# CWI Deploy Gate > Pre-flight checks that catch the bug classes unit tests miss. - Live docs: https://cumulativewebinc.github.io/cwi-trust-deploy-gate/ - Repo: https://github.com/CumulativeWebInc/cwi-trust-deploy-gate - CLI: `node bin/deploy-gate.js ` — zero dependencies, Node >= 18. ## The four checks Every check is a scar CWI already paid for (see docs/CATCHES.md): 1. `scope` — identifier referenced from a scope where none of its declarations is visible (gear-ledger 2026-09-17: `DISTRICT_BEACONS` ReferenceError killed boot before the first frame). 2. `labels` — literal `SAMPLE`/`LIVE` badge with no mode variable driving it (3D world 2026-09-18: hardcoded badges never followed the WorldClient mode). 3. `versioning` — importer AND its module both changed, but the import URL carries no `?v=` query (Pages cache split-brain 2026-09-17). 4. `secrets` — secret-shaped filenames, secret-shaped KEY/TOKEN/SECRET/ PASSWORD/CREDENTIAL assignments, private-key blocks (preventive; the scan never prints values — findings name file, line, and key shape only). ## Honest limits - Static checks only: they catch known bug classes, not novel ones. - The secret scan's test fixtures use obviously fake values (``). - Kill rule: catches zero real historical bug classes in dry-run before v1 → do not ship. (It caught 4/4 — see docs/CATCHES.md.) ## Tests `node test/test.js` — 21/21 green, zero dependencies. ## Machine-readable - docs/.well-known/agent-card.json — agent discovery card © 2026 Cumulative Web Inc · hp@cumulativeweb.com