deploy-to-mainnet — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited deploy-to-mainnet (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
# Suiperpower telemetry. Routes through the CLI so projects.json + Convex stay in sync.
# Silent on failure so the skill never blocks. Opt out: SUIPERPOWER_TELEMETRY=off.
#
# AGENT NOTE: when this skill finishes, run the matching completion command:
# suiperpower track deploy-to-mainnet ship completed
# Or use "failed" / "aborted" if it ended that way.
command -v suiperpower >/dev/null 2>&1 && suiperpower track deploy-to-mainnet ship started >/dev/null 2>&1 &
trueIf TEL_PROMPTED is no, before doing real work, ask the user:
Help suiperpower get better. We track which skills get used and how long they take. No code, no file paths, no PII. Change anytime in ~/.suiperpower/config.json.>
A) Sure, anonymous B) No thanks
Write the answer to ~/.suiperpower/config.json telemetryTier field and create ~/.suiperpower/.telemetry-prompted. Then continue.
Runs the mainnet deploy with refusal gates in front of the publish step. The point is not to gatekeep, it is to surface the gates honestly so the user is not deploying to mainnet because they typed a command, but because they have done the work that mainnet implies.
If a gate is missing, the skill names what is missing and routes the user to the relevant skill. The user can override and proceed by typing the literal phrase the skill asks for, but the override is logged in deploy-context.md so it is on the record.
validate-business-model and retention-loop first.If you activated this and the user actually wants something else, consult skills/SKILL_ROUTER.md and hand off.
.suiperpower/business-model.md (required, verdict must be yes or partial)..suiperpower/retention-loop.md (required, verdict must not be no).review-move output, indicated by an entry in .suiperpower/learnings.md under Decisions or a separate .suiperpower/review-move.md if present..suiperpower/deploy-context.md (required, must contain at least one testnet entry).Move.toml and the package path for the publish.A ## Deploy, <timestamp> block appended to .suiperpower/deploy-context.md with env: mainnet, the package id, the upgrade cap, the upgrade policy chosen, and any override notes:
## Deploy, <timestamp>
### Network
- env: mainnet
- rpc: <rpc url>
- gas address: <0x...>
- balance before: <SUI>
- balance after: <SUI>
### Package
- package id: <0x...>
- modules: <comma-separated module names>
- digest: <publish digest>
- upgrade cap object: <0x...>
- upgrade cap policy: <compatible | additive | dep-only | immutable>
### Gates
- business-model: <yes | partial | overridden>
- retention-loop: <yes | partial | overridden>
- review-move: <recent | overridden>
- testnet exercised: <yes | overridden>
### Notes
- <override rationale, if any>
- <stakeholders notified, if any>business-model.md, retention-loop.md, deploy-context.md. If any are missing, surface which ones and route the user back.review-move ran in the last 14 days. The skill considers a ## Decisions entry referencing review-move or a .suiperpower/review-move.md file as evidence.yes to proceed cleanly, partial to proceed with a flag, no to refuse unless override.yes or partial to proceed, no to refuse unless override.deploy-context.md plus user-confirmed evidence the testnet package was exercised by a frontend or PTB.validate-business-model, retention-loop, review-move, deploy-to-testnet.Notes section of the new deploy entry.skills/data/guides/deploy-runbook.md.mainnet, address is funded, RPC is healthy.sui move build, sui move test.sui client publish <package path> --gas-budget <budget> --json.skills/data/guides/package-id-capture.md.UpgradeCap id.compatible. The skill prompts the user to choose:compatible (default): future upgrades may add fields and functions but not change existing signatures.additive: future upgrades may only add, never modify.dep-only: future upgrades only update dependency package addresses.immutable: no future upgrades possible. Most secure, most rigid.immutable, the skill confirms with a second prompt.sui client object <package id> and sui client object <upgrade cap id>.submit-to-sui-overflow if this is a hackathon submission.apply-grant if the user is preparing a Sui Foundation grant application.analytics-baseline (post-launch grow phase) once it ships in v1.1.Before reporting done:
deploy-context.md with env: mainnet and all required fields?sui client object confirmation surfaced?If any answer is no, the skill keeps working.
On-demand references (load when relevant to the user's question):
references/gate-rationale.md: Why each gate exists and what failure looks like.references/upgrade-policy-choice.md: Trade-offs between compatible, additive, dep-only, immutable.Canonical:
skills/data/guides/deploy-runbook.mdskills/data/guides/package-id-capture.mdskills/data/guides/security-checklist.mdclaude "/suiper:deploy-to-mainnet <your message>"codex "/deploy-to-mainnet <your message>"grok, then /deploy-to-mainnet <your message> in the session~/.cursor/rules/deploy-to-mainnet.mdc and reference it.If you activated this and the user actually wants something else, consult skills/SKILL_ROUTER.md and hand off.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.