ship-it

ship-it is a skill for Claude Code, Codex from T4LEL/Claude-Arsenal. It costs 37 tokens per session (682 once invoked), scanned A, original, MIT.

A production deployment checklist for moving a project live or updating it. It covers pre-flight checks, database-before-code deployment, live verification, and reporting.

In plain words
What is it for?
Use it before first deployments and production updates to check the branch, tests, type checking, linting, build, environment variables, migrations, and security findings, then verify the live result.
Why use it?
It reduces the risk of deploying broken code, missing environment variables, incompatible database changes, or security problems. It also prevents claiming checks passed when they were not run.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one. Also seen: mentions CLAUDE.md.

Good fit Use it before first deployments and production updates to check the branch, tests, type checking, linting, build, environment variables, migrations, and security findings, then verify the live result.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/t4lel/claude-arsenal/ship-it
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add T4LEL/Claude-Arsenal --skill ship-it
Clone the repo
git clone --depth 1 https://github.com/T4LEL/Claude-Arsenal

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ship-it

README.md
[![agentmods](https://agentmods.dev/badge/skills/t4lel/claude-arsenal/ship-it/github.svg)](https://agentmods.dev/skills/t4lel/claude-arsenal/ship-it)
Your own site
<a href="https://agentmods.dev/skills/t4lel/claude-arsenal/ship-it"><img src="https://agentmods.dev/badge/skills/t4lel/claude-arsenal/ship-it/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for ship-it

Your own site · 80×15
<a href="https://agentmods.dev/skills/t4lel/claude-arsenal/ship-it"><img src="https://agentmods.dev/badge/skills/t4lel/claude-arsenal/ship-it.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 37 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 682 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00037 $0.00682
Opus 5 $0.00018 $0.00341
Sonnet 5 $0.00007 $0.00136
Haiku 4.5 $0.00004 $0.00068

Measured 10d ago against content hash 512ff13b3046, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade A, and why

ship-it scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

2. Exercise the critical path once (signup/login/core action) via curl or playwright.
skills/ship-it/SKILL.md · 48 lines

How it starts

The opening of the file, as written. The whole thing — 48 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Ship It

Pre-flight → deploy → verify. Never skip pre-flight to "just get it out."

Copy this checklist and check off items as you complete them:

Ship-It Progress:
- [ ] Step 1: Pre-flight — every gate passes
- [ ] Step 2: Deploy (DB before code)
- [ ] Step 3: Verify live (mandatory)
- [ ] Step 4: Report

Step 1 — Pre-flight (every gate must pass; paste real output)

  1. git status clean or only intended changes; on the expected branch.
  2. Tests pass. Typecheck/lint passes. Production build passes (npm run build / equivalent). If no test suite exists, record that as a risk in the report and run whatever checks do exist — never report a gate as passed that doesn't exist.
  3. Env vars: diff .env.example against the platform's configured vars (vercel env ls) — every required var present in production, no secret committed anywhere (check git ls-files for tracked env files).
  4. Database: pending migrations identified; migrations are backward-compatible with currently-running code (deploy DB first, then code). Supabase: run the supabase MCP get_advisors tool and triage security findings — RLS gaps block the deploy.
  5. First deploy only: run the security-auditor agent on the codebase; Critical findings block.

A failed gate stops the deploy: fix it, or get the user's explicit go-ahead to ship anyway and record that in the report. Never reinterpret a failing gate as passing.

Step 2 — Deploy

  • Next.js: vercel --prod (or push to main if CI-driven — check which mode the project uses first). If the CLI isn't logged in or the project isn't linked, stop and ask the user to run vercel login / vercel link — never guess credentials.
  • Supabase migrations: supabase db push (or the supabase MCP apply_migration tool) BEFORE the code deploy.
  • Other stacks: follow the project CLAUDE.md's deploy section; if none exists, stop and write one first with the devops-engineer agent.

Deploying is outward-facing: on a FIRST production deploy or anything user-visible and irreversible, confirm with the user before executing unless they already said to ship.

Read the full file on GitHub · 48 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 10d ago First seen · 48 lines · 37 tokens per session scan A 512ff13b3046

Subscribe to this mod's changes

ship-it is a skill published in the GitHub repository T4LEL/Claude-Arsenal (1 stars, last pushed 2mo ago), licensed MIT. It adds 37 tokens to every session and 682 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

workers-best-practices

Cloudflare Workers best practices for production applications. Use when writing, reviewing, or configuring Workers.

cloudflare/skills · 25 tokens

find-journalists

Build, refine, dedupe, and enrich small fit-checked journalist lists for newsjack campaigns. Uses the newsjack CLI (preferred) or the medialyst MCP for news search and journalist enrichment, and falls back to a best-effort local mode with no verified contacts; the agent owns how returned data is organized.

elvisun/newsjack · 69 tokens

story-origin-check

Recover the first public timestamp and canonical major coverage for a newsjacking signal, then decide whether newer coverage is the same story, a different story, or a materially new development.

elvisun/newsjack · 40 tokens

relevance-coarse-filter

Cheap, high-recall first-pass filter that removes obvious junk from a detector candidate pool before expensive story-origin research and PR judgment. Decides keep, monitoronly, or reject — never ranks, writes angles, verifies dates, or decides whether to pitch.

elvisun/newsjack · 57 tokens

annotating-task-lineage

Annotate Airflow tasks with data lineage using inlets and outlets. Use when the user wants to add lineage metadata to tasks, specify input/output datasets, or enable lineage tracking for operators without built-in OpenLineage extraction.

astronomer/agents · 51 tokens

checking-freshness

Quick data freshness check. Use when the user asks if data is up to date, when a table was last updated, if data is stale, or needs to verify data currency before using it.

astronomer/agents · 44 tokens