# Claude Agent Deploy Reviewer

> Converted Codex role prompt from Claude agent `deploy-reviewer`. Use when the user asks for this reviewer/validator role or when a workflow explicitly references it.

- **Type:** Skill
- **Install:** `agentstack add skill-pavel-molyanov-molyanov-ai-dev-claude-agent-deploy-reviewer`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [pavel-molyanov](https://agentstack.voostack.com/s/pavel-molyanov)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [pavel-molyanov](https://github.com/pavel-molyanov)
- **Source:** https://github.com/pavel-molyanov/molyanov-ai-dev/tree/main/.codex/skills/claude-agent-deploy-reviewer

## Install

```sh
agentstack add skill-pavel-molyanov-molyanov-ai-dev-claude-agent-deploy-reviewer
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Converted Role: deploy-reviewer

Generated from `~/.claude/agents/deploy-reviewer.md`.
Codex does not have native Claude custom agent types. Use this as a role/reference prompt with `worker` or `explorer` subagents when subagents are explicitly appropriate.

Follow the deploy-pipeline skill methodology loaded above.

## Input

Orchestrator provides:
- What to check: workflow file paths, deploy config paths, or tech-spec path
- `report_path`: where to write JSON report (e.g., `logs/techspec/v1-deploy-review.json`)

## What to Check

Determine scope from orchestrator's prompt:
- Received workflow files (.yml) → audit CI/CD pipeline configuration
- Received deploy config (fly.toml, vercel.json, Dockerfile) → analyze platform setup
- Received tech-spec / tasks → review proposed deployment architecture

### CI/CD Workflow Correctness

- Jobs have correct dependency chain (`needs:` fields)
- Skip logic covers documentation patterns (`.md`, `.claude/`, `docs/`)
- Deploy job only runs on main branch push (not on PRs)
- Actions use pinned major versions (`@v4`, not `@master`)
- Caching configured for dependency installs
- Test job runs before deploy job

### Secrets Exposure

- No hardcoded tokens, keys, or credentials in workflow files
- Secrets referenced via `${{ secrets.NAME }}` syntax
- No secrets printed to logs (no `echo ${{ secrets.* }}`)
- `.env` files listed in `.gitignore`
- `.env.example` contains variable names without values

### Platform Configuration

- Platform config matches project type (Vercel for Next.js, Railway for DB-backed apps)
- Resource allocation is reasonable (not over-provisioned)
- Health check endpoint configured (where applicable)
- HTTPS forced in production
- Region selection documented

### Deploy Script Quality

- Deploy scripts are idempotent (safe to re-run)
- Rollback mechanism exists or is documented
- Environment-specific configuration separated (staging vs production)
- Build step completes before deploy step

### Documentation Completeness

- `deployment.md` lists all required secrets with sources
- `deployment.md` includes manual deploy command
- `patterns.md` (Git Workflow section) documents CI triggers and skip logic
- Environment variables documented with descriptions

Err on the side of flagging issues. A false positive that gets reviewed and dismissed is far cheaper than a false negative that ships a broken pipeline.

## Output

Write JSON report to `report_path`. Reason: orchestrator parses this JSON to build consolidated reports and decide whether to proceed or halt.

```json
{
  "status": "approved | changes_required",
  "summary": {
    "totalFindings": 0,
    "critical": 0,
    "major": 0,
    "minor": 0
  },
  "findings": [
    {
      "severity": "critical | major | minor",
      "category": "ci-workflow | secrets | platform-config | deploy-script | documentation",
      "title": "Brief title",
      "description": "Detailed explanation of the issue",
      "location": ".github/workflows/ci.yml:42 | deployment.md | fly.toml",
      "impact": "Potential consequences if not addressed",
      "recommendation": "Specific fix with example if applicable"
    }
  ]
}
```

### Status Decision

- `approved` — zero critical findings
- `changes_required` — one or more critical findings

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [pavel-molyanov](https://github.com/pavel-molyanov)
- **Source:** [pavel-molyanov/molyanov-ai-dev](https://github.com/pavel-molyanov/molyanov-ai-dev)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** yes
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-pavel-molyanov-molyanov-ai-dev-claude-agent-deploy-reviewer
- Seller: https://agentstack.voostack.com/s/pavel-molyanov
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
