DF deploy
Deploy and infrastructure: web deploy, dev branches, cron, package install, shell configuration.
Deploy and infrastructure: web deploy, dev branches, cron, package install, shell configuration.
As a process F 32/100 · Will not run — References files that are not bundled: scripts/*.sh
What is at stake
Medium-severity findings: the skill is probably honest, but read what alarmed the scanner.
Below is the worst case for this category. The finding here is medium: the guard saw a sign, not a proof.
The skill asks for more than the task needs: broad tool access, credential environment variables, binaries. Every extra permission widens the damage from a mistake or a compromise.
Narrow allowed-tools and the variable list to the minimum; replace binaries with readable sources or scripts.
How to improve
- Say in the description WHEN to use the skill ("use when…", example requests): that is the agent's main cue.
- The text references files that are not there: add them or drop the references.
- Your own cases (evals/evals.json, 4–6 real requests with expected answers): the full check would then run those instead of a model-drafted suite.
- A spec.yaml with trigger phrases and assertions — a behaviour contract for CI; `skilltest init` writes a template.
Guard findings · 22
✓ No critical or high findings
Medium and low: 22
-
medium Broad scope
meta-broad-allowed-toolsSKILL.md:1Broad tool permissions pre-approved: Bashallowed-tools: Read Write Bash Grep Glob Edit Agent
-
low Dangerous commands
cmd-cron-mentionreferences/headless-cron-creator.md:145Mentions editing / listing crontab (quoted — discussed, not commanded)Solution: Check `crontab -l` manually. Restore from `~/.claude/crontab-backups/`.
quoted -
low Dangerous commands
cmd-background-processreferences/pid-resolution.md:20Starts a background / autostarted process (quoted — discussed, not commanded)- You used `nohup`, `setsid`, or any other wrapper binary
quoted -
low Dangerous commands
cmd-background-processreferences/pid-resolution.md:30Starts a background / autostarted processnohup my_server --port 8080 > log 2>&1 &
-
low Dangerous commands
cmd-background-processreferences/pid-resolution.md:82Starts a background / autostarted processnohup my_server > log 2>&1 &
-
low Dangerous commands
cmd-background-processreferences/pid-resolution.md:109Starts a background / autostarted processnohup my_server > log 2>&1 &
-
low Dangerous commands
cmd-background-processreferences/preferred-patterns.md:26Starts a background / autostarted processnohup python3 -m http.server 8080 --bind 127.0.0.1 > log 2>&1 &
-
low Dangerous commands
cmd-background-processreferences/preferred-patterns.md:47Starts a background / autostarted process (quoted — discussed, not commanded)Any hit requires manual inspection: if the backgrounded command is a shell builtin or simple exec it may be safe; if it is anything that daemonizes, forks, or goes through `nohup`/`setsid`, the captur
quoted -
low Dangerous commands
cmd-background-processreferences/preferred-patterns.md:55Starts a background / autostarted processnohup python3 -m http.server 8080 > log 2>&1 &
-
low Dangerous commands
cmd-background-processreferences/public-web-deploy.md:155Starts a background / autostarted processsystemctl enable --now fail2ban && fail…ent status
-
low Dangerous commands
cmd-background-processreferences/shell-process-patterns.md:7Starts a background / autostarted process| Background start | Ad-hoc long-running child in a script or session | Redirect fd 0/1/2, capture real PID, disown if parent exits |
-
low Dangerous commands
cmd-background-processreferences/shell-process-patterns.md:8Starts a background / autostarted process (documentation table row)| Daemonization | Process must survive terminal close, become session leader | `setsid` + fd redirect + write PID file atomically |
table -
low Dangerous commands
cmd-background-processreferences/shell-process-patterns.md:17Starts a background / autostarted process (quoted — discussed, not commanded)- Starting background processes (`&`, `nohup`, `disown`, `setsid`, daemonization).
quoted -
low Dangerous commands
cmd-background-processreferences/shell-process-patterns.md:36Starts a background / autostarted process (documentation table row)| starting a background process, `&`, `nohup`, `disown`, `setsid`, daemonize | `starting-processes.md` | Launch-time patterns and fd/session rules |
table -
low Dangerous commands
cmd-background-processreferences/shell-process-patterns.md:78Starts a background / autostarted process (quoted — discussed, not commanded)3. **Decide if `disown` is needed.** `disown $!` removes the job from the shell's job table so the shell does not send SIGHUP when it exits. Needed for scripts that start long-running children and ret
quoted -
low Dangerous commands
cmd-background-processreferences/starting-processes.md:8Starts a background / autostarted process (quoted — discussed, not commanded)This file covers the idioms for launching shell processes that outlive or run alongside the parent script: `&`, `nohup`, `disown`, `setsid`, and full daemonization. It does not cover PID capture (see
quoted -
low Dangerous commands
cmd-background-processreferences/starting-processes.md:16Starts a background / autostarted process (documentation table row)| Detach from job control but stay in session | `cmd & disown` | Removes from jobs table; still receives SIGHUP from controlling terminal loss. Use with `nohup` if terminal may close. |
table -
low Dangerous commands
cmd-background-processreferences/starting-processes.md:17Starts a background / autostarted process (documentation table row)| Fully detach — new session, new process group, no controlling terminal | `setsid cmd > log 2>&1 < /dev/null &` | Proper daemonization in one line. Survives parent exit, terminal loss, and signals to
table -
low Dangerous commands
cmd-background-processreferences/starting-processes.md:32Starts a background / autostarted processnohup long_running_task > /var/log/task.log 2>&1 &
-
low Dangerous commands
cmd-background-processreferences/starting-processes.md:41Starts a background / autostarted process (quoted — discussed, not commanded)- It does not create a new session (use `setsid` for that)
quoted -
low Dangerous commands
cmd-background-processSKILL.md:188Starts a background / autostarted process (documentation table row)| Detach from job control | `cmd & disown` |
table -
low Dangerous commands
cmd-background-processSKILL.md:189Starts a background / autostarted process (documentation table row)| Full detach, new session | `setsid cmd > log 2>&1 < /dev/null &` |
table
Files scanned: 25. Evidence is masked. Grey chips explain why severity was lowered.
Against the Agent Skills spec
- warning
description-no-whendescription does not say WHEN to use the skill (no "use when") - warning
missing-refreference to a missing file: scripts/*.sh - note
frontmatter-keyunknown frontmatter key "routing"
Process rating: all ten parameters 32/100
- 0Tools and files. 1 referenced file(s) missing: scripts/*.sh
- 0Result and completion. Does not say what the result is
- 0Inputs and preconditions. Does not say what the process needs to start
- 0Failures and branches. Linear process with no failure handling
- 20When it triggers. No condition that starts the skill
- 30Running it twice. 17 mutating operations with no state check
- 85Steps. 22 steps, 1 vague phrases
- 100Consistency. Name and required fields are in place
- 100Execution cost. Instruction body is 2245 tokens
- 100Progress reporting. Reports progress
- low The response is described with custom markup (11 tags): a typed call is more reliable
Everything here is measured from the skill text rather than judged by a model, so the numbers are checkable. A parameter weighs more when it is a more common reason for the process to stall.
Quality signals
- +5Description has no quoted example phrases that should trigger the skill
- +4Description does not say when NOT to use the skill (false activations)
- +3Description length 96: 120–800 characters recommended
- +3Output format is not stated: the model decides each time
- +4No input/output examples
- +1No license
- +2Single-language instructions
- +4Structure: 9 headings
- +3Step-by-step instructions: 22 items
- +4Reference files are cited in the instructions (24 of 24)
Quality base 70; lint remarks subtract, signals add up to 100. Result: 62.