ops-deploy
What this skill does
The skill 'ops-deploy' is a deployment status monitoring tool that checks the status of deployments across various platforms (ECS, Vercel, etc.). It reads deployment information, checks CI/CD pipeline
github/davepoon - Secrets Management - 3.3k stars
Threat analysis
Skill info
pkg:github/davepoon/buildwithclaude@faa769d?skill=ops-deployAssessments (2)
Secrets Management
Secrets Management via local-llm-review
SKILL.md
The skill references and relies on AWS and Vercel credentials, which are resolved using Doppler secrets (`doppler secrets get ...`). This could be a risk if the Doppler integration is not properly secRuntime Context
Runtime Context via local-llm-review
SKILL.md
The skill reads from `${CLAUDE_PLUGIN_DATA_DIR}/preferences.json` and `${CLAUDE_PLUGIN_DATA_DIR}/daemon-health.json`. If these files are not properly secured, they could be a vector for tampering or dBadge
Add the Anomity scan badge for ops-deploy to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of ops-deploy? Report an issue or request a rescan.




