Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Classify + announce the target Convex deployment before any deployment-affecting command; fresh explicit consent for prod actions; session read-only mode.
.claude/skills/get-convex-convex-deploy-guard/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 154% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 21% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 33% | 0% |
| case-08 | ✗→✓ | ▲ Improved | -24% | 0% |
| case-09 | ✗→✓ | ▲ Improved | -67% | 0% |
<!-- GENERATED from convex-agents content/capabilities/deploy-guard.json — do not edit by hand. -->
Deployments are not interchangeable, and most incidents start with a command aimed at the wrong one. Every Convex project has several (personal dev, preview, prod — often across multiple projects on one machine). This guard is the standing discipline: identify, announce, then act — and treat prod as consent-gated, per action, per session.
CONVEX_DEPLOYMENT in .env.local, convex.json, and whether CONVEX_DEPLOY_KEY is set; or call the official Convex MCP status tool. Classify the target: local-anonymous | dev | preview | prod. If two sources disagree, resolve before proceeding.target: dev (joyful-capybara-123, personal dev). Never run the command in the same breath as discovering the target — announce first.npx convex deploy (when it resolves to prod), npx convex run --prod, env set on prod, snapshot import/export on prod, or starting the MCP with prod access — state exactly what will change on which deployment and get an explicit yes in THIS session. A yes given earlier, or for a different target, does not carry.--deployment dev). The two prod flags are DIFFERENT risk levels — keep them split: a read-only prod audit (advisor/insights reading data/logs/insights) passes ONLY --cautiously-allow-production-pii (read tools); --dangerously-enable-production-deployments (which enables MUTATING prod tools) stays OFF unless the user explicitly asked to CHANGE prod this session. Never pair them by default — 'look at prod' must not silently grant 'mutate prod'.run, no imports; start the MCP with --disable-tools run,envSet,envRemove.npx convex env list fingerprints) — never guess.| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 7,563 | 38,977 | +415% | 1 | 1 | 0% | 1,034 | 2,624 | +154% | 0 | 0 | — |
case-02 | fail→pass | 11,669 | 9,993 | -14% | 1 | 1 | 0% | 1,897 | 2,290 | +21% | 0 | 0 | — |
case-03 | fail→fail | 8,667 | 6,020 | -31% | 1 | 1 | 0% | 1,327 | 1,594 | +20% | 0 | 0 | — |
case-04 | pass→pass | 3,790 | 3,444 | -9% | 1 | 1 | 0% | 658 | 1,381 | +110% | 0 | 0 | — |
case-05 | pass→pass | 9,581 | 6,326 | -34% | 1 | 1 | 0% | 1,880 | 1,806 | -4% | 0 | 0 | — |
case-06 | pass→pass | 12,728 | 8,348 | -34% | 1 | 1 | 0% | 1,876 | 2,097 | +12% | 0 | 0 | — |
case-07 | fail→pass | 6,969 | 3,064 | -56% | 1 | 1 | 0% | 884 | 1,174 | +33% | 0 | 0 | — |
case-08 | fail→pass | 10,447 | 2,880 | -72% | 1 | 1 | 0% | 1,596 | 1,217 | -24% | 0 | 0 | — |
case-09 | fail→pass | 20,078 | 3,046 | -85% | 1 | 1 | 0% | 3,576 | 1,174 | -67% | 0 | 0 | — |
case-10 | fail→pass | 16,798 | 1,859 | -89% | 1 | 1 | 0% | 2,312 | 1,085 | -53% | 0 | 0 | — |
case-11 | pass→pass | 14,107 | 7,668 | -46% | 1 | 1 | 0% | 2,394 | 2,104 | -12% | 0 | 0 | — |
case-12 | fail→fail | 11,604 | 2,459 | -79% | 1 | 1 | 0% | 1,572 | 1,103 | -30% | 0 | 0 | — |
case-13 | pass→pass | 9,051 | 3,660 | -60% | 1 | 1 | 0% | 1,156 | 1,377 | +19% | 0 | 0 | — |
case-14 | pass→pass | 11,035 | 5,498 | -50% | 1 | 1 | 0% | 1,401 | 1,512 | +8% | 0 | 0 | — |
case-15 | fail→pass | 15,260 | 3,940 | -74% | 1 | 1 | 0% | 1,991 | 1,323 | -34% | 0 | 0 | — |
case-16 | fail→pass | 16,971 | 6,125 | -64% | 1 | 1 | 0% | 2,332 | 1,642 | -30% | 0 | 0 | — |
case-17 | fail→pass | 7,659 | 5,730 | -25% | 1 | 1 | 0% | 1,105 | 1,524 | +38% | 0 | 0 | — |
case-18 | pass→pass | 10,046 | 4,925 | -51% | 1 | 1 | 0% | 1,288 | 1,439 | +12% | 0 | 0 | — |
case-19 | pass→pass | 13,115 | 5,883 | -55% | 1 | 1 | 0% | 1,771 | 1,564 | -12% | 0 | 0 | — |
case-20 | fail→fail | 13,451 | 4,478 | -67% | 1 | 1 | 0% | 1,862 | 1,514 | -19% | 0 | 0 | — |
case-21 | pass→pass | 11,359 | 4,140 | -64% | 1 | 1 | 0% | 1,810 | 1,551 | -14% | 0 | 0 | — |
case-22 | fail→pass | 15,470 | 2,330 | -85% | 1 | 1 | 0% | 2,346 | 1,087 | -54% | 0 | 0 | — |
case-23 | pass→pass | 11,536 | 3,224 | -72% | 1 | 1 | 0% | 1,641 | 1,192 | -27% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted. The headline lift of +43 percentage points is the difference between those two pass rates over the 23 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.