Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/monkilabs/opencastle/deployment-infrastructurenpx skills add monkilabs/opencastle --skill deployment-infrastructuregit clone --depth 1 https://github.com/monkilabs/opencastleWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/monkilabs/opencastle/deployment-infrastructure)<a href="https://agentmods.dev/skills/monkilabs/opencastle/deployment-infrastructure"><img src="https://agentmods.dev/badge/skills/monkilabs/opencastle/deployment-infrastructure.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00048 | $0.00545 |
| Opus 5 | $0.00024 | $0.00272 |
| Sonnet 5 | $0.00010 | $0.00109 |
| Haiku 4.5 | $0.00005 | $0.00055 |
Grade A, and why
deployment-infrastructure scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
Gate a release on lint + test + build all exiting 0 and no draft PRs, then semver-tag with a changelog categorized Features / Fixes / Breaking. Verify with `curl -sI https://example.com | grep -E 'HTTP|Strict'` — homepag What it actually says
Deployment Infrastructure
See .opencastle/stack/deployment-config.md for full architecture, env vars, cron jobs, caching headers.
Environment Variables
Precedence: .env (committed defaults) → .env.local (git-ignored) → .env.production / .env.preview → platform-injected (highest). Gitignore .env.local, .env.*.local.
Validate the whole environment with one Zod schema at startup, not at point of use. SCREAMING_SNAKE_CASE; PUBLIC_*/NEXT_PUBLIC_* is browser-exposed, SECRET_*/*_SECRET server-only.
CI/CD Pipeline
main → production, feature/* and fix/* → preview, all automatic. Stages in order: install (always --frozen-lockfile in CI) → lint → test → production build → deploy.
Cron route handlers must return 401 unless the authorization header equals Bearer ${process.env.CRON_SECRET}.
Caching Strategy
Set per-asset via framework headers() config or CDN rules — never a blanket no-store.
| Asset Type | Cache-Control |
|---|---|
| Hashed assets (JS, CSS), images, fonts | public, max-age=31536000, immutable |
| Favicon / manifest | public, max-age=86400 |
| SSG HTML | public, max-age=0, must-revalidate |
| API responses | private, no-cache |
| ISR pages | public, s-maxage=3600, stale-while-revalidate=86400 |
Security Headers
Load security-hardening skill for full CSP inventory and header configuration.
Release & Rollback
Gate a release on lint + test + build all exiting 0 and no draft PRs, then semver-tag with a changelog categorized Features / Fixes / Breaking. Verify with curl -sI https://example.com | grep -E 'HTTP|Strict' — homepage 200, headers correct.
A failed release gets rolled back immediately, not patched forward. Prefer platform rollback (promote last good deploy) over git revert -m 1 HEAD && git push; re-run the curl -sI check before calling it resolved.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 43 lines · 48 tokens per session scan A a814ae351450
deployment-infrastructure is a skill published in the GitHub repository monkilabs/opencastle (61 stars, last pushed 6d ago), licensed MIT. It adds 48 tokens to every session and 545 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
product-architect
Complete product development system with 80 agents and 36 frameworks. Use when the user wants to build a product, write a PRD, plan an MVP or roadmap, design an app, research a market or check whether a feature already exists or is novel, do competitive analysis, run a security audit, build a financial model, plan…
codex-delegation
Use when a coding task would benefit from delegating work to Codex in the background — a deep independent second opinion, security or architecture analysis, or a parallel implementation running while the session continues. Lets Claude drive the codex companion itself (task, review, status --wait, result) without the…
cursor-delegation
Use when a coding task would benefit from delegating work to Cursor in the background — fast parallel implementation, scaffolding, or an everyday review running while the session continues. Lets Claude drive the cursor companion itself (task, review, status --wait, result) without the user typing /cursor: commands.
cursor-cli-runtime
Internal helper contract for calling the cursor-companion runtime from Claude Code.
cursor-prompting
Internal guidance for composing cursor-agent prompts and picking models for coding, review, diagnosis, and research tasks inside the Cursor Claude Code plugin.
goal-runner
Use when the user asks to advance, continue, or work on the project's long-horizon goal (or to set one up) — the policy for goal-driven increments driven through the goal companion, one increment at a time, delegated via the codex/cursor delegation skills, honestly recorded.