Ship
Use when the user asks to push changes, says `/ship`, asks to open/create/publish/file a PR or pull request, asks for "review and push" / "commit and push" / "ship it" / "push and fix CI until green", or otherwise indicates they're ready to integrate local work to `main`. Do NOT invoke for routine in-flight commits, or for inspecting/merging an already-open PR (`gh pr view`/`merge` — e.g. `/janitor`). PR publish is owned by this skill — never bare `gh pr create` outside it.From its SKILL.md
npx -y skills add jsolly/agent-skills --skill shipAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
8.7 KB, ~2.1k tokens by cl100k_base, as published. Nobody here has run it
Git Review, Fix, and Integrate to Main
This is the sole semantic review gate before code reaches the remote. Default integration: branch → PR → CI-gated auto-merge ({INTEGRATION_MODEL} = pr-auto-merge). Legacy/break-glass: direct git push origin HEAD:main when AGENTS.md declares Integration: direct-push or for emergency admin bypass.
Review depth and deploy behavior are right-sized by ship profile (step 3): static Vercel SPAs get a light agent fleet; AWS SAM repos lean on GitHub deploy workflows (.github/workflows/deploy.yml) instead of local deploy:code. CI owner (local vs github-handoff) controls only how much of the battery runs locally before the PR — see references/ci-owner.md. There is no fire-and-forget canon. Success means the gate passes locally, the branch lands on the remote, CI is babysat to green (fix forward on red), and the PR merges. Where auto-merge can't arm (plan-gated private Free repos), merge manually once green. The skill runs the gate explicitly before push; the pre-commit hook already ran at commit time, but /ship must not rely on that alone.
PR CI babysit (required on every PR ship)
After the PR is open, do not stop at "PR created." For every {CI_OWNER} (local and github-handoff):
- Watch required checks:
gh pr checks --watch(or poll) untilCI / ci(or the repo's documented required check) completes. - On failure: read the failing job logs, fix forward on the same branch, commit, push, and re-watch. Cap at 3 fix-red-PR cycles; on the 4th, report
Not mergedwith which check failed. - On green: let auto-merge land, or if plan-gated run
gh pr merge --squash. - Then run step 12 deploy/verify and step 13 confirm.
Numbered orchestration
The orchestration is documented in references/orchestration.md — read it before each step. Summary:
- Inspect changes —
git status,git diff. → seereferences/orchestration.md - Sync main into the working branch — fetch, compare, merge or rebase, resolve conflicts. → see
references/orchestration.mdandreferences/conflict-resolution.md - Load guidelines + classify profile, integration, and CI owner — read AGENTS.md; infer
{SHIP_PROFILE},{INTEGRATION_MODEL}, and{CI_OWNER}; locate plan/spec (D.1). → seereferences/orchestration.mdandreferences/ci-owner.md - Smoke check — tests, type checker, reproduce the gate locally if the change could affect it. → see
references/orchestration.mdandreferences/conflict-resolution.md - Architectural sanity check — orchestrator notes structural concerns; these get injected into agent prompts via D.2. → see
references/orchestration.md - Review with parallel agents — read full changed-file bodies; fan out light or full fleet per profile and diff (see
references/agent-fleet.md). Skip fan-out only for trivialdocs-configdiffs. - Adjudicate findings with
confidence-scorer— drop Minor, score Critical/Important, verify surviving findings against real code paths. → seereferences/orchestration.md - Present verdict + findings — verdict-line first, TL;DR paragraph, then per-severity findings. Include
Ship profile,Review tier,Integration model, andCI owner. → seereferences/orchestration.md - Fix issues + re-smoke — fix verified Critical and reasonable Important findings; re-run smoke and scoped re-review; loop up to 3 cycles. → see
references/orchestration.md - Stage and commit — stage by name (no
git add -A); Conventional Commits message describing original intent. → seereferences/orchestration.md - Run the gate, then integrate — run the repo gate explicitly; then
pr-auto-merge: push branch + open PR (→references/pr-integration.md);direct-push:git push origin HEAD:main. Never--no-verify. → seereferences/orchestration.md - Babysit PR CI, then deploy/verify — watch CI, fix red checks (cap 3), merge when green, then post-merge Vercel/Actions/Heroku verify. Never auto-run
deploy:infra. → seereferences/deploy-rules.md,references/pr-integration.md,references/ci-owner.md - Confirm integration landed — PR path: merged SHA + CI status; direct-push: push is the CI. → see
references/orchestration.mdstep 13 - Final user summary — lead with
PR merged to main,PR open — auto-merge pending CI, orShipped to main(direct-push). → seereferences/orchestration.mdstep 14 - Clean up worktree — ran from a linked worktree? Remove it +
cdback to the primary checkout'smain(default).pr-auto-merge: after merge lands.direct-push: after the push lands. Only the worktree this ship ran from; never sweep others'. → seereferences/orchestration.mdstep 15
Safety rules (non-negotiable)
- Never push directly to
mainexcept break-glass — default path pushes a feature branch and opens a PR. DirectHEAD:mainonly when{INTEGRATION_MODEL}isdirect-pushor user explicitly requests emergency bypass. - Never push a branch without running the local gate first — the pre-commit hook already ran at commit, but
/shipre-runs the gate explicitly before push. - Never bare
gh pr create— always prefix withDOTAGENTS_SHIP=1(seereferences/pr-integration.md). Theblock-pr-create-outside-shipguard denies creates without that allow. - Never
--no-verifyon commit or push — orchestrator discipline + pre-commit hook backstop; there is noblock-gitshell guard. Seereferences/safety-rules.md. - Never
git push --force/--force-with-lease/git reset --hard— skill discipline; not blocked by shell guards. - Never
git add -Aorgit add .— stage by name to avoid sweeping in untracked secrets, large binaries, or probe artifacts. - Never weaken the gate — do not disable checks or make unrelated changes to force a green push.
- Review outputs are advisory — verify each surviving Critical/Important finding against the real code path before fixing.
Cycle bounds
The review fix loop (step 9) is capped at 3 cycles total. On the 4th, surface the failure to the user and stop.
The push-fix loop (step 11, local gate before push) is capped at 3 cycles. On the 4th rejection, stop and report.
The fix-red-PR loop (step 12, after the PR is open) is capped at 3 cycles: watch → fail → fix → push → re-watch. On the 4th failure, report Not merged — do not abandon the PR silently.
Token economics
This skill is the only semantic review gate — match depth to profile, not one size for every repo.
vercel-static/ frontend-only: default to light fleet (5 always-run agents + extension-gated specialists). Full file bodies still required forcode-quality-reviewer.aws-sam/ infra-DB-auth/provider changes: full fleet mandatory — all 10 always-run agents + extension-gated +confidence-scorer.- Trivial
docs-configdiff: skip fan-out (existing trivial path). - Escalation: if a light review surfaces structural/security/infra concerns, re-run with full fleet before push.
- Do not rerun the full fleet just to confirm a clean review. Push-fix cycles should not re-fan-out unless the failure is ambiguous or security-sensitive.
Reference files
references/orchestration.md— full step-by-step body, ship profiles, integration model, D.1, D.2, D.3, E.1, E.2 wiring.references/ci-owner.md—localvsgithub-handoff: local gate depth only (babysit is always required on PR ships).references/pr-integration.md— PR path (steps 11–14): watch CI, fix-red loop, merge, deploy verify.references/agent-fleet.md— light vs full fleet tables, gating rules, model behavior.references/output-contract.md— canonical reviewer output schema (every agent inlines this).references/dispatch-prompt.md— the prompt template each agent receives via Task.references/deploy-rules.md— AWS GitHub-managed deploy, Vercel Git verification, live checks.references/conflict-resolution.md— merge conflict resolution + gate reproduction guidance.references/safety-rules.md— git safety model + remaining shell guards (prod DB, stack delete, CLAUDE.md write).
What ships with it: 11 files
84.5 KB alongside SKILL.md, 1 of them executable
references/
- agent-fleet.md5.3 KB
- ci-owner.md3.0 KB
- conflict-resolution.md2.9 KB
- deploy-rules.md14.8 KB
- dispatch-prompt.md4.2 KB
- orchestration.md31.2 KB
- output-contract.md5.5 KB
- pr-integration.md6.4 KB
- release-id.md5.7 KB
- safety-rules.md2.9 KB
scripts/
- verify-x-release-id.shruns2.7 KB