SkillLow riskUnclaimed
Phase 2 — Stage → Launch
Phase 2 of building a Claude Managed Agent — turn a validated build sheet into exact API payloads and a resumable BYOK curl launch script, then launch (environment → agent → session → kickoff) using the founder's OWN Anthropic key. Use when the user says "launch it", "deploy the agent", "create the agent now", or when the orchestrator routes phase=stage-launch. payload_generator.py emits the four ordered payloads; launch_script_writer.py writes launch.sh that reads $ANTHROPIC_API_KEY at runtime and never embeds it; payload_validator.py runs a pre-launch check including an API-key-leak scan. No tool in this skill makes network calls — the user runs launch.sh themselves. Distinct from interview (planning) and grade-iterate (the outcome loop).
alirezarezvanialirezarezvani/stage-launch
Description
Turn the build sheet into runnable artifacts, then let the founder launch with
their own key. No script here touches the network or the key — the user runs
launch.sh.
Workflow
- Generate payloads.
Agent toolset →python3 scripts/payload_generator.py \ --sheet ./my-agent/build-sheet.json --out-dir ./my-agent # -> ./my-agent/payloads/{01-environment,02-agent,03-session,04-kickoff}.jsonalways_allow; every MCP toolset →always_ask(baked into the agent payload'spermission_policies). - Write the launch script.
python3 scripts/launch_script_writer.py --out-dir ./my-agentlaunch.shcreates environment → agent → session → kickoff in order, chaining IDs, and resumes on re-run (each step skips if its*.idfile exists). It reads$ANTHROPIC_API_KEYat runtime. - Validate before launch.
FAIL blocks — especially apython3 scripts/payload_validator.py --dir ./my-agentkey_leakfinding. Fix and re-run. - Minimal key step (never in chat). Check the shell first:
Point the founder to platform.claude.com → API keys. Never print the key to chat, never write it to a file.[ -n "$ANTHROPIC_API_KEY" ] && echo "key present" || echo "export ANTHROPIC_API_KEY=... first" - Launch + watch the first poll.
Mark checkpoints with Console deep links. Thenexport ANTHROPIC_API_KEY=... # in their shell, not in chat ./my-agent/launch.shgoal_state.py set --phase grade-iterateand advance.
Hard rules (API-key safety)
- The key never enters chat, a file, a payload, or a log.
launch.shreads it from the environment;payload_validator.pyscans forsk-ant-…leaks and FAILs. - Sequential launch. environment → agent → session → kickoff. Watch the first poll foreground before declaring success.
- Resumable. Re-running
launch.shcontinues from the last created ID.
Forcing-question library (recommend + cite)
- "Is the key in your shell env already?" Recommend: check
$ANTHROPIC_API_KEYbefore anything. Cite: this SKILL, key-safety rules. - "Cloud or self-hosted environment?" Recommend: cloud for v0. Cite: cma-primitives.md (environment).
- "Any MCP server in the payload?" Recommend: keep it
always_ask. Cite: cma-primitives.md (permissions). - "Did the first poll return idle/running cleanly?" Recommend: watch it foreground before moving on. Cite: cma-primitives.md (session lifecycle).
Tools
scripts/payload_generator.py— build sheet → 4 ordered API payloads.scripts/launch_script_writer.py— resumable BYOK curl launcher (no key handling).scripts/payload_validator.py— pre-launch check + API-key-leak scan.
Permissions
pythonapi.anthropic.complatform.claude.comANTHROPIC_API_KEYChecks
Low risk · Nothing worth a warning was found.
Not reviewed by a person · Checked by rules; the model review is not switched on yet.
Files5 files · 20.1 KB
- README.md1.0 KB
- SKILL.md3.8 KB
scripts/3
- launch_script_writer.py4.2 KB
- payload_generator.py4.5 KB
- payload_validator.py6.5 KB
Versions
- #1—latestOct 7, 2026