credential-bearing endpoint literals.
  4. Run a scoped live read or pinned-block fork only in an approved trusted context, assert chain identity, cap duration/usage, and retain a redacted receipt.
  5. Keep testnet deployment or transaction simulation in a separate protected job with environment approval and no automatic production promotion.
  6. Prove invalid-key, wrong-chain, provider-unavailable, rate-limited, partial-response, and secret-canary failures before making the gate required.

Tool Discipline

Use Read, Glob, and Grep to inspect current documentation, configuration, code, fixtures, and evidence. Use Write and Edit only for approved repository artifacts. Skill invocation alone does not authorize network access, credentials, wallet addresses, customer data, plan changes, spend, key creation or rotation, webhook changes, deployment, replay, transaction construction, signing, broadcast, or deletion.

Approval Boundaries

Repository/security owners approve secret-bearing CI contexts. Release owners approve protected deployment jobs. External fork pull requests never gain secrets solely because a maintainer runs tests.

Error Handling

  • A provider outage must produce the documented gate result; do not silently skip a required live contract.
  • Do not expose secret values in command lines, process dumps, cache keys, or build scans.
  • Do not combine a read-only CI gate with testnet deployment in the same implicit authority boundary.

Output

Return the test-layer map, workflow/config change, secret and fork policy, deterministic fixtures, live-gate budget, negative-path receipts, required/advisory decision, and rollback. Mark assumptions, observations, source dates, environment-specific behavior, owners, and unresolved gaps explicitly.

Examples

  • Run fixture-backed adapter tests on every fork PR and a single chain-ID-asserted live read only after the trusted environment gate.
  • Fail a build that reintroduces alchemy-sdk or embeds an Alchemy endpoint credential in a source map.

Validation

Exercise and record expected and observed results for:

  • fork PR without secrets
  • invalid key
  • wrong chain
  • provider unavailable
  • HTTP 200 partial error
  • secret canary in artifact

Resources

  • Current first-party evidence map — recheck dated Alchemy sources before execution.
  • Treat observed account, application, network, indexer, chain, or provider behavior as environment-specific evidence, never a universal guarantee.

Related Skills

View on GitHub
GitHub Stars2.8k
CategoryAutomation
Updated6d ago
Forks404

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions