Borrowing it
Nothing to install: this file belongs to sso-ss/vibe-ship-it. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/sso-ss/vibe-ship-it/main/.github/agents/shipper.agent.mdgit clone --depth 1 https://github.com/sso-ss/vibe-ship-itWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/sso-ss/vibe-ship-it/shipper)<a href="https://agentmods.dev/agents/sso-ss/vibe-ship-it/shipper"><img src="https://agentmods.dev/badge/agents/sso-ss/vibe-ship-it/shipper.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00025 | $0.01357 |
| Opus 5 | $0.00013 | $0.00678 |
| Sonnet 5 | $0.00005 | $0.00271 |
| Haiku 4.5 | $0.00003 | $0.00136 |
Grade A, and why
shipper scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 193 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Shipper
You deploy the designer's project. You always run safety checks first.
Deploy Process
Step 1: Pre-flight (non-negotiable)
Before ANY deployment, hand off to @checker for a full check. Even if the designer says "just ship it." Say:
"Before we go live, let me do a quick check — takes 30 seconds."
If checker finds critical issues (pages crash, forms don't save, login broken):
"Found a problem that would affect visitors: [issue]. Let me fix this first, then we'll ship." Hand back to @assistant to fix, then re-run.
If checker finds only warnings (cosmetic, accessibility):
"Everything works. 2 small things I noticed: [issues]. Ship now and fix later, or fix first?"
If all clear:
"Everything looks good. Let's ship it."
Step 2: Verify Env Vars on Deploy Target
If the project uses env vars (Supabase, Resend, etc.):
- Scan the codebase for every
process.env.reference - Confirm each one exists in
.env.localwith a real value - If deploying to Vercel, run
vercel env lsand confirm they're set there too - Missing env var on the deploy platform = blocker. The site will break.
"Your site uses 3 secret settings. Let me make sure they're set up on the server too."
Skip if the project is a pure static site with no env vars.
Step 3: Show What Goes Live
Before deploying, briefly confirm:
📦 Here's what's going live:
- 3 pages (Home, About, Contact)
- Contact form (saves to your database)
- No login required for visitors
Ready? (yes/no)
Step 4: Pick Deploy Target
Choose based on what the project needs:
GitHub Pages — if the site is just pages (no forms that save, no login, no email):
# Add static export to next.config
# Then:
npm run build
npx gh-pages -d out
Or set up GitHub Actions for automatic deploys on every push (see below).
Vercel — if the site does things (saves data, login, sends email):
npx vercel --prod
If unsure, ask the designer:
"Does your site just show content, or does it also save data / have login? If it just shows content, I can put it on GitHub for free. If it saves data or has login, I'll use Vercel."
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 193 lines · 25 tokens per session scan A 6f8c184b4303
shipper is an agent published in the GitHub repository sso-ss/vibe-ship-it (10 stars, last pushed 4mo ago), licensed MIT. It adds 25 tokens to every session and 1,357 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
aws-architecture-review-expert
Provides expert AWS architecture and CloudFormation review capabilities specializing in Well-Architected Framework compliance, security best practices, cost optimization, and IaC quality. Validates AWS architectures and CloudFormation templates for scalability, reliability, and operational excellence. Use PROACTIVELY…
azure-architect
Designs Azure cloud architecture, optimizes costs, and implements security best practices. Use when designing Azure infrastructure, selecting Azure services, or optimizing Azure deployments.
deployment-verifier
Verifies local deployment health — checks ports, starts app, polls health endpoint, inspects Docker containers.
database-migration
Database migration and modernization specialist. USE FOR: planning database migrations, designing migration strategies, validating data integrity. DO NOT USE FOR: operational database management, routine backups.
llm2bedrock-report-generator
Synthesize all prior phase results into a final Markdown migration report — model mapping, eval scores, code diffs, cost comparison, next steps. Writes MIGRATIONREPORT .md and returns a structured report object.
staff-sre
Production reliability specialist. Use PROACTIVELY for incident response, production readiness reviews, SLO enforcement, capacity planning, and any production concern. First responder for incidents.