Skills / Go-to-market / stage-launch

stage-launch

Phase 2 of building a Claude Managed Agent — turn a validated build sheet into exact API payloads and a resumable BYOK curl launch script, then launch (environment → agent → session → kickoff) using the founder's OWN Anthropic key. Use when the user says "launch it", "deploy the agent", "create the agent now", or when the orchestrator routes phase=stage-launch. payload_generator.py emits the four ordered payloads; launch_script_writer.py writes launch.sh that reads $ANTHROPIC_API_KEY at runtime and never embeds it; payload_validator.py runs a pre-launch check including an API-key-leak scan. No tool in this skill makes network calls — the user runs launch.sh themselves. Distinct from interview (planning) and grade-iterate (the outcome loop).

alirezarezvaniIndexed from GitHubFor Founders

By alirezarezvani on GitHub, licence MIT. Redistributed unchanged with its licence and attribution, from the source at commit 19392f7, the version we scanned. The description is ours.

SecurityReview before userisk 22 of 100 · SkillSpector (static rules)
Rating—0 verified reviews
Uses this month00 installs
Job done—reported after each use

About this skill

Summary from the skill's own text
Use it whenTurn the build sheet into runnable artifacts, then let the founder launch with their own key. **No script here touches the network or the key** — the user runs `launch.sh`.
You provideSee the skill's instructions.
You receiveSee the skill's instructions.
It needsRuns 3 scripts: scripts/launch_script_writer.py, scripts/payload_generator.py, scripts/payload_validator.py.
It won'tNot stated by the author.
Try asking“Use the stage-launch skill.”

What's inside

Every file in version 1.0.0, exactly as you will install it
Instructions 1Scripts 3References 37 files · 21.5 KB
Scripts can:Network access
SKILL.mdInstructions · 77 lines · 3.8 KB
medium · Skill declares no tool scope ('permissions' or 'allowed-tools') but code capabilities were detected: file_read, file_write, shell. · line 1
Without declared permissions the skill's intent is opaque and cannot be validated.

Phase 2 — Stage → Launch

Turn the build sheet into runnable artifacts, then let the founder launch with their own key. No script here touches the network or the key — the user runs launch.sh.

Workflow

  1. Generate payloads.

``bash python3 scripts/payload_generator.py \ --sheet ./my-agent/build-sheet.json --out-dir ./my-agent # -> ./my-agent/payloads/{01-environment,02-agent,03-session,04-kickoff}.json ` Agent toolset → always_allow; every MCP toolset → always_ask (baked into the agent payload's permission_policies`).

  1. Write the launch script.

``bash python3 scripts/launch_script_writer.py --out-dir ./my-agent ` launch.sh creates environment → agent → session → kickoff **in order**, chaining IDs, and **resumes** on re-run (each step skips if its *.id file exists). It reads $ANTHROPIC_API_KEY` at runtime.

  1. Validate before launch.

``bash python3 scripts/payload_validator.py --dir ./my-agent ` FAIL blocks — especially a key_leak` finding. Fix and re-run.

  1. Minimal key step (never in chat). Check the shell first:

``bash [ -n "$ANTHROPIC_API_KEY" ] && echo "key present" || echo "export ANTHROPIC_API_KEY=... first" `` Point the founder to platform.claude.com → API keys. Never print the key to chat, never write it to a file.

  1. Launch + watch the first poll.

``bash export ANTHROPIC_API_KEY=... # in their shell, not in chat ./my-agent/launch.sh ` Mark checkpoints with Console deep links. Then goal_state.py set --phase grade-iterate` and advance.

Hard rules (API-key safety)

  • The key never enters chat, a file, a payload, or a log. launch.sh reads it

from the environment; payload_validator.py scans for sk-ant-… leaks and FAILs.

  • Sequential launch. environment → agent → session → kickoff. Watch the first

poll foreground before declaring success.

  • Resumable. Re-running launch.sh continues from the last created ID.

Forcing-question library (recommend + cite)

  1. "Is the key in your shell env already?" *Recommend:* check $ANTHROPIC_API_KEY

before anything. *Cite:* this SKILL, key-safety rules.

  1. "Cloud or self-hosted environment?" *Recommend:* cloud for v0. *Cite:*

cma-primitives.md (environment).

  1. "Any MCP server in the payload?" *Recommend:* keep it always_ask. *Cite:*

cma-primitives.md (permissions).

  1. "Did the first poll return idle/running cleanly?" *Recommend:* watch it

foreground before moving on. *Cite:* cma-primitives.md (session lifecycle).

Tools

  • scripts/payload_generator.py — build sheet → 4 ordered API payloads.
  • scripts/launch_script_writer.py — resumable BYOK curl launcher (no key handling).
  • scripts/payload_validator.py — pre-launch check + API-key-leak scan.

Reviews

Only from people who installed it

No reviews yet.