coily-action: GitHub Action wrapper for lockdown-audited Claude Code runs #61

Closed
opened 2026-05-23 20:54:04 +00:00 by coilysiren · 1 comment
Owner

Originally filed by @coilysiren on 2026-05-03T19:53:46Z - https://github.com/coilysiren/coily/issues/42

🤖 Filed by Claude Code on Kai's behalf.

Inspiration: anthropics/claude-code-action and anthropics/claude-code-base-action - reusable Action shape for running Claude Code in CI. See also anthropics/claude-code-security-review for the security framing.

Joins against: coily/docs/features/03-lockdown.md, the "coily as a safety boundary for AI agents" blog issue (#11), and the bare-write deny rules in ~/.claude/settings.json.

Anthropic ships the reusable Action; Kai ships the lockdown layer. A coilysiren/coily-action would marry them: Claude Code in CI, but argv-validated and audit-logged via coily, so the agent can't shell out to anything not on the allowlist. The selling point is a single value prop ("audited Claude Code in CI") that's hard to assemble out of existing pieces. Pairs naturally with the security-boundary blog post.

🤖 Filed by Claude Code on Kai's behalf.


Moved from coilysiren/coilyco-ai#29.

_Originally filed by @coilysiren on 2026-05-03T19:53:46Z - [https://github.com/coilysiren/coily/issues/42](https://github.com/coilysiren/coily/issues/42)_ > 🤖 Filed by Claude Code on Kai's behalf. **Inspiration:** [`anthropics/claude-code-action`](https://github.com/anthropics/claude-code-action) and [`anthropics/claude-code-base-action`](https://github.com/anthropics/claude-code-base-action) - reusable Action shape for running Claude Code in CI. See also [`anthropics/claude-code-security-review`](https://github.com/anthropics/claude-code-security-review) for the security framing. **Joins against:** `coily/docs/features/03-lockdown.md`, the "coily as a safety boundary for AI agents" blog issue (#11), and the bare-write deny rules in `~/.claude/settings.json`. Anthropic ships the reusable Action; Kai ships the lockdown layer. A `coilysiren/coily-action` would marry them: Claude Code in CI, but argv-validated and audit-logged via coily, so the agent can't shell out to anything not on the allowlist. The selling point is a single value prop ("audited Claude Code in CI") that's hard to assemble out of existing pieces. Pairs naturally with the security-boundary blog post. > 🤖 Filed by Claude Code on Kai's behalf. --- *Moved from coilysiren/coilyco-ai#29.*
Author
Owner

Iceboxed in the 2026-05-29 backlog burn-down: Speculative GitHub Action wrapper, inspired by external repos. Reopen anytime if it becomes real.

Iceboxed in the 2026-05-29 backlog burn-down: Speculative GitHub Action wrapper, inspired by external repos. Reopen anytime if it becomes real.
Sign in to join this conversation.
No labels
P0
P1
P2
P3
P4
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
coilyco-bridge/coily#61
No description provided.