Agent skill

Deploy Flow

by sd0xdev in sd0xdev/sd0x-harness

Run the release flow a project declares in rules/git-workflow-project.md § Deploy Workflow: its git merge steps, and — only where § Run Steps is execute — its scripts, each after its own approval.

MITAuto-check passedDevelopment

Install Deploy Flow

skills CLI
$ npx skills add sd0xdev/sd0x-harness --skill deploy-flow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sd0xdev/sd0x-harness deploy-flow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/deploy-flow .claude/skills/deploy-flow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deploy-flow
GitHub stars
192
Token cost
~2.2k tokens
SKILL.md length
1,044 words
Files
2 (incl. scripts)
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Run the release flow a project declares in rules/git-workflow-project.md § Deploy Workflow: its git merge steps, and — only where § Run Steps is execute — its scripts, each after its own approval.

  • Works in 3 steps: Read the declaration → Each step, in declaration order → After the flow
  • : the user asks to release
  • SKILL.md covers Authorization, Trigger, When NOT to Use and The executable half, plus 3 more sections
  • Runs Shell scripts from its folder; calls git and bash

What it does

Deploy Flow is an agent skill from sd0xdev/sd0x-harness. Run the release flow a project declares in rules/git-workflow-project.md § Deploy Workflow: its git merge steps, and — only where § Run Steps is execute — its scripts, each after its own approval. Use when: the user asks to release, deploy, promote a branch, or run the project's deploy workflow. Not for: pushing (use /push-ci), committing (use /smart-commit), stacked PRs (use /epic-merge or /gh-stack).

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/deploy-flow.sh`).

It sits in Development, covering Git workflow. It works with Git. The repository describes itself as: The harness layer for Claude Code — a reference implementation of harness engineering with hook-enforced dual review, state-machine gates that survive context compaction, and… The licence is MIT.

When your agent uses it

  • : the user asks to release
  • Promote a branch
  • Run the projects deploy workflow

Example prompts

  • “/deploy-flow”

Requirements

  • A Bash shell
  • Pre-approved tools (allowed-tools): Bash(/bin/bash:*), Bash(git:*), Read, Grep, Glob, AskUserQuestion

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Read the declaration
  2. Each step, in declaration order
  3. After the flow

What it can do on your machine

Read from SKILL.md and the folder at commit c9a2036. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(/bin/bash:*)
    • Bash(git:*)
    • Read
    • Grep
    • Glob
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deploy Flow loads about 2.2k tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 1,044 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from sd0xdev/sd0x-harness at commit c9a2036, republished under its MIT licence (© sd0xdev). 1,044 words, ~2,202 tokens.

Download SKILL.mdSave it as .claude/skills/deploy-flow/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
deploy-flow
description
Run the release flow a project declares in rules/git-workflow-project.md § Deploy Workflow: its git merge steps, and — only where § Run Steps is execute — its scripts, each after its own approval. Use when: the user asks to release, deploy, promote a branch, or run the project's deploy workflow. Not for: pushing (use /push-ci), committing (use /smart-commit), stacked PRs (use /epic-merge or /gh-stack).
allowed-tools
Bash(/bin/bash:*), Bash(git:*), Read, Grep, Glob, AskUserQuestion

Deploy Flow

Read first: @skills/push-ci/references/authorization-contract.md before executing a declared merge or run step — § Efficacy Boundary for what the per-step approval authorizes, § Push safety for any step that pushes. If that Read fails, stop and report it; execute no step.

Run the steps a project declares for its own release — nothing it does not declare, and nothing without a per-step approval.

Authorization

⚠️ This skill is the Anchor Register #4 workflow for a project's declared deploy steps. It may run
⚠️ git switch + git merge for a declared merge step, and — only where the project sets
⚠️ Run Steps: execute — a declared script, each after an AskUserQuestion approval naming that step.
⚠️ It never runs git push. A declared script may push on its own; that is the run-script risk
⚠️ below, which the project opted into and every execute question states.
⚠️ An approval covers the one step it names, at the values it names — both OIDs for a merge, the
⚠️ HEAD commit and the script's blob hash for a run; nothing else.

Trigger

  • Keywords: deploy, release, promote, deploy workflow, run the release flow, 部署, 發佈

When NOT to Use

ScenarioUse instead
Push a branch/push-ci
Commit changes/smart-commit --execute
Merge a stacked PR chain/epic-merge, /gh-stack
The project declares no ## Deploy WorkflowSay so, and offer to scaffold one with /install-rules --customize git-workflow

The executable half

Every git call and every script run goes through one checked-in script, so what a step's approval names is exactly what runs.

Pin the helper once, before any step. A merge switches branches, and the branch it switches to may track its own copy of the helper; re-locating it for the next step would run that copy before the next approval. So Phase 0 resolves the helper a single time and copies it to a private file, and every later fence runs that copy by its literal path: each fence is its own shell, so nothing carries over except the path you paste.

bash
REPO_ROOT=$(git rev-parse --show-toplevel) || exit 1
SRC="$REPO_ROOT/.claude/scripts/deploy-flow.sh"
[ -r "$SRC" ] || SRC="$REPO_ROOT/skills/deploy-flow/scripts/deploy-flow.sh"
[ -r "$SRC" ] || SRC="${CLAUDE_PLUGIN_ROOT:-/nonexistent}/skills/deploy-flow/scripts/deploy-flow.sh"
[ -r "$SRC" ] || { echo "deploy-flow.sh not found — run /install-scripts --skill deploy-flow" >&2; exit 1; }
DF=$(mktemp "${TMPDIR:-/tmp}/deploy-flow.XXXXXX") && cat -- "$SRC" > "$DF" && echo "DF=$DF"
/bin/bash -p -- "$DF" clean --root "$REPO_ROOT" && /bin/bash -p -- "$DF" parse --root "$REPO_ROOT"

Every later call is /bin/bash -p -- '<the DF path printed above>' <subcommand> --root '<repo root>' … — never the locator again. Remove the copy when the flow ends, whatever its outcome.

SubcommandDoesExit
parsePrints the declared steps (merge⇥src⇥tgt⇥form, run⇥path⇥args…), then mode⇥print|execute2 on any parse error — the whole block is ignored
candidates <prefix>/*Local branches a pattern may bind to2 on a bad pattern
resolve <branch>The branch's current OID3 when absent
merge <src> <tgt> <src-oid> <tgt-oid> <form>Refuses an undeclared step or a dirty tree (untracked files included); re-checks both OIDs; switches to <tgt>; merges the approved object3 refused · 4 attribution guard · 5 conflict (aborted) · 6 read-back mismatch
run-plan <path> [args…]For a declared step on a clean worktree, prints head⇥<oid> and blob⇥<hash> — the values its approval names3 undeclared or dirty tree
run --expect-head <oid> --expect-blob <hash> <path> [args…]Runs a declared step, only under execute, only on a clean worktree at the approved HEAD and script content, arguments as separate argv entries3 undeclared, print mode, dirty tree, or HEAD/script changed; otherwise the script's own
cleanChecks the whole worktree, untracked files included3 when anything is uncommitted

Workflow

Phase 0: Read the declaration

Run clean, then parse. A dirty worktree → say so and stop: every step is approved against the committed tree. Exit 2 from parse → report the error line and stop: a malformed block is never partly run. No steps → say the project declares none and stop. Otherwise show the steps and the Run Steps mode.

Phase 1: Each step, in declaration order

Steps run one at a time in the order parse printed them — a run declared before a merge runs before it. Before each step, run parse again: output that differs from Phase 0's means the declaration changed under the flow (a merge brought a different override), and the flow stops. Any step that is refused, declined, or ends with a nonzero exit stops the flow: report which step and its exit status, and run nothing after it.

Show full SKILL.md (487 more words)Show less
A merge step
  1. Bind a pattern by the user's pick. A <prefix>/* source or target lists candidates; the user picks one from an AskUserQuestion (options, never typed). No candidate → the step is refused; a branch is never created.
  2. Resolve both concrete branches to OIDs with resolve.
  3. Ask: one AskUserQuestion naming the step, source, target, form and both full OIDs. Only "Merge" proceeds.
  4. Run merge <src> <tgt> <src-oid> <tgt-oid> <form>:
    • --no-ff (default): the message is the fixed template Merge branch '<src>' into <tgt>, never model-authored. commit-msg-guard.sh checks it before the merge and checks the recorded commit after it, read back with replace refs and grafts disabled, and the parents are asserted to be exactly <tgt-oid> <src-oid>. --no-edit and GIT_MERGE_AUTOEDIT=no keep an editor out.
    • --ff-only: creates no commit, so there is no message to check. It verifies the new HEAD is <src-oid> and <tgt-oid> is its ancestor.
  5. Report the outcome by exit status. Exit 4 names the OID and stops the flow: nothing is amended — that is the developer's call. Exit 5: the merge was aborted, nothing merged.
A run step
  • Run Steps: print (default): print the exact command for the user. Nothing runs.

  • Run Steps: execute: run run-plan <path> [args…] first; it prints the HEAD commit and the script's blob hash. Then one AskUserQuestion naming the exact command, both values, and stating the run-script risk verbatim:

    The script runs with your credentials and can commit, push, merge, publish or deploy. It bypasses the harness's own checks — /smart-commit's guaranteed attribution check and /push-ci's approval and protected pre-approval. Git hooks still run for its ordinary git commit and git push where they are installed (commit-msg-guard.sh, pre-push-gate.sh), but the script can skip hooks (e.g. --no-verify) or run where none is installed, and the harness cannot tell which.

    Only "Run" proceeds to run --expect-head <oid> --expect-blob <hash> <path> [args…] with the values the question named; the script refuses with exit 3 and runs nothing if HEAD or the script changed after approval.

Phase 2: After the flow

This skill issues no push and offers none itself. What follows is rules/git-workflow.md § Proactive Offer: the menu appears only when review-state.js offer returns true. A protected target gets no push menu; /push-ci, on request, still meets its protected pre-approval.

Prohibited

  • Running any step the declaration does not contain, or any step without its own approval
  • Merging by branch name after approving OIDs — the script merges the approved object
  • Authoring or editing the merge message, amending a merge commit, or passing --ai-co-author
  • Running git push, or offering to
  • Running a run step under Run Steps: print, or passing a step's arguments through a shell string
  • Printing a deploy command for the user to copy when they asked to run the flow — ask, then run

Verification

  • Every executed step had its own AskUserQuestion approval naming it
  • Every merge commit passed commit-msg-guard.sh on its recorded message
  • No git push executed by this skill

© sd0xdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in skills/deploy-flow of sd0xdev/sd0x-harness.

  • SKILL.md
  • scripts/deploy-flow.sh

Open the folder on GitHubat commit c9a2036

Compare with similar skills

Deploy Flow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deploy Flow compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deploy Flow this skillsd0xdev/sd0x-harness192—~2.2kAutomated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Code Design Rationale Investigatorcursor/plugins10k9 repos~2.6kAutomated safety check: PassNone
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Migrate Internal Package into GhostTryGhost/Ghost55k—~3.8kAutomated safety check: PassMIT
Create Pull Requestcline/cline70k1 repos~1.6kAutomated safety check: PassApache-2.0

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Official

    Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.

    10k GitHub starsUsed in 9 repos~2.6k tokens
    DevelopmentAuto-check passed
  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.

    55k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Git Merge Conflict Resolver

    tailcallhq/forgecode

    Resolves Git merge conflicts with a plan-first workflow that keeps both sides' intent, regenerates lock files and backs up deleted-but-modified files.

    7.6k GitHub starsUsed in 1 repo~4.5k tokens
    DevelopmentAuto-check passed

More from sd0xdev/sd0x-harness

All 91 skills in this repo
  • Adr

    sd0xdev/sd0x-harness

    Write an Architecture Decision Record (ADR) for a feature — Context / Decision / Status / Consequences / Alternatives, filed as docs/features/<feature/adr-<NNN-<title.md with a 3-digit zero-padded…

    192 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Load PR Review

    sd0xdev/sd0x-harness

    Load GitHub PR review comments into AI session — analyze, triage, plan.

    192 GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed
  • Next Step

    sd0xdev/sd0x-harness

    Change-aware next step advisor. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Obsidian CLI

    sd0xdev/sd0x-harness

    Obsidian vault integration via official CLI. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Orchestrate

    sd0xdev/sd0x-harness

    Agent-driven workflow orchestration (v1 report-only). An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • PR Comment

    sd0xdev/sd0x-harness

    Post friendly review comments to a GitHub PR — prepare locally, preview, then submit as atomic review.

    192 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Deploy Flow

What does Deploy Flow do?

Run the release flow a project declares in rules/git-workflow-project.md § Deploy Workflow: its git merge steps, and — only where § Run Steps is execute — its scripts, each after its own approval. Deploy Flow is an agent skill from sd0xdev/sd0x-harness.md § Deploy Workflow: its git merge steps, and — only where § Run Steps is execute — its scripts, each after its own approval.

When should I use Deploy Flow?

Deploy Flow fits situations like: : the user asks to release; promote a branch; run the projects deploy workflow.

How do I install Deploy Flow in Claude Code?

Run `npx skills add sd0xdev/sd0x-harness --skill deploy-flow -a claude-code`. Or copy the skill folder (skills/deploy-flow in sd0xdev/sd0x-harness) into .claude/skills/deploy-flow in your project. Claude Code loads it when a task matches its description.

How do I install Deploy Flow in Codex?

Run `npx skills add sd0xdev/sd0x-harness --skill deploy-flow -a codex`. Or copy the skill folder (skills/deploy-flow in sd0xdev/sd0x-harness) into .agents/skills/deploy-flow in your project. Codex loads it when a task matches its description.

Can I use Deploy Flow in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sd0xdev/sd0x-harness --skill deploy-flow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deploy-flow, .gemini/skills/deploy-flow, .github/skills/deploy-flow and .opencode/skills/deploy-flow in your project.

What does Deploy Flow need to run?

Going by SKILL.md and its folder, Deploy Flow needs a shell for the scripts in its folder and the command-line tools its instructions call (git and bash). Our summary lists: A Bash shell. Its frontmatter pre-approves these tools: Bash(/bin/bash:*), Bash(git:*), Read, Grep, Glob, AskUserQuestion.

Does Deploy Flow access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Deploy Flow safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Deploy Flow use?

Deploy Flow is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deploy Flow use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Deploy Flow?

Skills that share tags, products or a category with Deploy Flow: Finishing a Development Branch (obra/superpowers, 296k stars), Code Design Rationale Investigator (cursor/plugins, 10k stars), Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars) and Migrate Internal Package into Ghost (TryGhost/Ghost, 55k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deploy Flow?

sd0xdev (a GitHub user) maintains it in sd0xdev/sd0x-harness, which has 192 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 6, 2026.

Source: sd0xdev/sd0x-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.