deck-gateway — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited deck-gateway (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Generate, inspect, and apply Kong Gateway entity configuration with decK without losing track of live state, scope, or deployment model.
Use this skill for Gateway entities and Gateway-oriented GitOps. Do not use it as a replacement for Konnect platform workflows that belong in kongctl or Terraform.
kong-konnect MCP server first for live Konnect inspectionwhen the target Gateway entities live in Konnect and MCP is available.
decK, _format_version,or deck gateway commands, or when the user explicitly asks for decK.
kongctl-query first when the real task is incidentdiagnosis, live-state discovery, or Konnect inspection before a repo-owned decK slice is identified.
decK layout, file split, tags, and CI patterns inthe repository.
kongctl repository to decK unless the userexplicitly asks for that migration.
terraform-kong-gateway, terraform-konnect, orkongctl-declarative when the user wants HCL or kongctl rather than decK.
Load only the reference file that matches the active branch:
references/command-paths.mdpaths.
references/openapi-generation.mdentities derived from it.
references/state-shaping-and-tags.mdmore than the entity content itself.
references/dump-diff-sync-safety.mdmutating it.
Before editing files or proposing a live sync:
deck is installed and runnable: deck versionconfig files, or secure host settings. Never echo or commit secrets.
mutation before choosing a decK path.
before any sync.
deck gateway sync only when the user explicitly asked for mutation.sync aligned with the already previewed file, directory, tags, orinclude boundary.
deck gateway diff and expect no remaining intendedchanges.
whole repo.
intent.
decK as the source-controlled representation of Gateway entities, notas proof that the live Gateway currently matches it.
deck command appears blocked by the agent environment ratherthan the live product or CLI itself, request an unsandboxed retry with approval before assuming auth or command failure.
deck gateway validate plus a scoped deck gateway diff as therequired preview surface before sync.
them.
plane unless the user asks for a full export.
live dumps to inspect or recover, not as the default authoring format.
decK files. decK is for Gatewayentities, not the full Konnect product surface.
wants Gateway entities derived from it.
decK is the right answer for DB-less runtime loading,identity or team management, or non-Gateway Konnect resources.
decK shapeIdentify:
decK state filesdeck gateway diff, deck gateway sync, or wrapper scriptsMatch the existing conventions before adding new files or commands.
Pin down:
consumer groups, upstreams, targets, certificates, or vault-related config
Do not treat platform resources such as teams, portals, or access rules as Gateway entities.
decK's native safety surfacePick the smallest decK path that answers the request:
Load references/command-paths.md when several decK paths could fit and you need a sharper decision rule.
When editing state:
Load references/state-shaping-and-tags.md when the repo's split, tags, or include boundaries are the main constraint.
command.
deck gateway sync only when the user explicitly asked for livemutation.
already previewed.
Load references/dump-diff-sync-safety.md when the user needs a safer inspection-first path or is about to use a broad dump/sync flow.
decKAfter any requested sync:
deck gateway diff and expect no remaining intendedchanges
rather than trusting a broad sync success message
sync exit status alone as proof that the live Gateway nowmatches the intended state
State:
sync
decK is strongest for Gateway entities, not the broader Konnect platform.decK file in Git does not prove the live control plane matches it.sync runs can overwrite adjacent entity changes when file scope ortag scope is too loose.
decK for Gateway-entity workflows, butthe surrounding platform resources may belong in another tool.
decK addsunnecessary translation.
Before answering, verify that you can state:
decK is the right tool for this repository or requestdeck preview commands prove the intended change safelyterraform-kong-gateway when the repository already managesself-managed Gateway config in HCL.
terraform-konnect when the repository already manages Konnect-hostedGateway entities or surrounding Konnect resources in HCL.
kongctl-declarative when the task is really Konnect platform YAMLrather than Gateway-entity decK.
kongctl-query or the relevant domain skill when the user first needslive inspection rather than config authoring.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.