Finishing a Development Branch
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
Run the release flow a project declares in rules/git-workflow-project.md § Deploy Workflow: its git merge steps, and — only where § Run Steps is execute — its scripts, each after its own approval.
$ npx skills add sd0xdev/sd0x-harness --skill deploy-flow -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sd0xdev/sd0x-harness deploy-flow --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/deploy-flow .claude/skills/deploy-flow && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "deploy-flow" agent skill from https://github.com/sd0xdev/sd0x-harness/tree/main/skills/deploy-flow into .claude/skills/deploy-flow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deploy-flow", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sd0xdev/sd0x-harness/tree/main/skills/deploy-flowType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sd0xdev/sd0x-harness --skill deploy-flow -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sd0xdev/sd0x-harness deploy-flow --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/deploy-flow .agents/skills/deploy-flow && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "deploy-flow" agent skill from https://github.com/sd0xdev/sd0x-harness/tree/main/skills/deploy-flow into .agents/skills/deploy-flow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deploy-flow", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sd0xdev/sd0x-harness --skill deploy-flow -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sd0xdev/sd0x-harness deploy-flow --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/deploy-flow .cursor/skills/deploy-flow && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "deploy-flow" agent skill from https://github.com/sd0xdev/sd0x-harness/tree/main/skills/deploy-flow into .cursor/skills/deploy-flow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deploy-flow", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sd0xdev/sd0x-harness.git --path skills/deploy-flow--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sd0xdev/sd0x-harness --skill deploy-flow -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sd0xdev/sd0x-harness deploy-flow --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/deploy-flow .gemini/skills/deploy-flow && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "deploy-flow" agent skill from https://github.com/sd0xdev/sd0x-harness/tree/main/skills/deploy-flow into .gemini/skills/deploy-flow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deploy-flow", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sd0xdev/sd0x-harness deploy-flowInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sd0xdev/sd0x-harness --skill deploy-flow -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/deploy-flow .github/skills/deploy-flow && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "deploy-flow" agent skill from https://github.com/sd0xdev/sd0x-harness/tree/main/skills/deploy-flow into .github/skills/deploy-flow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deploy-flow", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sd0xdev/sd0x-harness --skill deploy-flow -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sd0xdev/sd0x-harness deploy-flow --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/deploy-flow .opencode/skills/deploy-flow && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "deploy-flow" agent skill from https://github.com/sd0xdev/sd0x-harness/tree/main/skills/deploy-flow into .opencode/skills/deploy-flow/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deploy-flow", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
deploy-flowRun the release flow a project declares in rules/git-workflow-project.md § Deploy Workflow: its git merge steps, and — only where § Run Steps is execute — its scripts, each after its own approval.
Deploy Flow is an agent skill from sd0xdev/sd0x-harness. Run the release flow a project declares in rules/git-workflow-project.md § Deploy Workflow: its git merge steps, and — only where § Run Steps is execute — its scripts, each after its own approval. Use when: the user asks to release, deploy, promote a branch, or run the project's deploy workflow. Not for: pushing (use /push-ci), committing (use /smart-commit), stacked PRs (use /epic-merge or /gh-stack).
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/deploy-flow.sh`).
It sits in Development, covering Git workflow. It works with Git. The repository describes itself as: The harness layer for Claude Code — a reference implementation of harness engineering with hook-enforced dual review, state-machine gates that survive context compaction, and… The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c9a2036. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(/bin/bash:*)Bash(git:*)ReadGrepGlobAskUserQuestionFrom allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
gitbashFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Deploy Flow loads about 2.2k tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 1,044 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from sd0xdev/sd0x-harness at commit c9a2036, republished under its MIT licence (© sd0xdev). 1,044 words, ~2,202 tokens.
.claude/skills/deploy-flow/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Read first: @skills/push-ci/references/authorization-contract.md before executing a declared merge or run step — § Efficacy Boundary for what the per-step approval authorizes, § Push safety for any step that pushes. If that Read fails, stop and report it; execute no step.
Run the steps a project declares for its own release — nothing it does not declare, and nothing without a per-step approval.
⚠️ This skill is the Anchor Register #4 workflow for a project's declared deploy steps. It may run
⚠️ git switch + git merge for a declared merge step, and — only where the project sets
⚠️ Run Steps: execute — a declared script, each after an AskUserQuestion approval naming that step.
⚠️ It never runs git push. A declared script may push on its own; that is the run-script risk
⚠️ below, which the project opted into and every execute question states.
⚠️ An approval covers the one step it names, at the values it names — both OIDs for a merge, the
⚠️ HEAD commit and the script's blob hash for a run; nothing else.| Scenario | Use instead |
|---|---|
| Push a branch | /push-ci |
| Commit changes | /smart-commit --execute |
| Merge a stacked PR chain | /epic-merge, /gh-stack |
The project declares no ## Deploy Workflow | Say so, and offer to scaffold one with /install-rules --customize git-workflow |
Every git call and every script run goes through one checked-in script, so what a step's approval names is exactly what runs.
Pin the helper once, before any step. A merge switches branches, and the branch it switches to may track its own copy of the helper; re-locating it for the next step would run that copy before the next approval. So Phase 0 resolves the helper a single time and copies it to a private file, and every later fence runs that copy by its literal path: each fence is its own shell, so nothing carries over except the path you paste.
REPO_ROOT=$(git rev-parse --show-toplevel) || exit 1
SRC="$REPO_ROOT/.claude/scripts/deploy-flow.sh"
[ -r "$SRC" ] || SRC="$REPO_ROOT/skills/deploy-flow/scripts/deploy-flow.sh"
[ -r "$SRC" ] || SRC="${CLAUDE_PLUGIN_ROOT:-/nonexistent}/skills/deploy-flow/scripts/deploy-flow.sh"
[ -r "$SRC" ] || { echo "deploy-flow.sh not found — run /install-scripts --skill deploy-flow" >&2; exit 1; }
DF=$(mktemp "${TMPDIR:-/tmp}/deploy-flow.XXXXXX") && cat -- "$SRC" > "$DF" && echo "DF=$DF"
/bin/bash -p -- "$DF" clean --root "$REPO_ROOT" && /bin/bash -p -- "$DF" parse --root "$REPO_ROOT"Every later call is /bin/bash -p -- '<the DF path printed above>' <subcommand> --root '<repo root>' …
— never the locator again. Remove the copy when the flow ends, whatever its outcome.
| Subcommand | Does | Exit |
|---|---|---|
parse | Prints the declared steps (merge⇥src⇥tgt⇥form, run⇥path⇥args…), then mode⇥print|execute | 2 on any parse error — the whole block is ignored |
candidates <prefix>/* | Local branches a pattern may bind to | 2 on a bad pattern |
resolve <branch> | The branch's current OID | 3 when absent |
merge <src> <tgt> <src-oid> <tgt-oid> <form> | Refuses an undeclared step or a dirty tree (untracked files included); re-checks both OIDs; switches to <tgt>; merges the approved object | 3 refused · 4 attribution guard · 5 conflict (aborted) · 6 read-back mismatch |
run-plan <path> [args…] | For a declared step on a clean worktree, prints head⇥<oid> and blob⇥<hash> — the values its approval names | 3 undeclared or dirty tree |
run --expect-head <oid> --expect-blob <hash> <path> [args…] | Runs a declared step, only under execute, only on a clean worktree at the approved HEAD and script content, arguments as separate argv entries | 3 undeclared, print mode, dirty tree, or HEAD/script changed; otherwise the script's own |
clean | Checks the whole worktree, untracked files included | 3 when anything is uncommitted |
Run clean, then parse. A dirty worktree → say so and stop: every step is approved against the
committed tree. Exit 2 from parse → report the error line and stop: a malformed block is never
partly run. No steps → say the project declares none and stop. Otherwise show the steps and the Run Steps mode.
Steps run one at a time in the order parse printed them — a run declared before a merge runs
before it. Before each step, run parse again: output that differs from Phase 0's means the
declaration changed under the flow (a merge brought a different override), and the flow stops. Any step that is refused, declined, or ends with a nonzero exit stops the flow: report
which step and its exit status, and run nothing after it.
merge step<prefix>/* source or target lists candidates; the
user picks one from an AskUserQuestion (options, never typed). No candidate → the step is refused;
a branch is never created.resolve.merge <src> <tgt> <src-oid> <tgt-oid> <form>:--no-ff (default): the message is the fixed template Merge branch '<src>' into <tgt>, never
model-authored. commit-msg-guard.sh checks it before the merge and checks the recorded
commit after it, read back with replace refs and grafts disabled, and the parents are asserted
to be exactly <tgt-oid> <src-oid>. --no-edit and GIT_MERGE_AUTOEDIT=no keep an editor out.--ff-only: creates no commit, so there is no message to check. It verifies the new HEAD is
<src-oid> and <tgt-oid> is its ancestor.run stepRun Steps: print (default): print the exact command for the user. Nothing runs.
Run Steps: execute: run run-plan <path> [args…] first; it prints the HEAD commit and the
script's blob hash. Then one AskUserQuestion naming the exact command, both values, and stating
the run-script risk verbatim:
The script runs with your credentials and can commit, push, merge, publish or deploy. It bypasses the harness's own checks —
/smart-commit's guaranteed attribution check and/push-ci's approval and protected pre-approval. Git hooks still run for its ordinarygit commitandgit pushwhere they are installed (commit-msg-guard.sh,pre-push-gate.sh), but the script can skip hooks (e.g.--no-verify) or run where none is installed, and the harness cannot tell which.
Only "Run" proceeds to run --expect-head <oid> --expect-blob <hash> <path> [args…] with the
values the question named; the script refuses with exit 3 and runs nothing if HEAD or the script
changed after approval.
This skill issues no push and offers none itself. What follows is rules/git-workflow.md
§ Proactive Offer: the menu appears only when review-state.js offer returns true. A protected
target gets no push menu; /push-ci, on request, still meets its protected pre-approval.
--ai-co-authorgit push, or offering torun step under Run Steps: print, or passing a step's arguments through a shell stringcommit-msg-guard.sh on its recorded messagegit push executed by this skill© sd0xdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (scripts) in skills/deploy-flow of sd0xdev/sd0x-harness.
Open the folder on GitHubat commit c9a2036
Deploy Flow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Deploy Flow this skillsd0xdev/sd0x-harness | 192 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Finishing a Development Branchobra/superpowers | 296k | 5 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Code Design Rationale Investigatorcursor/plugins | 10k | 9 repos | ~2.6k | Automated safety check: Pass | None | |
| Contributor-First PR MergeHKUDS/OpenHarness | 16k | 1 repos | ~847 | Automated safety check: Pass | MIT | |
| Migrate Internal Package into GhostTryGhost/Ghost | 55k | — | ~3.8k | Automated safety check: Pass | MIT | |
| Create Pull Requestcline/cline | 70k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 |
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
cursor/plugins
Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.
HKUDS/OpenHarness
Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.
TryGhost/Ghost
Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.
cline/cline
Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.
tailcallhq/forgecode
Resolves Git merge conflicts with a plan-first workflow that keeps both sides' intent, regenerates lock files and backs up deleted-but-modified files.
sd0xdev/sd0x-harness
Write an Architecture Decision Record (ADR) for a feature — Context / Decision / Status / Consequences / Alternatives, filed as docs/features/<feature/adr-<NNN-<title.md with a 3-digit zero-padded…
sd0xdev/sd0x-harness
Load GitHub PR review comments into AI session — analyze, triage, plan.
sd0xdev/sd0x-harness
Change-aware next step advisor. An agent skill from sd0xdev/sd0x-harness.
sd0xdev/sd0x-harness
Obsidian vault integration via official CLI. An agent skill from sd0xdev/sd0x-harness.
sd0xdev/sd0x-harness
Agent-driven workflow orchestration (v1 report-only). An agent skill from sd0xdev/sd0x-harness.
sd0xdev/sd0x-harness
Post friendly review comments to a GitHub PR — prepare locally, preview, then submit as atomic review.
Works with
Categories
Run the release flow a project declares in rules/git-workflow-project.md § Deploy Workflow: its git merge steps, and — only where § Run Steps is execute — its scripts, each after its own approval. Deploy Flow is an agent skill from sd0xdev/sd0x-harness.md § Deploy Workflow: its git merge steps, and — only where § Run Steps is execute — its scripts, each after its own approval.
Deploy Flow fits situations like: : the user asks to release; promote a branch; run the projects deploy workflow.
Run `npx skills add sd0xdev/sd0x-harness --skill deploy-flow -a claude-code`. Or copy the skill folder (skills/deploy-flow in sd0xdev/sd0x-harness) into .claude/skills/deploy-flow in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sd0xdev/sd0x-harness --skill deploy-flow -a codex`. Or copy the skill folder (skills/deploy-flow in sd0xdev/sd0x-harness) into .agents/skills/deploy-flow in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sd0xdev/sd0x-harness --skill deploy-flow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deploy-flow, .gemini/skills/deploy-flow, .github/skills/deploy-flow and .opencode/skills/deploy-flow in your project.
Going by SKILL.md and its folder, Deploy Flow needs a shell for the scripts in its folder and the command-line tools its instructions call (git and bash). Our summary lists: A Bash shell. Its frontmatter pre-approves these tools: Bash(/bin/bash:*), Bash(git:*), Read, Grep, Glob, AskUserQuestion.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Deploy Flow is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Deploy Flow: Finishing a Development Branch (obra/superpowers, 296k stars), Code Design Rationale Investigator (cursor/plugins, 10k stars), Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars) and Migrate Internal Package into Ghost (TryGhost/Ghost, 55k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sd0xdev (a GitHub user) maintains it in sd0xdev/sd0x-harness, which has 192 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 6, 2026.
Source: sd0xdev/sd0x-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.