Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/stefan-stepzero/shipkit/shipkit-user-instructionsnpx skills add stefan-stepzero/shipkit --skill shipkit-user-instructionsgit clone --depth 1 https://github.com/stefan-stepzero/shipkitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00038 | $0.03213 |
| Opus 5 | $0.00019 | $0.01606 |
| Sonnet 5 | $0.00008 | $0.00643 |
| Haiku 4.5 | $0.00004 | $0.00321 |
Grade A, and why
shipkit-user-instructions scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 397 lines — stays where its author put it; the contents beside it link to each section on GitHub.
shipkit-user-instructions - Task Tracking for Manual User Actions
Purpose: Prevent manual tasks from being lost in chat by maintaining a persistent JSON tracking file for tasks that require user action outside Claude's control.
What it does: Captures manual tasks the user must complete, tracks their status, and persists them in .shipkit/user-tasks.json — a structured JSON artifact readable by Claude, machine-readable by other tools, and the single source of truth for user action items.
Output format: JSON — follows the Shipkit artifact convention for dashboard integration.
When to Invoke
Auto-trigger scenarios (other skills invoke this):
- Package installation needed (implement)
- External service configuration required (Lemon Squeezy webhooks, API keys)
- Database migrations need running
- Deploy configuration needed
- Git repository setup required
Manual invocation:
- User says: "Track this task", "Add to my todo", "Remind me to..."
- Claude realizes: "I need the user to do X before I can continue"
Philosophy: If Claude can't do it directly, track it so it doesn't get forgotten.
Prerequisites
Optional:
.shipkit/directory (will create if missing)
No hard prerequisites - This skill can run anytime.
Process
Step 1: Confirm Task Details
Before creating task entry, ask user 2-3 questions:
-
What specific task needs to be done?
- "Set up Lemon Squeezy webhook?"
- "Configure webhook endpoint?"
- "Set environment variable?"
- (Let user describe or Claude infers from context)
-
Why is this needed?
- "For local webhook testing during development"
- "To enable payment processing"
- "To connect to production database"
-
How urgent is this?
- "Blocking me right now?" → High priority
- "Needed before deploy?" → Medium priority
- "Nice to have later?" → Low priority
-
Which phase does this block? (infer from context when possible)
- Read
.shipkit/why.jsonto determine current stage (poc, mvp, growth, scale) - If the task is needed for the current stage →
blocksPhase= current phase,blocking=true - If the task is needed for a future stage →
blocksPhase= that future phase,blocking=false - If unclear or not phase-specific →
blocksPhase=null,blockingbased on priority
- Read
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 397 lines · 38 tokens per session scan A 89a924f8a34a
shipkit-user-instructions is a skill published in the GitHub repository stefan-stepzero/shipkit (1 stars, last pushed 1mo ago), licensed MIT. It adds 38 tokens to every session and 3,213 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
opencli-sitemap-author
Use when creating or maintaining OpenCLI site sitemaps: agent-facing navigation, page-state, action, workflow, API-reference, pitfall, and fallback knowledge for a website. Use after browser exploration discovers durable site context, when a sitemap is stale, or when promoting local site knowledge into the repo.
golden-rss
Use when testing the rss golden build.
omh-buzz
This is a Hermes-native buzz workflow skill.
omh-code-review
This is a Hermes-native code-review workflow skill.
redteam-api-detail-pack
Domain routing and boundary guidance for authorized API security testing, including BOLA/IDOR, authentication bypass, mass assignment, missing rate limits, and GraphQL issues. Use when a task belongs to the API testing domain and needs scope, evidence, pivot, or exit criteria.
redteam-postex-detail-pack
Domain routing and boundary guidance for authorized post-exploitation testing after initial access, including privilege escalation, persistence, lateral movement, data collection, and cleanup considerations. Use when a task belongs to the post-exploitation domain and needs scope, evidence, pivot, or exit criteria.