netlify-deploy
Deploy web projects to Netlify using the Netlify CLI (`npx netlify`). Use when the user asks to deploy, host, publish, or link a site/repo on Netlify, including preview and production deploys.
Savant verdict: Review advised
SkillSpector or the source hub flagged patterns to review before use.
Live evaluation
59overall
47quality
66compliance
75grounding
48actionability
66efficiency
Why this score may understate the skillThe live evaluation is a chat-only run: the model follows the skill's instructions but can't execute its scripts, call tools or reach the network.
- Expects tools, MCP servers, installs or network access that a chat-only run doesn't have.
0 pass · 1 investigate · 7 fail across 8 cases. Jev accepted 8 of 19 LLM-drafted cases. Drafted and run by nvidia/nemotron-3-super-120b-a12b, validated and scored by jev-latest.
- Deploy my React Vite project to Netlify for testing. I want a preview URL to share with my team.positive case · fail
- Deploy my Next.js site to production on Netlify. The code is ready and I want it live at my custom domain later.positive case · fail
- I have a static HTML site in a folder called 'public'. Deploy it to Netlify and give me the URL.positive case · fail
- Deploy my WordPress site to Netlify. I have the PHP files and MySQL database ready.negative case · fail
- Deploy my Docker container to Netlify. I want to run my Node.js API as a service.negative case · fail
- Deploy my site to Netlify. I think it's linked but I'm not sure which site it's connected to.edge case · investigate
- Deploy my site to Netlify. I have a build script in package.json but I'm not sure if it's the right one for Netlify.edge case · fail
- Deploy this to Netlify. I think I'm logged in but I'm not seeing any site info when I check status.edge case · fail
Safety (NVIDIA SkillSpector)
Risk score
40/100
Recommendation
CAUTION
Severity
MEDIUM
Savant decision
Review advised
SkillSpector rated it CAUTION with a risk score of 20/100 or more; review the findings before use. SkillSpector 2.12.0, static analysis.
89 patterns found
- Privilege Escalation: .envhigh · references/cli-commands.md:95 · Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- MCP Rug Pull: npx netlifymedium · SKILL.md:1 · MCP server references in the skill manifest without version pinning are a rug-pull risk.
- MCP Rug Pull: npx netlifymedium · SKILL.md:3 · npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
- MCP Rug Pull: npx netlifymedium · SKILL.md:30 · npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
- MCP Rug Pull: npx netlifymedium · SKILL.md:31 · npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
- MCP Rug Pull: npx netlifymedium · SKILL.md:45 · npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
- MCP Rug Pull: npx netlifymedium · SKILL.md:55 · npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
- MCP Rug Pull: npx netlifymedium · SKILL.md:90 · npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
- MCP Rug Pull: npx netlifymedium · SKILL.md:97 · npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
- MCP Rug Pull: npx netlifymedium · SKILL.md:125 · npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
SKILL.md
--- name: netlify-deploy description: Deploy web projects to Netlify using the Netlify CLI (`npx netlify`). Use when the user asks to deploy, host, publish, or link a site/repo on Netlify, including preview and production deploys. --- # Netlify Deployment Skill Deploy web projects to Netlify using the Netlify CLI with intelligent detection of project configuration and deployment context. ## Overview This skill automates Netlify deployments by: - Verifying Netlify CLI authentication - Detecting project configuration and framework - Linking to existing sites or creating new ones - Deploying to production or preview environments ## Prerequisites - **Netlify CLI**: Installed via npx (no global install required) - **Authentication**: Netlify account with active login session - **Project**: Valid web project in current directory - When sandboxing blocks the deployment network calls, rerun with `sandbox_permissions=require_escalated`. - The deployment might take a few minutes. Use appropriate timeout values. ## Authentication Pattern The skill uses the **pre-authenticated Netlify CLI** approach: 1. Check authentication status with `npx netlify status` 2. If not authenticated, guide user through `npx netlify login` 3. Fail gracefully if authentication cannot be established Authentication uses either: - **Browser-based OAuth** (primary): `netlify login` opens browser for authentication - **API Key** (alternative): Set `NETLIFY_AUTH_TOKEN` environment variable ## Workflow ### 1. Verify Netlify CLI Authentication Check if the user is logged into Netlify: ```bash npx netlify status ``` **Expected output patterns**: - ✅ Authenticated: Shows logged-in user email and site link status - ❌ Not authenticated: "Not logged into any site" or authentication error **If not authenticated**, guide the user: ```bash npx netlify login ``` This opens a browser window for OAuth authentication. Wait for user to complete login, then verify with `netlify status` again. **Alternative: API Key authentication** If browser authentication isn't available, users can set: ```bash export NETLIFY_AUTH_TOKEN=your_token_here ``` Tokens can be generated at: https://app.netlify.com/user/applications#personal-access-tokens ### 2. Detect Site Link Status From `netlify status` output, determine: - **Linked**: Site already connected to Netlify (shows site name/URL) - **Not linked**: Need to link or create site ### 3. Link to Existing Site or Create New **If already linked** → Skip to step 4 **If not linked**, attempt to link by Git remote: ```bash # Check if project is Git-based git remote show origin # If Git-based, extract remote URL # Format: https://github.com/username/repo or git@github.com:username/repo.git # Try to link by Git remote npx netlify link --git-remote-url <REMOTE_URL> ``` **If link fails** (site doesn't exist on Netlify): ```bash # Create new site interactively npx netlify init ``` This guides user through: 1. Choosing team/account 2. Setting site name 3. Configuring build settings 4. Creating netlify.toml if needed ### 4. Verify Dependencies Before deploying, ensure project dependencies are installed: ```bash # For npm projects npm install # For other package managers, detect and use appropriate command # yarn install, pnpm install, etc. ``` ### 5. Deploy to Netlify Choose deployment type based on context: **Preview/Draft Deploy** (default for existing sites): ```bash npx netlify deploy ``` This creates a deploy preview with a unique URL for testing. **Production Deploy** (for new sites or explicit production deployments): ```bash npx netlify deploy --prod ``` This deploys to the live production URL. **Deployment process**: 1. CLI detects build settings (from netlify.toml or prompts user) 2. Builds the project locally 3. Uploads built assets to Netlify 4. Returns deployment URL ### 6. Report Results After deployment, report to user: - **Deploy URL**: Unique URL for this deployment - **Site URL**: Production URL (if production deploy) - **Deploy logs**: Link to Netlify dashboard for logs - **Next steps**: Suggest `netlify open` to view site or dashboard ## Handling netlify.toml If a `netlify.toml` file exists, the CLI uses it automatically. If not, the CLI will prompt for: - **Build command**: e.g., `npm run build`, `next build` - **Publish directory**: e.g., `dist`, `build`, `.next` Common framework defaults: - **Next.js**: build command `npm run build`, publish `.next` - **React (Vite)**: build command `npm run build`, publish `dist` - **Static HTML**: no build command, publish current directory The skill should detect framework from `package.json` if possible and suggest appropriate settings. ## Example Full Workflow ```bash # 1. Check authentication npx netlify status # If not authenticated: npx netlify login # 2. Link site (if needed) # Try Git-based linking first git remote show origin npx netlify link --git-remote-url https://github.com/user/repo # If no site exists, create new one: npx netlify init # 3. Install dependencies npm install # 4. Deploy (preview for testing) npx netlify deploy # 5. Deploy to production (when ready) npx netlify deploy --prod ``` ## Error Handling Common issues and solutions: **"Not logged in"** → Run `npx netlify login` **"No site linked"** → Run `npx netlify link` or `npx netlify init` **"Build failed"** → Check build command and publish directory in netlify.toml or CLI prompts → Verify dependencies are installed → Review build logs for specific errors **"Publish directory not found"** → Verify build command ran successfully → Check publish directory path is correct ## Troubleshooting ### Escalated Network Access If deployment fails due to network issues (timeouts, DNS errors, connection resets), rerun the deploy with escalated permissions (use `sandbox_permissions=require_escalated`). The deploy requires escalated network access when sandbox networking blocks outbound requests. Example guidance to the user: ``` The deploy needs escalated network access to deploy to Netlify. I can rerun the command with escalated permissions—want me to proceed? ``` ## Environment Variables For secrets and configuration: 1. Never commit secrets to Git 2. Set in Netlify dashboard: Site Settings → Environment Variables 3. Access in builds via `process.env.VARIABLE_NAME` ## Tips - Use `netlify deploy` (no `--prod`) first to test before production - Run `netlify open` to view site in Netlify dashboard - Run `netlify logs` to view function logs (if using Netlify Functions) - Use `netlify dev` for local development with Netlify Functions ## Reference - Netlify CLI Docs: https://docs.netlify.com/cli/get-started/ - netlify.toml Reference: https://docs.netlify.com/configure-builds/file-based-configuration/ ## Bundled References (Load As Needed) - [CLI commands](references/cli-commands.md) - [Deployment patterns](references/deployment-patterns.md) - [netlify.toml guide](references/netlify-toml.md)