Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/calneymgp/solodev/dev-shipnpx skills add calneymgp/solodev --skill dev-shipgit clone --depth 1 https://github.com/calneymgp/solodevWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00121 | $0.01141 |
| Opus 5 | $0.00060 | $0.00571 |
| Sonnet 5 | $0.00024 | $0.00228 |
| Haiku 4.5 | $0.00012 | $0.00114 |
Grade A, and why
dev-ship scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 98 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/dev-ship — Pronto é estado verificado, não sensação
Task ✅ ≠ feature ✅. Esta skill é a barreira entre "terminei as tasks" e "isso pode ir pra produção". Roda no fim de um PLAN.md ou standalone sobre qualquer diff que o usuário queira fechar.
Processo
1. Verificação dura (must_pass global)
Rode, na ordem, o que o projeto tiver (CLAUDE.md diz quais):
- Typecheck / build
- Suite de testes completa (não só os módulos tocados)
- Lint
Qualquer vermelho para o ship aqui. Vermelho vira fix-task (ou /dev-fix) — nunca "é flaky, ignora".
2. Must-Haves do PLAN.md (goal-backward)
Se existe .plans/<feature>/PLAN.md:
- Truths: cheque cada behavior listado — idealmente via smoke test, não inspeção visual
- Artifacts: cada arquivo existe? min_lines? exports/contains corretos?
- Key Links: rode os regex declarados — devem casar
- Demo script: execute os passos. A feature demonstra em 60s ou não demonstra?
Falhou qualquer um → diagnostique por que a task "completed" não satisfez o goal, crie fix-task no PLAN.md, execute, re-verifique. Loop até verde. Não mascare.
3. Revisão do diff (você é o reviewer agora)
Leia o diff completo da feature (git diff <base>...HEAD ou working tree) com olhos de reviewer, não de autor:
Caçada a restos:
console.log/print/dbg!de debug, prefixos[DEBUG-*]TODO/FIXME/HACKnovos sem issue ou justificativa- Código comentado, imports não usados, arquivos órfãos
- Dependência adicionada que só se usa em 1 linha trocável
Caçada a bugs de autor:
- Edge cases dos Goals que nenhuma task cobriu
- Error paths que engolem erro em silêncio (catch vazio)
- Async sem await / promise solta / race óbvia
- Off-by-one em paginação/slice/loop
4. Lente de segurança (só arquivos tocados)
Não é auditoria completa — é o mínimo que evita vergonha:
- Segredo/chave/token hardcoded? (inclusive em teste e fixture)
- Input externo chegando em query/comando/path sem validação?
- Endpoint novo sem auth/permissão onde os vizinhos têm?
- Dado sensível indo pra log?
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 98 lines · 121 tokens per session scan A 3d373dc1071f
dev-ship is a skill published in the GitHub repository calneymgp/solodev (2 stars, last pushed 2mo ago), licensed MIT. It adds 121 tokens to every session and 1,141 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
karpathy-guidelines
Tool-agnostic behavioral guidelines for AI coding assistants. Use when writing, reviewing, debugging, or refactoring code to reduce overengineering, surface ambiguity, make surgical changes, and define verifiable success criteria.
Evolve-Skill
核心进化技能。在开发结束时调用,自动分析对话历史,将“项目进化资产”沉淀到 EVOLVE.md,并将平台特有的 AI 行为教训写入 CLAUDE.md / GEMINI.md / AGENTS.md / CURSOR.md,实现可审计、可复用的持续进化。触发词:"总结经验"、"进化"、"evolve"、"复盘"、"summarize lessons"、"retrospective"、"postmortem"。不适用于仅完成简单查询、单文件小改动或未产生可沉淀资产的场景。.
metrics-instrumentation
Specification for instrumenting an opik-backend workflow with operational OpenTelemetry metrics — per-stage throughput/latency/error counters and native histograms, dimensioned per-customer (workspace). Use when a pipeline (scoring, ingestion, experiments, jobs) needs per-stage visibility. Covers metric emission only…
happiness-skill
当用户问「怎么才能更幸福/为什么得到了还不满足/怎么减少焦虑」时调用。 核心理念: 幸福是缺憾感清空的默认状态, 是可训练的技能; 欲望是与自己的契约(得到前不快乐), 同时只留一个重大欲望; 活在当下。 不适用于: 临床抑郁等需要专业治疗的场景(本书方法不能替代医疗)。 Triggers: 幸福/不快乐/欲望/焦虑/知足/活在当下/happiness/desire/anxiety.
api-design
REST/GraphQL/gRPC API design best practices. Use when designing APIs, defining contracts, handling versioning. Covers OpenAPI 3.2, GraphQL Federation, gRPC streaming.
setup-matt-pocock-skills
为本仓库配置工程技能——设置其 issue tracker、分诊标签词汇表和领域文档布局。首次使用其他工程技能前运行一次。.