setup-deploy — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited setup-deploy (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use when: "setup deploy", "configure deployment", "set up land-and-deploy", "how do I configure deploys".
eval "$(~/.vibestack/bin/vibe-slug 2>/dev/null)" 2>/dev/null || SLUG="unknown"
_LEARN_FILE="${VIBESTACK_HOME:-$HOME/.vibestack}/projects/${SLUG:-unknown}/learnings.jsonl"
if [ -f "$_LEARN_FILE" ]; then
_LEARN_COUNT=$(wc -l < "$_LEARN_FILE" 2>/dev/null | tr -d ' ')
echo "LEARNINGS: $_LEARN_COUNT entries loaded"
if [ "$_LEARN_COUNT" -gt 5 ] 2>/dev/null; then
~/.vibestack/bin/vibe-learnings-search --limit 5 2>/dev/null || true
fi
else
echo "LEARNINGS: none yet"
fi{{include lib/snippets/session-host.md}}
{{include lib/snippets/decision-brief.md}}
{{include lib/snippets/working-protocols.md}}
{{include lib/snippets/state-protocols.md}}
When the user types /setup-deploy, run this skill.
grep -A 20 "## Deploy Configuration" CLAUDE.md 2>/dev/null || echo "NO_CONFIG"If configuration already exists, show it and ask:
If the user picks C, stop.
Run the platform detection from the deploy bootstrap:
# Platform config files
[ -f fly.toml ] && echo "PLATFORM:fly" && cat fly.toml
[ -f render.yaml ] && echo "PLATFORM:render" && cat render.yaml
[ -f vercel.json ] || [ -d .vercel ] && echo "PLATFORM:vercel"
[ -f netlify.toml ] && echo "PLATFORM:netlify" && cat netlify.toml
[ -f Procfile ] && echo "PLATFORM:heroku"
[ -f railway.json ] || [ -f railway.toml ] && echo "PLATFORM:railway"
# GitHub Actions deploy workflows
for f in $(find .github/workflows -maxdepth 1 \( -name '*.yml' -o -name '*.yaml' \) 2>/dev/null); do
[ -f "$f" ] && grep -qiE "deploy|release|production|staging|cd" "$f" 2>/dev/null && echo "DEPLOY_WORKFLOW:$f"
done
# Project type
[ -f package.json ] && grep -q '"bin"' package.json 2>/dev/null && echo "PROJECT_TYPE:cli"
find . -maxdepth 1 -name '*.gemspec' 2>/dev/null | grep -q . && echo "PROJECT_TYPE:library"Based on what was detected, guide the user through platform-specific configuration.
#### Fly.io
If fly.toml detected:
grep -m1 "^app" fly.toml | sed 's/app = "\(.*\)"/\1/'fly CLI is installed: which fly 2>/dev/nullfly status --app {app} 2>/dev/nullhttps://{app}.fly.devfly status --app {app}https://{app}.fly.dev (or /health if the app has one)Ask the user to confirm the production URL. Some Fly apps use custom domains.
#### Render
If render.yaml detected:
echo $RENDER_API_KEY | head -c 4 (don't expose the full key)https://{service-name}.onrender.comAsk the user to confirm. Render uses auto-deploy from the connected git branch — after merge to main, Render picks it up automatically. The "deploy wait" in /land-and-deploy should poll the Render URL until it responds with the new version.
#### Vercel
If vercel.json or .vercel detected:
vercel CLI: which vercel 2>/dev/nullvercel ls --prod 2>/dev/null | head -3#### Netlify
If netlify.toml detected:
#### GitHub Actions only
If deploy workflows detected but no platform config:
#### Custom / Manual
If nothing detected, use AskUserQuestion to gather the information:
fly status, kubectl rollout status)bun run build)Read CLAUDE.md (or create it). Find and replace the ## Deploy Configuration section if it exists, or append it at the end.
## Deploy Configuration (configured by /setup-deploy)
- Platform: {platform}
- Production URL: {url}
- Deploy workflow: {workflow file or "auto-deploy on push"}
- Deploy status command: {command or "HTTP health check"}
- Merge method: {squash/merge/rebase}
- Project type: {web app / API / CLI / library}
- Post-deploy health check: {health check URL or command}
### Custom deploy hooks
- Pre-merge: {command or "none"}
- Deploy trigger: {command or "automatic on push to main"}
- Deploy status: {command or "poll production URL"}
- Health check: {URL or command}After writing, verify the configuration works:
curl -sf "{health-check-url}" -o /dev/null -w "%{http_code}" 2>/dev/null || echo "UNREACHABLE"{deploy-status-command} 2>/dev/null | head -5 || echo "COMMAND_FAILED"Report results. If anything failed, note it but don't block — the config is still useful even if the health check is temporarily unreachable.
DEPLOY CONFIGURATION — COMPLETE
════════════════════════════════
Platform: {platform}
URL: {url}
Health check: {health check}
Status cmd: {status command}
Merge method: {merge method}
Saved to CLAUDE.md. /land-and-deploy will use these settings automatically.
Next steps:
- Run /land-and-deploy to merge and deploy your current PR
- Edit the "## Deploy Configuration" section in CLAUDE.md to change settings
- Run /setup-deploy again to reconfigurefly or vercel CLI isn't installed, fall back to URL-based health checks.If you discovered a non-obvious platform quirk, deployment pattern, or configuration gotcha during this session, log it for future sessions:
~/.vibestack/bin/vibe-learnings-log '{"skill":"setup-deploy","type":"TYPE","key":"SHORT_KEY","insight":"DESCRIPTION","confidence":N,"source":"SOURCE","files":["path/to/relevant/file"]}'Types: pattern (reusable approach), pitfall (what NOT to do), preference (user stated), architecture (structural decision), operational (environment/CLI/workflow).
Only log genuine discoveries. Don't log obvious things. A good test: would this insight save time in a future session?
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.