Borrowing it
Nothing to install: this file belongs to c9r-io/orchestrator. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/c9r-io/orchestrator/main/.claude/skills/deploy-gh-k8s/SKILL.mdgit clone --depth 1 https://github.com/c9r-io/orchestratorWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/c9r-io/orchestrator/deploy-gh-k8s)<a href="https://agentmods.dev/skills/c9r-io/orchestrator/deploy-gh-k8s"><img src="https://agentmods.dev/badge/skills/c9r-io/orchestrator/deploy-gh-k8s/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/c9r-io/orchestrator/deploy-gh-k8s"><img src="https://agentmods.dev/badge/skills/c9r-io/orchestrator/deploy-gh-k8s.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00039 | $0.00432 |
| Opus 5 | $0.00019 | $0.00216 |
| Sonnet 5 | $0.00008 | $0.00086 |
| Haiku 4.5 | $0.00004 | $0.00043 |
Grade A, and why
deploy-gh-k8s scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Deploy GH K8s
Deploy only after proving that the target repository owns a Kubernetes deployment contract.
Applicability Gate
From the target repository root, require all of these before using Kubernetes:
test -x deploy/upgrade.sh
test -d k8s/base
kubectl config current-context
deploy/upgrade.sh and k8s/base/ are outputs of the project-bootstrap template; they are not present in the Agent Orchestrator repository. When either path is absent, report the Kubernetes portion as not applicable. Do not invent manifests, copy hidden template assets into the repository, or treat a successful Rust build as a deployment.
Workflow
-
Resolve the branch and inspect the latest relevant GitHub Actions run with
gh run listandgh run view. -
Stop before deployment when required CI is not successful. Diagnose and fix only when the user also authorized implementation.
-
Confirm the current Kubernetes context, namespace, and intended release revision with the user-visible evidence.
-
Run the repository-owned upgrade script:
./deploy/upgrade.sh -
Monitor rollout state with
kubectl get,kubectl rollout status, events, and bounded log tails. -
Run the repository-owned readiness or health checks and report the exact deployed revision.
Agent Orchestrator Repository
This repository ships local binaries and an optional Slack gateway but no deploy/ or k8s/ tree. For a release-readiness request here, use project-readiness; for daemon operations, use ops. Deployment requires a separately supplied target or deployment contract.
Guardrails
- Never switch Kubernetes context or namespace implicitly.
- Never deploy after failed or pending required CI.
- Prefer bounded logs and exact resource names.
- A failed rollout is a failure, even if some pods are healthy.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 46 lines · 39 tokens per session scan A cbd27aa514d0
deploy-gh-k8s is a skill published in the GitHub repository c9r-io/orchestrator (21 stars, last pushed 8d ago), licensed MIT. It adds 39 tokens to every session and 432 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
cw-gates
Use before claiming any Codewhale change is done, green, or ready to land: the focused-to-broad verification ladder, the budget checks CI enforces, and the rules for what counts as a passing test.
cw-land
Use when turning verified Codewhale work into commits, branches, or a merge: choosing direct-main vs. worktree vs. integration branch, preserving contributor credit, and honoring the gate artifact before merging.
cw-orient
Use at the start of any Codewhale work session, or when unsure which checkout, branch, or worktree is authoritative: establish live repo truth before reading a plan or editing a file.
contributor-onboarding
Help a new contributor get productive on this checkout - inspect sync state against main, build, run the repository's exact verification gate, and produce a local what's-new digest. Never fetches, pulls, or modifies a dirty tree on its own. Explicit-only.
codew-release-qa-sweep
Use before claiming Codewhale release work is done: run the full gate sweep and list the manual QA targets.
gh-close-issues
Close resolved Codewhale issues only after verifying the landed commit/behavior, with a positive crediting comment; never from title alone.