ship

A skill for closing out a software milestone by landing its pull request, a proposed set of code changes, on the default branch. It verifies issue-closing commits, merges the pull request, and can delete the branch and close the milestone.

In plain words
What is it for?
Use it to ship a milestone, merge its pull request, verify that issues closed correctly, close the milestone, or preview the actions with a dry run.
Why use it?
It checks that the milestone’s tracked work is complete before merging and handles the related cleanup and status updates.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/stefan-jansen/coding-agent-toolkit/ship
Any agent
npx skills add stefan-jansen/coding-agent-toolkit --skill ship
Clone the repo
git clone --depth 1 https://github.com/stefan-jansen/coding-agent-toolkit

Made for: Claude Code, Codex.

Per session 105 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,640 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00105 $0.02640
Opus 5 $0.00053 $0.01320
Sonnet 5 $0.00021 $0.00528
Haiku 4.5 $0.00011 $0.00264

Measured 2d ago against content hash bba95ab18443, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

ship scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/ship/SKILL.md · 245 lines

How it starts

The opening of the file, as written. The whole thing — 245 lines — stays where its author put it; the contents beside it link to each section on GitHub.

ship — close out the active milestone

You are running the SHIP step of the workflow. Your job is to take the milestone's open PR — built up one commit at a time by /next-issue — and land it on the default branch, then verify that all milestone issues auto-closed and close the milestone.

This step is host-neutral: same contract on Claude and Codex. The verbs are gh and git.

Arguments

Parse these from the user's invocation (any order):

Arg Required Default Meaning
--repo <owner/name> no current repo via gh repo view --json nameWithOwner --jq .nameWithOwner Target GitHub repo
--milestone <title> no the active milestone (resolved as in /next-issue) Restrict to this milestone
--pr <N> no the open PR whose milestone matches Override PR pick
--no-delete-branch no false (delete) Keep the feature branch after merge
--no-close-milestone no false (close) Leave the milestone open after merge
--dry-run no false (act) Print what would happen, change nothing

Default behavior is to act, not dry-run — landing the PR is the point of the verb. --dry-run is for "show me the ship checklist" without merging.

What "active milestone" means

Same resolution as /next-issue:

  1. List open milestones: gh api "repos/<owner>/<repo>/milestones?state=open" --jq '.[].title'.
  2. One open → pick it.
  3. Multiple → ask the user, listing them with open-issue counts.
  4. Zero → tell the user there's nothing to ship and stop.

What "the milestone's PR" means

gh pr list --repo <owner>/<repo> --state open \
  --json number,headRefName,milestone,isDraft,title \
  --jq '.[] | select(.milestone.title == "<title>")'
  • Exactly one open PR with that milestone → use it.
  • More than one → ask the user which to ship.
  • Zero → suggest /next-issue (no work has landed yet) and abort.

If --pr <N> is passed, fetch that PR and verify its milestone matches.

Readiness checklist (pre-merge)

Read the full file on GitHub · 245 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 245 lines · 105 tokens per session scan A bba95ab18443

Subscribe to this mod's changes

ship is a skill published in the GitHub repository stefan-jansen/coding-agent-toolkit (22 stars, last pushed 17d ago), licensed MIT. It adds 105 tokens to every session and 2,640 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

git-workflow-and-versioning

Structures git workflow practices. Use when making any code change. Use when committing, branching, resolving conflicts, opening or reviewing a pull request (PR), pushing to a remote, or when you need to organize work across multiple parallel streams. Use when cutting a release, choosing a semantic version bump…

addyosmani/agent-skills · 74 tokens

release

Cut a Symphony release by bumping the committed version, landing it, tagging the merged commit, and verifying the Burrito release workflow. Use when asked to release, tag, or retag Symphony.

openai/symphony · 42 tokens

release-notes

Draft concise release notes.

ollama/ollama · 9 tokens

greptimedb-release

Runbook for publishing a new GreptimeDB version (tag + GitHub release + docs release-note PR) on the upstream GreptimeTeam/greptimedb repo. Use when asked to "release" / "publish" a GreptimeDB version (e.g. v1.1.0, v1.0.3).

GreptimeTeam/greptimedb · 75 tokens

refresh-arm-sdk-release

WORKFLOW SKILL — Prepares Azure.ResourceManager SDK refresh pull requests in azure-sdk-for-net. WHEN: "prepare sdk refresh", "refresh Azure.ResourceManager package", "update ARM SDK from autorest tag", "refresh changelog dependencies". INVOKES: git and GitHub pull request tools for branch, commit, push, and PR…

Azure/azure-sdk-for-net · 91 tokens

store-update

在 CCX Desktop 发布后下载 Store MSIX 并生成发布公告。用户提到 Store 上架、MSIX、从 GitHub Release 下载 store.msix、发布后同步 Windows Store、从 release 填写商店更新内容时必须使用此技能。该技能会下载最新 GitHub Release 的 amd64/arm64 MSIX,校验 sha256,从 Release body 生成 Store listing releaseNotes 预览,并输出手动上传指引。.

BenedictKing/ccx · 100 tokens