Project-scoped and bound to a slash command inside one repo. Runs the production deploy, reports the live URL, and requires an explicit confirm before it starts.
Fires on /deploy in that project.
On failure it stops and surfaces the error. It does not retry blindly, which is the behaviour that turns one bad deploy into four.