CtrlK
BlogDocsLog inGet started
Tessl Logo

convex-deploy-guard

Classify + announce the target Convex deployment before any deployment-affecting command; fresh explicit consent for prod actions; session read-only mode.

65

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable guard skill with explicit validation and feedback loops for destructive deployment operations. Its main weakness is the Rules section duplicating the Workflow, adding token cost without new information.

Suggestions

Collapse the "Rules" section or fold only the non-duplicated points (e.g., the composition note) back into the Workflow to remove restatement and recover tokens.

Trim the opening motivational sentence ("Deployments are not interchangeable, and most incidents start with..."), which restates context Claude can infer from the workflow.

DimensionReasoningScore

Conciseness

The body is mostly efficient and assumes Claude knows Convex, but the "Rules" section substantially restates the "Workflow" steps (prod consent, flag splitting, read-only absoluteness, wrong-deploy diagnosis), which is redundant padding that could be tightened.

3 / 5

Actionability

Concrete, executable guidance throughout: specific commands ("npx convex deploy", "npx convex run --prod", "convex env list"), exact MCP flags (--cautiously-allow-production-pii, --dangerously-enable-production-deployments, --disable-tools run,envSet,envRemove), and a copy-ready announce example.

5 / 5

Workflow Clarity

A clearly sequenced 7-step workflow with explicit validation checkpoints (resolve source disagreement in step 1, a diagnose-don't-redeploy feedback loop in step 6, and a stop-on-ambiguity rule in step 7) for destructive deployment operations.

5 / 5

Progressive Disclosure

The skill is under 50 lines, no external references are needed, and the body is well-organized into Workflow and Rules sections — meeting the simple-skill exception for a top score.

5 / 5

Total

18

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A clear, specific third-person description with strong distinctiveness, but it lacks an explicit "Use when..." trigger clause, capping completeness. Trigger-term coverage is good rather than comprehensive.

Suggestions

Add an explicit trigger clause, e.g. "Use before any Convex deploy, run, env, or migration command — especially when prod might be the target."

Include a few more natural trigger terms/synonyms ("convex deploy", "preview deployment", "npx convex run --prod") to raise trigger-term coverage.

Mention MCP flag handling briefly in the description to round out capability coverage.

DimensionReasoningScore

Specificity

Names the Convex-deployment domain and several concrete actions ("Classify + announce the target Convex deployment", "fresh explicit consent for prod actions", "session read-only mode"), but stops short of the body's full coverage (MCP flag splitting, wrong-deployment diagnosis), leaving minor gaps.

4 / 5

Completeness

The "what" is clear, but there is no explicit "Use when..." trigger clause — the "when" is only weakly implied by "before any deployment-affecting command", which per the rubric caps completeness at 3.

3 / 5

Trigger Term Quality

Natural terms a Convex user would say are present ("Convex deployment", "prod actions", "read-only mode", "deployment-affecting command"), though common variations like "convex deploy", "preview", or specific subcommands are missing.

4 / 5

Distinctiveness Conflict Risk

The niche is highly specific (Convex deployment target identification + per-action prod consent + read-only mode), with minimal overlap risk against other skills.

5 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
openclaw/clawhub
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.