local-deployment

A guide for starting a project's local Docker environment for testing and operator review.

In plain words
What is it for?
Use it when DevOps needs to deploy a project locally so QA can run tests and people can open the application in a browser for manual checks.
Why use it?
It helps bring up the required application services and data stores while avoiding interference with unrelated containers, hard-coded ports, or exposed secrets.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/evolplus/talos/local-deployment
Any agent
npx skills add evolplus/talos --skill local-deployment
Clone the repo
git clone --depth 1 https://github.com/evolplus/talos

Made for: Claude Code, Codex.

Per session 55 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 9,496 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00055 $0.09496
Opus 5 $0.00028 $0.04748
Sonnet 5 $0.00011 $0.01899
Haiku 4.5 $0.00006 $0.00950

Measured 2d ago against content hash df045f8601e1, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

local-deployment scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

if curl -sf -o /dev/null --max-time 3 "$url"; then return 0; fi
skills/local-deployment/SKILL.md · 635 lines

How it starts

The opening of the file, as written. The whole thing — 635 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Local Deployment

When to use

You are DevOps, dispatched against a task in status ready-for-deploy. Your job is to bring the local environment up — typically FE + BE + datastores composed via Docker — so two consumers can work against it:

  1. QA-Exec runs the test runner against base_url / api_base_url per the kit's QA-Exec Run Contract.
  2. The operator (PM, designer, eng lead) opens the running app in a browser to manually trial the feature before sign-off — confirming the feature looks and behaves right against intent, not just against test assertions.

The skill covers Docker-based composition, port discovery (probe-then-bind, never hardcode), and deploy-report population. For non-Docker stacks (rare in modern projects), consult docs/architecture.md for the project's documented run mode.

Project-scoped container discipline (safety rule)

The kit dispatches DevOps inside an operator's environment that almost always has unrelated containers running — the operator's personal Postgres, another project's Redis, a sibling repo's docker-compose stack. A careless docker compose down -v would nuke them all. DevOps's blast radius is scoped to the current project's containers only.

Project slug — single source of truth

Determine the project slug (the Compose project name) once at deploy start; thread it through every subsequent docker command. Lookup priority:

  1. COMPOSE_PROJECT_NAME environment variable if set (most explicit; respects the operator's intent).
  2. SRS header's project name field if Phase 0 read SRS successfully — sanitize: lowercase(name).replace(/[^a-z0-9]+/g, '-').replace(/(^-|-$)/g, ''). Example: "Stats Overflow"stats-overflow.
  3. Working-directory basename as a fallback when neither of the above is available. Same sanitization.

Record the chosen slug at the top of the deploy report (## Test Environment block adds project_slug: <slug> field) so QA-Exec and the operator can verify.

Every command takes the slug

Read the full file on GitHub · 635 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 635 lines · 55 tokens per session scan A df045f8601e1

Subscribe to this mod's changes

local-deployment is a skill published in the GitHub repository evolplus/talos (8 stars, last pushed 28d ago), licensed Apache-2.0. It adds 55 tokens to every session and 9,496 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

deploy-docker-compose

Run the Omnigent server as a Docker compose stack (server + Postgres) on any Docker host — your laptop, a VPS, EC2 by hand, or as the base layer of any container-platform deploy. Invoke when the user wants to build the image, bring up the compose stack, debug the stack on a host they already have, or extend the stack…

omnigent-ai/omnigent · 84 tokens

reproduce-issue

The single skill for reproducing an nx issue. Given a GitHub issue number (human entry) OR explicit repro parameters (agent entry), it runs the reproduction ENTIRELY inside an isolated Docker sandbox — gVisor on Linux, the Docker VM on macOS — so the untrusted repro's install scripts and commands never execute on the…

nrwl/nx · 91 tokens

timoni

Use when deploying applications to Kubernetes with Timoni. Covers installing and upgrading module instances from OCI registries, composing multi-app deployments with bundles, injecting values from clusters or CI with runtimes, targeting multiple clusters, and authoring, testing, signing and publishing modules with CUE.

stefanprodan/timoni · 59 tokens

atmos-aws-ecr

AWS ECR commands in Atmos: atmos aws ecr login, ECR auth integrations, Docker credential writes, registry login via identity or explicit registry.

cloudposse/atmos · 36 tokens

windows-builder

Build Windows images with Packer using WinRM communicator and PowerShell provisioners. Use when creating Windows AMIs, Azure images, or VMware templates.

hashicorp/agent-skills · 33 tokens

release-openclaw-plugin-testing

Plan and run pre-release OpenClaw plugin validation across bundled plugins, package artifacts, lifecycle commands, doctor/fix, config round-trip, gateway startup, SDK compatibility, Docker E2E, Package Acceptance, and Testbox proof.

openclaw/openclaw · 54 tokens