Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/vegastack/vegastack-cli/shipnpx skills add vegastack/vegastack-cli --skill shipgit clone --depth 1 https://github.com/vegastack/vegastack-cliWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/vegastack/vegastack-cli/ship)<a href="https://agentmods.dev/skills/vegastack/vegastack-cli/ship"><img src="https://agentmods.dev/badge/skills/vegastack/vegastack-cli/ship.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00299 | $0.04267 |
| Opus 5 | $0.00150 | $0.02133 |
| Sonnet 5 | $0.00060 | $0.00853 |
| Haiku 4.5 | $0.00030 | $0.00427 |
Grade A, and why
ship scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 262 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Ship Workflow — @vegastack/cli internal release
Full release cycle for v0.1 internal GitHub Packages publishing: pre-flight tests across all 3 codebases, diff + doc audit, version bump synced across package.json × 3, changelog entry, commit + tag push, post-ship verification.
The actual npm publish is performed by .github/workflows/publish-internal.yml when it sees the v* tag — this skill prepares the release locally and then triggers the workflow by pushing the tag. Do not invoke gh workflow run publish-internal.yml — the tag push is the only correct trigger. Calling the workflow manually risks publishing without a corresponding git tag, which breaks the version-tag-matches-package-version check.
Project context this skill encodes
- 3 codebases under one repo, all version-synced:
package.json(CLI, 398 tests),apps/mcp/package.json(Cloudflare Workers MCP server, 19 tests),apps/dashboard/package.json(Astro Cloudflare Workers eval dashboard, 9 tests). All three carry the same version even though only the CLI publishes via this skill — keeping them aligned makes "what version is this code?" answerable from any package.json. - Bundle is a separate repo (
engg-vegastack-agent-tf-providers). It ships on its own daily cron viabuild-and-publish.yml. This skill never touches it. - App deploys are automatic. Cloudflare Workers Builds watches the repo and redeploys
apps/mcp+apps/dashboardon every push to main. This skill never invokeswrangler deploy. - The dormant
release.ymlis the future public-npm path with cosign + SLSA. It auto-trigger onv*is commented out. This skill never modifies or invokes it. prepublishOnlyguard atscripts/check-bundle-pin.jsrefuses to publish ifexpectedBundleShais the placeholder. The CI workflow setsVEGASTACK_ALLOW_PENDING_BUNDLE_SHA=1to bypass for v0.1 internal builds. Never bypass the guard locally — locally the guard's role is to remind you that the bundle SHA is still stub-pinned, which matters when v1.0 ships publicly.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 262 lines · 299 tokens per session scan A 579ae6d58836
ship is a skill published in the GitHub repository vegastack/vegastack-cli (2 stars, last pushed 3mo ago), licensed MIT. It adds 299 tokens to every session and 4,267 once invoked, about $0.0015 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
release
Cut a Symphony release by bumping the committed version, landing it, tagging the merged commit, and verifying the Burrito release workflow. Use when asked to release, tag, or retag Symphony.
changelog-entry
Add a new entry to CHANGELOG.yml under the current unreleased version (or create the version block if needed), then regenerate documentation. Use when the user says things like "add a changelog entry", "log this fix in the changelog", or "/changelog-entry".
release-notes
Generate user-facing release notes from tickets, PRDs, or changelogs. Creates clear, engaging summaries organized by category (new features, improvements, fixes). Use when writing release notes, creating changelogs, announcing product updates, or summarizing what shipped.
mate-oss-gate
在准备把 MateCloud(或其子集)开源 / 发布到公开仓前使用。按 open-core 边界把关:剥离企业代码、清竞品名与内部路径、查密钥、确认 LICENSE。当用户说"要开源了""发布公开版""开源前检查""oss release"时触发。.
devops/changelog-generation
自动生成 CHANGELOG,基于 git 提交历史和 pipeline 产物信息,遵循 Conventional Commits 和 Keep a Changelog 规范.
changelog-composer
Generates structured changelogs and release notes from git history and PRs, classifying breaking changes, features, fixes, performance, docs. Triggers on: "generate changelog", "write release notes", "what changed since", "prepare release", "release notes for", "diff since tag".