Agent skill

Ipaship Audit

by atharvnaik1 in atharvnaik1/ipaship-audit

A skill your agent uses when auditing iOS/Android app submissions for compliance with Apple App Store Review Guidelines or Google Play Developer Policies.

MITAuto-check: notesMobile

Install Ipaship Audit

skills CLI
$ npx skills add atharvnaik1/ipaship-audit --skill ipaship-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install atharvnaik1/ipaship-audit ipaship-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/atharvnaik1/ipaship-audit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/wrappers/claude-code .claude/skills/ipaship-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ipaship-audit
GitHub stars
108
Token cost
~1.5k tokens
SKILL.md length
544 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when auditing iOS/Android app submissions for compliance with Apple App Store Review Guidelines or Google Play Developer Policies.

  • Works in 4 steps: Web Interface (No Code Required) → CLI via cURL → Python Wrapper → …
  • Auditing iOS/Android app submissions for compliance with Apple App Store Review Guidelines
  • SKILL.md covers When to Use, Setup, Usage and Features, plus 3 more sections
  • Calls curl, apt-get and npm; reaches ipaship.com; needs IPASHIP_API_KEY and NVIDIA_KEY

What it does

Ipaship Audit is an agent skill from atharvnaik1/ipaship-audit. Use when auditing iOS/Android app submissions for compliance with Apple App Store Review Guidelines or Google Play Developer Policies. Scan .ipa, .apk, or .zip files against official store policies, generate structured compliance reports, and identify violations with remediation steps.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Mobile, covering Android development, App store release and iOS development. It works with iOS, Android, Python and OpenAI. The repository describes itself as: Let your AI Agent review your iOS/Android apps for appstore policy & security bugs with ipaShip's web app, cli, mcp or claude-skill with safety hooks layer any any llm agent you… The licence is MIT.

When your agent uses it

  • Auditing iOS/Android app submissions for compliance with Apple App Store Review Guidelines
  • Google Play Developer Policies

Example prompts

  • “/ipaship-audit”

Requirements

  • Python 3
  • Node.js
  • A credential in IPASHIP_API_KEY
  • A credential in NVIDIA_KEY

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Web Interface (No Code Required)
  2. CLI via cURL
  3. Python Wrapper
  4. Programmatic — All Language Wrappers

What it can do on your machine

Read from SKILL.md and the folder at commit e420905. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • apt-get
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • ipaship.com

    Also links to:

    • developer.apple.com
    • play.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • IPASHIP_API_KEY
    • NVIDIA_KEY
    • NEXT_PUBLIC_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ipaship Audit loads about 1.5k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 544 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:140
    you see extraction errors, install it: `sudo apt-get install unzip`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from atharvnaik1/ipaship-audit at commit e420905, republished under its MIT licence (© atharvnaik1). 544 words, ~1,535 tokens.

Download SKILL.mdSave it as .claude/skills/ipaship-audit/SKILL.md (or your agent's skills folder).
name
ipaship-audit
description
Use when auditing iOS/Android app submissions for compliance with Apple App Store Review Guidelines or Google Play Developer Policies. Scan .ipa, .apk, or .zip files against official store policies, generate structured compliance reports, and identify violations with remediation steps.
tags
app-store, compliance, audit, ios, android, apple, google-play, app-review

ipaShip — ipaship-audit

Audit your iOS/Android app packages against official store policies before submission. Upload .ipa or .apk files and get a structured compliance report with guideline references, severity ratings, and actionable fixes.

When to Use

  • Before submitting an iOS app to the Apple App Store — catch rejections early
  • Before submitting an Android app to Google Play — identify policy violations
  • During CI/CD to automate pre-submission compliance checks
  • When reviewing third-party apps for compliance risks
  • As part of a code review workflow for mobile apps

Setup

Prerequisites
RequirementDetails
Accountipaship.com — free to use
API KeyGet yours at ipaship.com
App Package.ipa (iOS), .apk (Android), or .zip file (max 150MB)
DependenciesThe server needs unzip installed
Environment Variables
bash
export IPASHIP_API_KEY="your-api-key-here"

Usage

1. Web Interface (No Code Required)
  1. Go to ipaship.com
  2. Upload your .ipa or .apk file
  3. Select your AI provider (Claude, GPT, Gemini, or OpenRouter)
  4. Click "Audit" and wait for the streaming report
2. CLI via cURL
bash
# Basic audit with default provider (Anthropic Claude)
curl -X POST https://ipaship.com/api/audit \
  -H "Authorization: Bearer $IPASHIP_API_KEY" \
  -F "file=@/path/to/your-app.ipa" \
  -F "provider=anthropic" \
  -F "model=claude-3-5-sonnet-20241022"

# With context about your app
curl -X POST https://ipaship.com/api/audit \
  -H "Authorization: Bearer $IPASHIP_API_KEY" \
  -F "file=@/path/to/your-app.ipa" \
  -F "provider=anthropic" \
  -F "model=claude-3-5-sonnet-20241022" \
  -F "context=This is a social media app with user-generated content"

# Using OpenAI
curl -X POST https://ipaship.com/api/audit \
  -H "Authorization: Bearer $IPASHIP_API_KEY" \
  -F "file=@/path/to/your-app.apk" \
  -F "provider=openai" \
  -F "model=gpt-4o"
3. Python Wrapper
python
# wrappers/python/ipaship.py
from ipaship import audit_app

result = audit_app(
    file_path="build/YourApp.ipa",
    provider="anthropic",
    model="claude-3-5-sonnet-20241022",
    api_key="your-key"
)
print(result)
4. Programmatic — All Language Wrappers

The repo ships wrappers in 15+ languages under wrappers/:

LanguagePathStatus
Pythonwrappers/python/ipaship.py✅
Node.jswrappers/npm/index.js✅
Gowrappers/go/ipaship.go✅
Rustwrappers/rust/src/main.rs✅
Rubywrappers/ruby/lib/ipaship.rb✅
Javawrappers/java/✅
Kotlinwrappers/kotlin/✅
Swiftwrappers/swift-cocoapods/✅
Flutter/Dartwrappers/flutter-dart/✅
PHPwrappers/php/✅
C++wrappers/cpp/✅
C# (.NET)wrappers/csharp-dotnet/✅
Rwrappers/r/✅
Expowrappers/expo/✅
Homebrewwrappers/homebrew/✅

Features

Supported AI Providers
ProviderModels
AnthropicClaude Sonnet 4, Claude 3.5 Sonnet, Claude 3 Opus
OpenAIGPT-4o, GPT-4o-mini
Google GeminiGemini 2.5 Flash, Gemini 2.0 Pro
OpenRouterAny model (e.g., anthropic/claude-3.5-sonnet)
ipaShip (NVIDIA)Llama 3.1 405B, NVIDIA NIM models
Audit Report Structure

Every report includes:

  1. Executive Summary — What the app does (from code analysis)
  2. Dashboard — Risk level (LOW/MEDIUM/HIGH), readiness score, issue counts
  3. Phase 1: Policy Compliance — Per-guideline checks with PASS/WARN/FAIL
  4. Phase 2: Remediation Plan — Prioritized fix table with file references
  5. Submission Readiness — Go/no-go verdict with score
Key Capabilities
  • Multi-provider AI — Choose your preferred LLM backend
  • Real-time streaming — Watch the audit generate live
  • IPA & APK support — Both iOS and Android
  • Export — Download as Markdown or PDF
  • Zero-trust — Files deleted after analysis, API keys stay client-side
  • Rate limited — 5 requests/minute per client (DDoS protection)
Show full SKILL.md (197 more words)Show less

Common Pitfalls

  1. Forgetting unzip — The server needs unzip installed to extract packages. If you see extraction errors, install it: sudo apt-get install unzip.
  2. File too large — Maximum upload size is 150MB. For larger apps, trim the .ipa/.apk first.
  3. No source files found — Ensure your app package isn't encrypted or DRM-protected. The auditor only analyzes readable source code (.swift, .java, .kt, etc.).
  4. API key in the wrong place — The server uses NVIDIA_KEY or NEXT_PUBLIC_API_KEY env vars for the backend. For BYOK (bring your own key), pass it in the upload form.
  5. Binary-only apps — Apps compiled without source code (e.g., Unity builds with only IL2CPP binaries) will have few files to analyze. The audit quality depends on available source.

Verification

After setting up:

  1. Deploy the app locally: npm run dev
  2. Upload a test .ipa or use the cURL command above
  3. Verify you get a streaming JSON response starting with {"type":"meta","filesScanned":N}
  4. Check that the final report includes both Phase 1 (compliance checks) and Phase 2 (remediation plan)
  5. Test with different providers by changing the provider field

References

© atharvnaik1, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in wrappers/claude-code of atharvnaik1/ipaship-audit.

Open the folder on GitHubat commit e420905

Compare with similar skills

Ipaship Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ipaship Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ipaship Audit this skillatharvnaik1/ipaship-audit108—~1.5kAutomated safety check: NotesMIT
uni-app Native App Packagingfeige996/unibest2.3k—~651Automated safety check: PassMIT
Suede AsoJasonColapietro/suede-creator-skills127—~4.3kAutomated safety check: PassMIT
Senior Mobileborghei/Claude-Skills891—~1.9kAutomated safety check: PassMIT
Phoneagentrounak/PhoneAgent800—~2.2kAutomated safety check: PassMIT
Expo Brownfield Integrationmweinbach/agent-coworker1562 repos~900Automated safety check: NotesCustom licence

Similar skills

  • A comprehensive skill for uni-app native app offline packaging. Use this skill to package uni-app as native Android/iOS apps, configure native app settings…

    2.3k GitHub stars~651 tokensUpdated 25 days ago
    MobileAuto-check passed
  • Suede Aso

    JasonColapietro/suede-creator-skills

    Suede-owned app-store optimization discipline for keyword fields, titles, subtitles, descriptions, screenshots, ratings context, and competitor listing audits.

    127 GitHub stars~4.3k tokensUpdated today
    MobileAuto-check passed
  • Senior Mobile

    borghei/Claude-Skills

    A skill your agent uses when the user asks to "build a mobile app", "scaffold React Native project", "create SwiftUI views", "set up Jetpack Compose", "optimize mobile performance", "configure Expo…

    891 GitHub stars~1.9k tokensUpdated 3 days ago
    MobileAuto-check passed
  • Phoneagent

    rounak/PhoneAgent

    Control a connected iPhone, iOS simulator, Android emulator, or Android device from macOS through PhoneAgent's JSON-RPC bridge.

    800 GitHub stars~2.2k tokensUpdated 1 mo ago
    MobileAuto-check passed
  • Expo Brownfield Integration

    mweinbach/agent-coworker

    Helps add Expo and React Native to an existing native iOS or Android app, and choose between a prebuilt AAR or XCFramework and a fully integrated build.

    156 GitHub starsUsed in 2 repos~900 tokens
    MobileAuto-check: notes
  • Simulator Audio E2E

    hyochan/react-native-nitro-sound

    Build and run repeatable react-native-nitro-sound recorder/player regression tests on an iOS Simulator or Android emulator, with explicit virtual-device selection, microphone permission, Maestro…

    961 GitHub stars~1.1k tokensUpdated 10 days ago
    MobileAuto-check passed

Categories

Questions about Ipaship Audit

What does Ipaship Audit do?

A skill your agent uses when auditing iOS/Android app submissions for compliance with Apple App Store Review Guidelines or Google Play Developer Policies. Ipaship Audit is an agent skill from atharvnaik1/ipaship-audit. Use when auditing iOS/Android app submissions for compliance with Apple App Store Review Guidelines or Google Play Developer Policies.

When should I use Ipaship Audit?

Ipaship Audit fits situations like: auditing iOS/Android app submissions for compliance with Apple App Store Review Guidelines; google Play Developer Policies.

How do I install Ipaship Audit in Claude Code?

Run `npx skills add atharvnaik1/ipaship-audit --skill ipaship-audit -a claude-code`. Or copy the skill folder (wrappers/claude-code in atharvnaik1/ipaship-audit) into .claude/skills/ipaship-audit in your project. Claude Code loads it when a task matches its description.

How do I install Ipaship Audit in Codex?

Run `npx skills add atharvnaik1/ipaship-audit --skill ipaship-audit -a codex`. Or copy the skill folder (wrappers/claude-code in atharvnaik1/ipaship-audit) into .agents/skills/ipaship-audit in your project. Codex loads it when a task matches its description.

Can I use Ipaship Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add atharvnaik1/ipaship-audit --skill ipaship-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ipaship-audit, .gemini/skills/ipaship-audit, .github/skills/ipaship-audit and .opencode/skills/ipaship-audit in your project.

What does Ipaship Audit need to run?

Going by SKILL.md and its folder, Ipaship Audit needs the command-line tools its instructions call (curl, apt-get and npm) and credentials named IPASHIP_API_KEY, NVIDIA_KEY and NEXT_PUBLIC_API_KEY. Our summary lists: Python 3; Node.js; A credential in IPASHIP_API_KEY; A credential in NVIDIA_KEY.

Does Ipaship Audit access the network?

SKILL.md names 3 domains. In commands or code: ipaship.com; the agent is likely to contact it when it follows the instructions. As links in the text: developer.apple.com and play.google.com. This is read from the text; nothing was executed.

Is Ipaship Audit safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ipaship Audit use?

Ipaship Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ipaship Audit use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ipaship Audit?

Skills that share tags, products or a category with Ipaship Audit: uni-app Native App Packaging (feige996/unibest, 2.3k stars), Suede Aso (JasonColapietro/suede-creator-skills, 127 stars), Senior Mobile (borghei/Claude-Skills, 891 stars) and Phoneagent (rounak/PhoneAgent, 800 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ipaship Audit?

atharvnaik1 (a GitHub user) maintains it in atharvnaik1/ipaship-audit, which has 108 GitHub stars. The repository was last updated on May 25, 2026.

Source: atharvnaik1/ipaship-audit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.