Review deployment
Git-versioned agent memory: agents that never make the same mistake twice. Anthropic-Skill folder standard, multi-runtime (Claude Code, Cursor, Gemini CLI, OpenCode).
npx -y skills add sordi-ai/skill-everything --skill review-deploymentAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 17 stars17 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Apply when reviewing code or planning a deployment. Pre-merge checks, migration ordering, rollback strategy, post-deploy verification.
The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
2.9 KB, as published. Nobody here has run it
Sub-Skill: Review & Deployment Process
<!-- target: ~800 tokens (real tiktoken count) -->Purpose: Prevents deployment accidents and ensures reviews are more than rubber-stamping. Concrete checklists the agent runs through before every PR and deployment.
PR Review Checklist (Agent runs this before opening a PR)
Correctness
- All new functions have tests
- Existing tests pass (
npm test/pytest/ etc.) - Edge cases covered: null/undefined, empty arrays, negative numbers
- No TODO comments without a linked ticket
Security
- No secrets or API keys in code (not even in comments)
- User input is validated before flowing into DB queries or shell commands
- New endpoints have authentication/authorization
- No
eval(),exec(), or dynamic SQL strings without prepared statements
Performance
- No N+1 queries (database queries in loops)
- Large datasets are paginated, not loaded entirely
- New indexes for new WHERE clauses in queries
Maintainability
- Complex logic is commented (the why, not the what)
- No duplicated code blocks (DRY)
- Dependencies updated in
package.json/requirements.txt
Deployment Checklist
Before Deployment
- Check migrations: Are all DB migrations backward-compatible? (No DROP COLUMN without prior deprecation cycle)
- Feature flags: New features behind a feature flag? Especially for large changes.
- Rollback plan: How to roll back if something goes wrong? Documented?
- Monitoring: Are alerts set up for new critical paths?
Deployment Order (for microservices)
- First: Database migrations (additive changes)
- Then: Backend services (new version)
- Last: Frontend (new version)
- Never: Frontend before backend when there are API changes
After Deployment
- Health check endpoint responds with 200
- Error rate in monitoring not elevated (observe for 5 minutes)
- Critical user flows manually tested (login, main feature, checkout)
Escalation Rules
| Situation | Action |
|---|---|
| Test coverage drops below 70% | Block PR, request additional tests |
| Security vulnerability in dependency | Patch immediately, no merge until fixed |
| Production errors > 1% error rate | Rollback immediately, then analyze |
| Deployment takes > 30 min | Abort, investigate root cause |
Why This Sub-Skill Earns Stars
The agent never forgets security checks or deployment order. Every PR is reviewed as if a senior developer went through the checklist — automatically.