Install
$ agentstack add skill-butterbase-ai-butterbase-skills-journey-deploy ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Journey: Deploy verification
Stage 4 of the guided journey. Verify the deployed app actually works end-to-end.
When to use
- Dispatched by
journeywhencurrent_stage: deploy. - Directly via
/butterbase-skills:journey-deploy.
Preflight
If docs/butterbase/03-preflight.md is missing, older than 24 hours, or 00-state.md has app_id: null, invoke butterbase-skills:journey-preflight first. Wait for it to return successfully before proceeding.
Inputs
docs/butterbase/00-state.md— forapp_id,deployed_url.docs/butterbase/02-plan.md— for the function list to smoke.docs/butterbase/04-build-log.md— to know what shipped.
Procedure
- Refresh docs. Call
butterbase_docswithtopic: "frontend". For end-to-end smoke patterns, also WebFetchhttps://docs.butterbase.ai/deploy. Skip if cache is fresh.
For each check, log a one-line result to 04-build-log.md. Halt on the first ✗ and ask the user to fix or skip.
- Frontend reachable. If
deployed_urlis set, fetch it via Bashcurl -sS -o /dev/null -w "%{http_code}". Expect200. Logdeploy curl 200 okor... fail.
- Functions respond. For each function in the plan with HTTP trigger, call
mcp__butterbase__invoke_functionwith a representative payload. Expect 2xx. Log per function.
- Auth round-trip (if configured). If the plan included OAuth, prompt the user:
"Open , click 'Sign in with ', and confirm you land logged-in. Did it work? (yes/no)". Log the answer.
- Function logs clean. Call
mcp__butterbase__manage_function action: get_logsfor the most recent invocations. Show the user any error-level lines. Ask:"Anything concerning here? (no → continue, yes → fix and re-run)".
- If all checks pass, tick
- [x] deployin00-state.md, setcurrent_stage: submit(ifhackathon_mode: true) orcurrent_stage: done(otherwise).
- Return to
journeyorchestrator.
Outputs
- Multiple lines in
04-build-log.md. - Updated
00-state.md.
Anti-patterns
- ❌ Treating a 200 from the frontend root as proof the app works — actually invoke a function.
- ❌ Skipping the auth round-trip check just because OAuth is configured server-side — judges will try to log in.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: butterbase-ai
- Source: butterbase-ai/butterbase-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.