Install
$ agentstack add skill-kevinzai-commander-ccc-deploy-check ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
/ccc-deploy-check — Pre-deploy readiness gate
> Placeholders like ~~CI/CD and ~~monitoring refer to connected tools. See [CONNECTORS.md](../../CONNECTORS.md).
Run a pre-deployment readiness check before shipping. Quick Mode runs the essential checklist in under 60 seconds. Power Mode performs a full assessment with rollback plan.
Quick Mode (default)
Run this checklist automatically — no questions needed:
[ ] Tests pass → npm test / vitest / pytest (auto-detect)
[ ] Build is clean → npm run build / tsc --noEmit
[ ] No console.log → grep -r "console\.log" src/ --include="*.ts"
[ ] No hardcoded secrets → scan for API keys, tokens, passwords in diff
[ ] No TODO/FIXME in → grep -r "TODO\|FIXME" src/ (warn, don't block)
changed files
[ ] package.json lock → check for lockfile changes that don't match package.json
[ ] Migrations are safe → check for destructive SQL (DROP, DELETE without WHERE)
Report each check as PASS / WARN / FAIL.
Verdict:
- All PASS → GO — ship it
- Any WARN → CAUTION — review warnings before shipping
- Any FAIL → NO-GO — fix before deploying
Power Mode
Activate by passing --power or detailed or production.
Full deploy readiness assessment:
Pre-Deploy Checks
- All Quick Mode checks (above)
- Diff size — flag if >500 lines changed (increased risk)
- New dependencies — security scan via
npm auditorpip audit - Environment variable diff — any new required env vars documented?
- Feature flags — is the change gated appropriately?
- Database migration — reversible? tested on staging?
Rollback Plan (auto-generated)
## Rollback Plan
- **How to roll back:** `git revert ` + redeploy OR feature flag off
- **Data concerns:** [Are there DB migrations that are hard to reverse?]
- **Estimated rollback time:** [X minutes]
- **Owner on call:** [Who to page if this goes wrong]
Risk Assessment
| Dimension | Risk | Notes | |-----------|------|-------| | Scope of change | Low/Med/High | Lines changed, files touched | | Data mutations | Low/Med/High | Schema changes, data migrations | | External dependencies | Low/Med/High | New 3rd-party calls | | Traffic impact | Low/Med/High | Hot paths, rate limits |
Overall risk: Low (GO) / Medium (CAUTION) / High (NO-GO pending review)
If Connectors Available
If ~~CI/CD is connected:
- Pull latest pipeline status — only proceed if all checks green
- Block deploy if tests are failing on the target branch
- Show flaky test history for context
If ~~monitoring is connected:
- Check current error rates before deploying (don't deploy into an incident)
- Set a deploy marker after shipping for correlation
- Alert if error rate spikes >2x in first 5 minutes post-deploy
Output
┌─────────────────────────────────────────────────────────────────┐
│ DEPLOY CHECK — [Environment] [Date/Time] │
├─────────────────────────────────────────────────────────────────┤
│ ✓ Tests pass │
│ ✓ Build clean │
│ ✓ No console.log │
│ ✓ No hardcoded secrets │
│ ⚠ 2 TODOs in changed files (non-blocking) │
│ ✓ Lockfile consistent │
│ ✓ No destructive migrations │
├─────────────────────────────────────────────────────────────────┤
│ VERDICT: ✅ GO — Safe to deploy │
└─────────────────────────────────────────────────────────────────┘
Tips
- Run before every deploy — 60-second check is cheaper than a 2am rollback.
- Production flag adds rigor — pass
productionto enable the full risk assessment. - Fix FAIL before shipping — WARNs are judgment calls; FAILs are not.
- Rollback plan is required — if you can't explain how to roll back, you're not ready to ship.
> ⚙️ Fable contract: plan before build · verifier ≠ worker · prove before alarm · loops need gates · leave durable state — rules/fable-method.md
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: KevinZai
- Source: KevinZai/commander
- License: MIT
- Homepage: https://commanderplugin.com
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.