shipkit-update

A setup and upgrade helper for Shipkit, a project framework or toolkit. It finds old Shipkit installations, saves them, and combines your project content with the new files.

In plain words
What is it for?
Installing Shipkit for the first time, upgrading an existing installation, or reinstalling it from GitHub.
Why use it?
Updating project files can overwrite local changes or leave several old versions mixed together. This helper preserves previous files and handles the update in one process.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/stefan-stepzero/shipkit/shipkit-update
Any agent
npx skills add stefan-stepzero/shipkit --skill shipkit-update
Clone the repo
git clone --depth 1 https://github.com/stefan-stepzero/shipkit

Made for: Claude Code, Codex.

Per session 31 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 6,279 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00031 $0.06279
Opus 5 $0.00015 $0.03139
Sonnet 5 $0.00006 $0.01256
Haiku 4.5 $0.00003 $0.00628

Measured yesterday against content hash cc5c8d04e594, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

shipkit-update scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

curl -sL https://raw.githubusercontent.com/stefan-stepzero/shipkit/main/installers/install.py -o /tmp/shipkit-install.py
install/skills/shipkit-update/SKILL.md · 725 lines

How it starts

The opening of the file, as written. The whole thing — 725 lines — stays where its author put it; the contents beside it link to each section on GitHub.

shipkit-update - Install & Update Shipkit

Purpose: One skill to install Shipkit fresh or update an existing installation. Archives previous versions safely and intelligently merges user content.

Role: Bootstrap/update skill. Can be fetched directly from GitHub even before Shipkit is installed.


Why This Skill Exists

Updates are tricky without version tracking and safe migration.

This skill provides:

  1. Detection - Finds all Shipkit variants (current + legacy naming)
  2. Safe archiving - Never deletes, always preserves
  3. Clean install - Fresh framework files from source
  4. Intelligent merge - Claude merges user content into new structure

When to Invoke

User-invoked:

  • "Install Shipkit" / "Update Shipkit" / "Upgrade Shipkit"
  • /shipkit-update (explicit)
  • "Reinstall Shipkit from GitHub"

Bootstrap scenario:

  • User pastes GitHub link + "install this"
  • Claude fetches this skill directly and executes

Prerequisites

For installation:

  • Access to GitHub (WebFetch or gh CLI)
  • Write access to project root

For update:

  • Existing Shipkit installation (any version)

Process

Completion Tracking (MANDATORY)

After getting user permission (Step 0), create tasks for every remaining step:

  1. TaskCreate: "Detect existing installation"
  2. TaskCreate: "Archive existing installation + write MANIFEST.md"
  3. TaskCreate: "Run npx installer"
  4. TaskCreate: "Merge CLAUDE.md (+ subfolder CLAUDE.md files)"
  5. TaskCreate: "Merge settings.json"
  6. TaskCreate: "Scan settings.local.json for stale refs"
  7. TaskCreate: "Migrate user content from archive"
  8. TaskCreate: "Cleanup deprecated .md files"
  9. TaskCreate: "Output comprehensive summary"

Rules:

  • TaskUpdate each task to completed only after the step is fully done
  • The installer completing (Step 3) is NOT the finish line — 5 more steps remain
  • Do NOT present the final summary until ALL tasks show completed
  • The CLAUDE.md merge task includes subfolder CLAUDE.md files, not just root

Read the full file on GitHub · 725 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 725 lines · 31 tokens per session scan A cc5c8d04e594

Subscribe to this mod's changes

shipkit-update is a skill published in the GitHub repository stefan-stepzero/shipkit (1 stars, last pushed 1mo ago), licensed MIT. It adds 31 tokens to every session and 6,279 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.