Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/shipwrights/core/shipwrights-statusnpx skills add shipwrights/core --skill shipwrights-statusgit clone --depth 1 https://github.com/shipwrights/coreWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/shipwrights/core/shipwrights-status)<a href="https://agentmods.dev/skills/shipwrights/core/shipwrights-status"><img src="https://agentmods.dev/badge/skills/shipwrights/core/shipwrights-status.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00040 | $0.00568 |
| Opus 5 | $0.00020 | $0.00284 |
| Sonnet 5 | $0.00008 | $0.00114 |
| Haiku 4.5 | $0.00004 | $0.00057 |
Grade A, and why
shipwrights-status scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
/shipwrights-status — what's in flight
Read the configured lock service and report on every active orchestration.
What you do
-
Load
.shipwrights.ymlto determine the lock backend. -
Query the lock service via
lib/lock-service.mjs(the engine handles the kind dispatch; markdown / github-issues / custom). -
Render the table:
In flight: | Branch | Epic | Stage | Tier | Active specialists | Updated | Stale? | |---------------------|----------|-----------|-------|--------------------|------------|--------| | feature/e-04-09 | E-04-09 | build | full | backend, frontend | 2026-05-09 | | | feature/e-04-08 | E-04-08 | review | light | — | 2026-05-07 | ⚠ 48h | Stale entries (>48h with no commit on the branch): - feature/e-04-08 has no commits since 2026-05-07 14:23. Resume, archive, or delete? -
Stale detection: for each entry, check
git log --since=<48h ago> <branch>(or whatever threshold is inlock.config.stale_after_hours). If empty, mark stale. -
Print a footer:
Lock backend: markdown (docs/process/in-flight.md) Stale threshold: 48h Operations: /shipwrights-epic <id> — start or resume an epic /shipwrights-doctor — validate config + agent availability
When the register has no entries
Print:
Nothing in flight.
To start an epic:
/shipwrights-epic <id> — by id from your backlog
/shipwrights-epic — picks the next ready epic from <backlog source>
Failure modes
- Lock backend unreachable (e.g., GitHub API down for the github-issues lock). Print the error, suggest checking auth / network.
- Markdown register file missing — propose creating it (writes empty register).
- Permissions — if the configured lock backend requires a token the orchestrator doesn't have, fail with a clear message naming which env var to set.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 57 lines · 40 tokens per session scan A d945b4a047b3
shipwrights-status is a skill published in the GitHub repository shipwrights/core (2 stars, last pushed 1mo ago), licensed MIT. It adds 40 tokens to every session and 568 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
great_cto
Use when the CTO describes a feature, task, or project goal. Orchestrates the full SDLC pipeline automatically based on project type.
vertical-real-estate
Residential-proptech domain knowledge so architect / pm aren't naive when speccing real-estate products (listings, lead-crm, transaction-coordination, property-mgmt). Codifies MLS/IDX reality, listing status lifecycle + syndication canonical-source, long-cycle lead nurture, transaction-coordination as the high-pain…
anti-patterns
Catalogue of known SDLC anti-patterns that greatcto agents must actively reject when reviewing architecture, plans, code, or post-mortems. Used by architect (pre-impl), pm (planning), senior-dev (impl), l3-support (post-incident).
cost-model
Standardized cost-estimation framework for greatcto plans. Forces explicit LLM cost, infra cost, human-supervision time, and the (defensible) human-equivalent comparison. Output format is parsable by the board's /api/cost path — must follow exactly.
migration-ready-schema
Data-model rules that make a schema importable from day one, so the migration-import-engineer is never blocked on missing columns. Every SMB Product-Builder product must let a customer bring their data from an incumbent (ServiceTitan/Toast/Mindbody/Shopify) — that requires provenance (sourceref) and rollback…
stack-baseline
The pinned default technology stack for SMB Product-Builder products. One source of truth so the architect, app-scaffolder, auth-engineer, and senior-dev never re-decide the stack per build — they build ON it. Covers framework, ORM/DB, auth, UI, payments/email/SMS, files, jobs, testing, hosting, and observability…