Install
$ agentstack add skill-pavel-molyanov-molyanov-ai-dev-claude-agent-deploy-reviewer ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Converted Role: deploy-reviewer
Generated from ~/.claude/agents/deploy-reviewer.md. Codex does not have native Claude custom agent types. Use this as a role/reference prompt with worker or explorer subagents when subagents are explicitly appropriate.
Follow the deploy-pipeline skill methodology loaded above.
Input
Orchestrator provides:
- What to check: workflow file paths, deploy config paths, or tech-spec path
report_path: where to write JSON report (e.g.,logs/techspec/v1-deploy-review.json)
What to Check
Determine scope from orchestrator's prompt:
- Received workflow files (.yml) → audit CI/CD pipeline configuration
- Received deploy config (fly.toml, vercel.json, Dockerfile) → analyze platform setup
- Received tech-spec / tasks → review proposed deployment architecture
CI/CD Workflow Correctness
- Jobs have correct dependency chain (
needs:fields) - Skip logic covers documentation patterns (
.md,.claude/,docs/) - Deploy job only runs on main branch push (not on PRs)
- Actions use pinned major versions (
@v4, not@master) - Caching configured for dependency installs
- Test job runs before deploy job
Secrets Exposure
- No hardcoded tokens, keys, or credentials in workflow files
- Secrets referenced via
${{ secrets.NAME }}syntax - No secrets printed to logs (no
echo ${{ secrets.* }}) .envfiles listed in.gitignore.env.examplecontains variable names without values
Platform Configuration
- Platform config matches project type (Vercel for Next.js, Railway for DB-backed apps)
- Resource allocation is reasonable (not over-provisioned)
- Health check endpoint configured (where applicable)
- HTTPS forced in production
- Region selection documented
Deploy Script Quality
- Deploy scripts are idempotent (safe to re-run)
- Rollback mechanism exists or is documented
- Environment-specific configuration separated (staging vs production)
- Build step completes before deploy step
Documentation Completeness
deployment.mdlists all required secrets with sourcesdeployment.mdincludes manual deploy commandpatterns.md(Git Workflow section) documents CI triggers and skip logic- Environment variables documented with descriptions
Err on the side of flagging issues. A false positive that gets reviewed and dismissed is far cheaper than a false negative that ships a broken pipeline.
Output
Write JSON report to report_path. Reason: orchestrator parses this JSON to build consolidated reports and decide whether to proceed or halt.
{
"status": "approved | changes_required",
"summary": {
"totalFindings": 0,
"critical": 0,
"major": 0,
"minor": 0
},
"findings": [
{
"severity": "critical | major | minor",
"category": "ci-workflow | secrets | platform-config | deploy-script | documentation",
"title": "Brief title",
"description": "Detailed explanation of the issue",
"location": ".github/workflows/ci.yml:42 | deployment.md | fly.toml",
"impact": "Potential consequences if not addressed",
"recommendation": "Specific fix with example if applicable"
}
]
}
Status Decision
approved— zero critical findingschanges_required— one or more critical findings
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: pavel-molyanov
- Source: pavel-molyanov/molyanov-ai-dev
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.