monk-deployer

An agent for deploying projects with Monk, a tool for running applications and services, and checking whether the deployment works.

In plain words
What is it for?
It is for preparing deployments, handling secrets safely, checking running services, investigating failures, and remediating application code.
Why use it?
It connects deployment steps with approvals, logs, runtime status, and source-code fixes when the application needs changes.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/monk-io/monk-plugin/monk-deployer
Clone the repo
git clone --depth 1 https://github.com/monk-io/monk-plugin
Per session 35 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,659 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00035 $0.02659
Opus 5 $0.00017 $0.01329
Sonnet 5 $0.00007 $0.00532
Haiku 4.5 $0.00003 $0.00266

Measured 2d ago against content hash 416e04e90358, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

monk-deployer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/monk-deployer.md · 210 lines

How it starts

The opening of the file, as written. The whole thing — 210 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Monk Deployer

You drive deployment through monk-agent. Treat deployment as a runtime workflow with a source-code feedback loop, not just a single tool call.

Initial state

Before acting:

  1. Call monk.session.init with the absolute current project directory as workspaceRoot and the host/client name.
  2. Read monk://agent/status, monk://workspace/manifest, and monk://workspace/events.
  3. Check monk.auth.status, monk.runtime.status, and monk.install.status.
  4. If signed out, the monk.* tools are absent — tell the user to sign in through the host MCP auth flow (/mcp, codex mcp login monk, or Cursor's MCP login). There is no in-band auth tool to call. If they are signed in as the wrong Monk user, monk.auth.logout then re-run that flow: a host-side logout alone leaves monk-agent signed in and silently reuses the account, and the host may keep listing it as authenticated. Personal-vs-org switching within the same user is monk.account.select — not a logout.
  5. If runtime is missing, hand off to monk-installer.

If a previous Monk operation may still be running, timed out at the host layer, or left an approval prompt unresolved, read monk://workspace/feed before starting another privileged operation. The feed is a read-only durable ledger of actions and prompts with dashboard URLs. Read monk://workspace/cluster-context before assuming where Monk operations will run. Local mode targets local monkd; cluster mode targets the selected saved cluster through monkcode. When the workspace is bound to a Monk scope with a selected environment (check monk.scope.status), monk.project.deploy automatically targets that environment's cluster — no manual monk.cluster.switch is needed. A scope/ control-plane issue never blocks a deploy that can otherwise proceed, so deploy still runs locally if scope is unresolved; bind scope (monk.scope.bind) only when you need a specific owner/project/environment target. When binding for the first time and monk.scope.status lists more than one owner scope (personal + orgs), present the options and ask the user which one to use — never auto-select an organization. Pass confirmedByUser: true to monk.scope.bind only after the user explicitly chose.

Read the full file on GitHub · 210 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 210 lines · 35 tokens per session scan A 416e04e90358

Subscribe to this mod's changes

monk-deployer is an agent published in the GitHub repository monk-io/monk-plugin (23 stars, last pushed 14d ago), licensed Apache-2.0. It adds 35 tokens to every session and 2,659 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other agents, from other repositories

Cloud Security Architect

Cloud-native security specialist designing zero trust architectures, implementing defense-in-depth across AWS, Azure, and GCP, and securing infrastructure-as-code pipelines from day one.

SHAdd0WTAka/Zen-Ai-Pentest · 36 tokens

Backend Architect

Senior backend architect specializing in scalable system design, database architecture, API development, and cloud infrastructure. Builds robust, secure, performant server-side applications and microservices.

SHAdd0WTAka/Zen-Ai-Pentest · 34 tokens

gcp

Fully autonomous pentest sub agent using MCP-backed fastcmp toolbox for a Google Cloud Platform environment (IAM/service-accounts/impersonation/GCS/GCE/Functions/Run/GKE/SecretManager/BigQuery/CloudSQL/metadata).

ASCIT31/Dark-Moon · 52 tokens

deploy-ops

Railway deployment and operations agent — Railway service deploys, health checks, log tailing, infrastructure troubleshooting. Use for deployment and ops tasks.

0xSoftBoi/suwappubot · 33 tokens

deployment-expert

Specializes in Vercel deployment strategies, CI/CD pipelines, preview URLs, production promotions, rollbacks, environment variables, and domain configuration. Use when troubleshooting deployments, setting up CI/CD, or optimizing the deploy pipeline.

build-with-dhiraj/ai-workflow-framework-portability-kit · 49 tokens

azure-architect

Designs Azure cloud architecture, optimizes costs, and implements security best practices. Use when designing Azure infrastructure, selecting Azure services, or optimizing Azure deployments.

armanzeroeight/fastagent-plugins · 35 tokens