convex-deploy-guard
clawdbot/clawdhub/.agents/skills/convex-deploy-guard/SKILL.md
Classify + announce the target Convex deployment before any deployment-affecting command; fresh explicit consent for prod actions; session read-only mode.
Skill9.5k starsChanged 2 days ago
- Reads credentials
What's in it
- Deployment target guard
- Workflow
- Rules
--- name: convex-deploy-guard description: "Classify + announce the target Convex deployment before any deployment-affecting command; fresh explicit consent for prod actions; session read-only mode." --- <!-- GENERATED from convex-agents content/capabilities/deploy-guard.json — do not edit by hand. --> # Deployment target guard Deployments are not interchangeable, and most incidents start with a command aimed at the wrong one. Every Convex project has several (personal dev, preview, prod — often across multiple projects on one machine). This guard is the standing discipline: identify, announce, then act — and treat prod as consent-gated, per action, per session. ## Workflow 1. IDENTIFY before you act: read `CONVEX_DEPLOYMENT` in .env.local, `convex.json`, and whether `CONVEX_DEPLOY_KEY` is set; or call the official Convex MCP `status` tool. Classify the target: local-anonymous | dev | preview | prod. If two sources disagree, resolve before proceeding. 2. ANNOUNCE in one line before any deployment-affecting command: `target: dev (joyful-capybara-123, personal dev)`. Never run the command in the same breath as discovering the target — announce first. 3. PROD needs a FRESH explicit yes: before `npx convex deploy` (when it resolves to prod), `npx convex run --prod`, `env set` on prod, snapshot `import`/`export` on prod, or starting the MCP with prod access — state exactly what will change on which deployment and get an explicit yes in THIS session. A yes given earlier, or for a different target, does not carry. 4. MCP safety defaults: start the official MCP scoped non-prod (`--deployment dev`). The two prod flags are DIFFERENT risk levels — keep them split: a read-only prod audit (advisor/insights reading data/logs/insights) passes ONLY `--cautiously-allow-production-pii` (read tools); `--dangerously-enable-production-deployments` (which enables MUTATING prod tools) stays OFF unless the user explicitly asked to CHANGE prod this session. Never pair them by default — 'look at prod' must not silently grant 'mutate prod'. 5. READ-ONLY session mode: when the user says 'read-only' / 'don't change anything', honor it absolutely for the rest of the session — no deploy, no env set/remove, no mutations via `run`, no imports; start the MCP with `--disable-tools run,envSet,envRemove`. 6. Wrong-deployment diagnosis: when a deploy 'didn't change anything', do NOT re-deploy harder. Re-run step 1 — the deploy almost certainly landed on a different deployment than the one being observed. 7. Ambiguity = stop: if you cannot determine which deployment a command will hit, find out (status tool; compare `npx convex env list` fingerprints) — never guess. ## Rules - Classify and announce the target BEFORE every deployment-affecting command — identification and action are two separate steps. - Prod consent is per-action, per-target, per-session: state what changes where, get a fresh explicit yes. - Keep the two prod MCP flags split by risk: --cautiously-allow-production-pii (read-only) for an audit; --dangerously-enable-production-deployments (mutating) only when the user explicitly asks to change prod. Both are user-spoken-only; default every MCP start to a non-prod deployment selector. - Read-only mode, once requested, is absolute for the session — including 'harmless' mutations. - A deploy that seemed to do nothing means the WRONG deployment changed — diagnose the target, don't re-run. - This guard composes: ship, env, migrate, and seed run it as their step 0; it is not itself a deploy tool.
More agent context in clawdbot/clawdhub
64 other files this repository gives its agents, the first 60 shown.
AGENTS.md
Skill
- autoreview.agents/skills/autoreview/SKILL.md
- axiom-alerting.agents/skills/axiom-alerting/SKILL.md
- axiom-sre.agents/skills/axiom-sre/SKILL.md
- building-dashboards.agents/skills/building-dashboards/SKILL.md
- clawhub-content-rights-correspondence.agents/skills/clawhub-content-rights-correspondence/SKILL.md
- clawhub-convex.agents/skills/clawhub-convex/SKILL.md
- clawhub-moderation.agents/skills/clawhub-moderation/SKILL.md
- clawhub-pr-maintainer.agents/skills/clawhub-pr-maintainer/SKILL.md
- clawhub-production-release.agents/skills/clawhub-production-release/SKILL.md
- controlling-costs.agents/skills/controlling-costs/SKILL.md
- convex-acquire-domain.agents/skills/convex-acquire-domain/SKILL.md
- convex-add.agents/skills/convex-add/SKILL.md
- convex-advisor.agents/skills/convex-advisor/SKILL.md
- convex-agent.agents/skills/convex-agent/SKILL.md
- convex-auth.agents/skills/convex-auth/SKILL.md
- convex-authz.agents/skills/convex-authz/SKILL.md
- convex-backup.agents/skills/convex-backup/SKILL.md
- convex-billing.agents/skills/convex-billing/SKILL.md
- convex-check-updates.agents/skills/convex-check-updates/SKILL.md
- convex-cost.agents/skills/convex-cost/SKILL.md
- convex-create-component.agents/skills/convex-create-component/SKILL.md
- convex-crons.agents/skills/convex-crons/SKILL.md
- convex-design.agents/skills/convex-design/SKILL.md
- convex-docs.agents/skills/convex-docs/SKILL.md
- convex-domains.agents/skills/convex-domains/SKILL.md
- convex-env.agents/skills/convex-env/SKILL.md
- convex-expert.agents/skills/convex-expert/SKILL.md
- convex-explain-app.agents/skills/convex-explain-app/SKILL.md
- convex-improve-convex-plugin.agents/skills/convex-improve-convex-plugin/SKILL.md
- convex-insights.agents/skills/convex-insights/SKILL.md
- convex-launch-readiness.agents/skills/convex-launch-readiness/SKILL.md
- convex-migrate-rehearse.agents/skills/convex-migrate-rehearse/SKILL.md
- convex-migrate.agents/skills/convex-migrate/SKILL.md
- convex-migration-helper.agents/skills/convex-migration-helper/SKILL.md
- convex-monitor.agents/skills/convex-monitor/SKILL.md
- convex-optimize.agents/skills/convex-optimize/SKILL.md
- convex-performance-audit.agents/skills/convex-performance-audit/SKILL.md
- convex-quickstart.agents/skills/convex-quickstart/SKILL.md
- convex-retention.agents/skills/convex-retention/SKILL.md
- convex-reviewer.agents/skills/convex-reviewer/SKILL.md
- convex-seed.agents/skills/convex-seed/SKILL.md
- convex-self-heal.agents/skills/convex-self-heal/SKILL.md
- convex-sentinel.agents/skills/convex-sentinel/SKILL.md
- convex-setup-auth.agents/skills/convex-setup-auth/SKILL.md
- convex-ship.agents/skills/convex-ship/SKILL.md
- convex.agents/skills/convex/SKILL.md
- convex-suggest.agents/skills/convex-suggest/SKILL.md
- convex-test.agents/skills/convex-test/SKILL.md
- convex-verify.agents/skills/convex-verify/SKILL.md
- create-and-cleanup-migration.agents/skills/create-and-cleanup-migration/SKILL.md
- openclaw-brand.agents/skills/openclaw-brand/SKILL.md
- openclaw-carapace.agents/skills/openclaw-carapace/SKILL.md
- openclaw-design-audit.agents/skills/openclaw-design-audit/SKILL.md
- openclaw-design.agents/skills/openclaw-design/SKILL.md
- openclaw-design-system.agents/skills/openclaw-design-system/SKILL.md
- openclaw-marketing-pages.agents/skills/openclaw-marketing-pages/SKILL.md
- proof-video.agents/skills/proof-video/SKILL.md
- query-metrics.agents/skills/query-metrics/SKILL.md
- sentry-fix-issues.agents/skills/sentry-fix-issues/SKILL.md
Also found in 3 other repositories
The same file, byte for byte, in the weekly crawl of public GitHub.
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
No reports yet. Be the first to say whether it worked.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool registry_write, action report. How to connect one.

