Convex Deploy Guard
Classify and announce the Convex deployment target before any deployment-affecting command; consent-gated prod
- What
- Classify and announce the Convex deployment target before any deployment-affecting command; consent-gated prod
- Cost
- Free
- Needs
- a Convex project (see the repo README for setup); the official Convex MCP for the full workflow
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — the standing discipline against "the command landed on the wrong deployment": identify, announce, then act. Classifies every target as local-anonymous | dev | preview | prod (from `CONVEX_DEPLOYMENT`, `convex.json`, `CONVEX_DEPLOY_KEY`, or the official Convex MCP `status` tool), announces it in one line before any deployment-affecting command, and requires a FRESH explicit yes per action per session for anything touching prod — a yes from earlier, or for another target, never carries. Teaches the two prod MCP flags as different risk levels that must never be paired by default: `--cautiously-allow-production-pii` (read-only prod audit) vs `--dangerously-enable-production-deployments` (mutating prod). Plus an absolute read-only session mode. No equivalent among the 16 get-convex fiches of lot 32 — it's a safety discipline, not a deploy tool. By @get-convex, listed here with credit to its creator. Honest caveats: requires a Convex project and the official MCP for the full workflow; it changes nothing itself, it governs everything around it. Skill Harbor never reviews the code, review it yourself before use.
Version:
Install
Prerequisites: a Convex project (see the repo README for setup); the official Convex MCP for the full workflow Install "Convex Deploy Guard" for me. Give my agent the standing discipline: classify and announce the Convex deployment target (local-anonymous | dev | preview | prod) before every deployment-affecting command, require fresh explicit consent per action per session for prod, keep the two prod MCP flags split by risk level, and honor absolute read-only session mode Repository: https://github.com/get-convex/agent-skills/blob/main/skills/convex-deploy-guard/SKILL.md 1. Fetch the SKILL.md file for the get-convex-agent-skills-convex-deploy-guard skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md into the agent's skills directory, in a folder named "get-convex-agent-skills-convex-deploy-guard". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. install the Convex MCP, know my deployment names). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.