Hex Ci IntegrationSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: hex-ci-integration description: 'Configure Hex CI/CD integration with GitHub Actions and testing. Use when setting up automated testing, configuring CI pipelines, or integrating Hex tests into your build process. Trigger with phrases like "hex CI", "hex GitHub Actions", "hex automated tests", "CI hex". ' allowed-tools: Read, Write, Edit, Bash(gh:*) version: 1.6.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - hex - data - analytics compatibility: Designed for Claude Code --- # Hex CI Integration ## Overview Set up CI/CD for Hex data analytics integrations: run unit tests with mocked project run and connection responses on every PR, trigger live Hex project runs and validate outputs on merge to main. Hex provides collaborative data notebooks with scheduled runs and API-triggered execution, so CI pipelines verify data transform logic, trigger post-deploy dashboard refreshes, and monitor run status. ## GitHub Actions Workflow ```yaml # .github/workflows/hex-ci.yml name: Hex CI on: pull_request: paths: ['src/hex/**', 'tests/**'] push: branches: [main] jobs: unit-tests: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: { node-version: '20' } - run: npm ci - run: npm test -- --reporter=verbose trigger-hex-refresh: if: github.ref == 'refs/heads/main' needs: unit-tests runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: { node-version: '20' } - run: npm ci - run: npm run test:integration env: HEX_API_TOKEN: ${{ secrets.HEX_API_TOKEN }} HEX_PROJECT_ID: ${{ vars.HEX_PROJECT_ID }} ``` ## Mock-Based Unit Tests ```typescript // tests/hex-service.test.ts import { describe, it, expect, vi } from 'vitest'; import { triggerProjectRun, getRunStatus } from '../src/hex-service'; vi.mock('../src/hex-client', () => ({ HexClient: vi.fn().mockImplementation(() => ({ runProject: vi.fn().mockResolvedValue({ runId: 'run_abc123', projectId: 'proj_xyz', status: 'running', startedAt: '2026-04-01T10:00:00Z', }), getRunStatus: vi.fn().mockResolvedValue({ runId: 'run_abc123', status: 'completed', elapsedMs: 4500, outputs: { row_count: 1250, last_updated: '2026-04-01T10:00:04Z' }, }), listProjects: vi.fn().mockResolvedValue({ projects: [{ id: 'proj_xyz', title: 'Revenue Dashboard' }], }), })), })); describe('Hex Service', () => { it('triggers a project run and returns run ID', async () => { const result = await triggerProjectRun('proj_xyz', { triggered_by: 'ci' }); expect(result.runId).toBe('run_abc123'); expect(result.status).toBe('running'); }); it('polls run status until complete', async () => { const status = await getRunStatus('run_abc123'); expect(status.status).toBe('completed'); expect(status.outputs.row_count).toBe(1250); }); }); ``` ## Integration Tests ```typescript // tests/integration/hex.integration.test.ts import { describe, it, expect } from 'vitest'; const hasToken = !!process.env.HEX_API_TOKEN; describe.skipIf(!hasToken)('Hex Live API', () => { it('triggers a project run via API', async () => { const res = await fetch( `https://app.hex.tech/api/v1/project/${process.env.HEX_PROJECT_ID}/run`, { method: 'POST', headers: { 'Authorization': `Bearer ${process.env.HEX_API_TOKEN}`, 'Content-Type': 'application/json', }, body: JSON.stringify({ inputParams: { triggered_by: 'ci' }, updateCacheResult: true }), }, ); expect(res.status).toBe(200); const body = await res.json(); expect(body).toHaveProperty('runId'); }); }); ``` ## Error Handling | CI Issue | Cause | Fix | |----------|-------|-----| | `401 Unauthorized` | Invalid or expired API token | Regenerate at app.hex.tech account settings | | `404 Project not found` | Wrong project ID | Verify `HEX_PROJECT_ID` matches the Hex dashboard URL | | Run status stuck on `running` | Long-running query or connection issue | Set timeout and poll interval (max 5 min) | | `inputParams` rejected | Parameter name mismatch | Match param names exactly to Hex project input cells | | Rate limit (429) | Too many run triggers | Deduplicate CI triggers and add cooldown between runs | ## Prerequisites - CI secret references, a sandbox project/destination, fixtures with no production output, protected branches, and a rollback mechanism. ## Instructions 1. Run mocked tests first, including malformed parameter, denied access, quota, cancellation, and output-assertion cases. 2. Run a bounded sandbox integration with idempotency and prohibit production projects/destinations in CI configuration. 3. Emit aggregate counts, opaque IDs, and policy revisions only; fail for unexpected scope, unredacted output, or expanded access. 4. Canary after protected review, verify assertions, and restore the last-known-good revision on failure. ## Output Publish a CI receipt with commit SHA, fixture revision, sandbox project, test totals, policy checks, canary outcome, and rollback reference. Exclude SQL, output, and secrets. ## Examples `sha=abc123; fixtures=v5; project=ci-synthetic; tests=18/18; access=least-privilege; assertions=pass; canary=not-promoted` is a valid pre-production receipt. ## Resources - Hex API Reference - [GitHub Actions Secrets](https://docs.github.com/en/actions/security-guides/encrypted-secrets) ## Next Steps For deployment patterns, see `hex-deploy-integration`.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__hex-ci-integration.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Hex Ci Integration skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Hex Ci Integration safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Hex Ci Integration access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Hex Ci Integration work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.