Agent skill

Ship Gate

by Houseofmvps in Houseofmvps/ultraship

Turn the /ship scorecard into a blocking, config-as-code quality gate.

MITAuto-check: notesTesting & QA

Install Ship Gate

skills CLI
$ npx skills add Houseofmvps/ultraship --skill ship-gate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Houseofmvps/ultraship ship-gate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Houseofmvps/ultraship.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ship-gate .claude/skills/ship-gate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ship-gate
GitHub stars
123
Token cost
~1k tokens
SKILL.md length
405 words
Files
1
Skills in repo
28
Repo updated
First seen
Licence
MIT

At a glance

Turn the /ship scorecard into a blocking, config-as-code quality gate.

  • Works in 4 steps: Initialize the config → Run the gate → Explain and fix failures → …
  • The user wants a merge gate
  • SKILL.md covers When to use, Process and Key Principles
  • Calls node and git

What it does

Ship Gate is an agent skill from Houseofmvps/ultraship. Turn the /ship scorecard into a blocking, config-as-code quality gate. Sets per-category score thresholds, hard-fails on leaked secrets or critical findings, and wires the gate into a pre-push hook and CI so nothing below the bar merges. Use when the user wants a merge gate, CI quality gate, pre-push check, or to enforce ship-readiness.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Quality gates, Secrets management and Code quality. The repository describes itself as: "ULTRASHIP" Claude Code plugin — 39 skills, 33 tools, 11 agents for ship-ready workflows: planning, review, pentesting, safety guardrails, canary monitoring, SEO/AI-readiness… The licence is MIT.

When your agent uses it

  • The user wants a merge gate
  • CI quality gate
  • Enforce ship-readiness

Example prompts

  • “/ship-gate”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Bash, Read, Edit, Grep, Glob

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Initialize the config
  2. Run the gate
  3. Explain and fix failures
  4. Enforce it (CI + pre-push)

What it can do on your machine

Read from SKILL.md and the folder at commit ed232cb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Edit
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ship Gate loads about 1k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 405 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Edit, Grep, Glob

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Houseofmvps/ultraship at commit ed232cb, republished under its MIT licence (© Houseofmvps). 405 words, ~1,001 tokens.

Download SKILL.mdSave it as .claude/skills/ship-gate/SKILL.md (or your agent's skills folder).
name
ship-gate
description
Turn the /ship scorecard into a blocking, config-as-code quality gate. Sets per-category score thresholds, hard-fails on leaked secrets or critical findings, and wires the gate into a pre-push hook and CI so nothing below the bar merges. Use when the user wants a merge gate, CI quality gate, pre-push check, or to enforce ship-readiness.
allowed-tools
Bash, Read, Edit, Grep, Glob
argument-hint
[init|run|ci|hook] [directory]

Ship-Gate — Deterministic Quality Gate

The 2026 consensus on AI-written code is "did it pass the gates," not "did a senior read every line." This skill promotes the /ship scorecard from advisory to a blocking, deterministic gate: same scoring as /ship (shared tools/lib/ship-scoring.mjs), compared against thresholds in .ultraship/ship-gate.json, exiting non-zero so it can fail a push or a CI job.

When to use

The user wants a merge gate, a CI quality check, a pre-push guard, or to enforce a minimum ship-readiness score before code goes out.

Process

Phase 1: Initialize the config
bash
node ${CLAUDE_PLUGIN_ROOT}/tools/ship-gate.mjs init <project-directory>

Writes .ultraship/ship-gate.json:

json
{
  "thresholds": { "overall": 80, "seo": 70, "a11y": 80, "security": 90, "quality": 70, "bundle": 70 },
  "hardFail": { "onLeakedSecrets": true, "onCriticalFindings": true },
  "skipMissing": true
}
  • thresholds — minimum score (0–100) per category and overall. Below it = fail.
  • hardFail.onLeakedSecrets — any secret finding fails the gate regardless of score.
  • hardFail.onCriticalFindings — any critical-severity finding (any audit) fails the gate.
  • skipMissing — categories that didn't run (e.g. no HTML → SEO/a11y skipped) are ignored rather than failing. Set false to require every category.

Tune thresholds to the project. Sensible starting points: backend API → drop seo/a11y/bundle or rely on skipMissing; marketing site → raise seo/a11y; pre-revenue MVP → lower overall to 70.

Phase 2: Run the gate
bash
node ${CLAUDE_PLUGIN_ROOT}/tools/ship-gate.mjs run <project-directory>
# or, installed: npx ultraship ship-gate .
# machine-readable: ... run <dir> --json

It runs all six auditors (seo, a11y, secrets, code-profiler, deps, bundle), scores them, and prints a PASS/FAIL table with a merge-confidence number (the overall score). Exit 0 = pass, exit 1 = fail.

Show full SKILL.md (198 more words)Show less
Phase 3: Explain and fix failures

When the gate fails, report exactly which checks were below the bar, then fix:

  • Score below a category threshold → run that category's fixer: /a11y, /secure, /seo, /profile apply fixes.
  • Leaked secret → remove it, rotate the key, move it to an env var (/secure).
  • Critical finding → resolve it before anything else.

Re-run the gate to confirm it now passes. Never lower a threshold just to pass — fix the issue, or change the threshold only with the user's explicit agreement and a reason.

Phase 4: Enforce it (CI + pre-push)

Wire the gate in so it runs automatically:

bash
# GitHub Actions workflow at .github/workflows/ship-gate.yml
node ${CLAUDE_PLUGIN_ROOT}/tools/ship-gate.mjs ci <project-directory>

# Local git pre-push hook (.git/hooks/pre-push) — blocks a push that fails the gate
node ${CLAUDE_PLUGIN_ROOT}/tools/ship-gate.mjs hook <project-directory>

Tell the user how to bypass the local hook in an emergency: git push --no-verify. The CI gate has no bypass by design.

Key Principles

  • One source of truth. The gate and /ship share the same scoring module — the gate can never disagree with the scorecard.
  • Deterministic. Same input → same verdict. Auditable for SOC2/ISO/HIPAA, unlike an LLM-only "looks fine."
  • Fix, don't dodge. Failing the gate means fixing the code, not weakening the threshold.
  • Never block on a missing tool. A tool that can't run leaves its category skipped (or fails only if skipMissing:false), never crashes the gate.

© Houseofmvps, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ship-gate of Houseofmvps/ultraship.

Open the folder on GitHubat commit ed232cb

Compare with similar skills

Ship Gate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ship Gate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ship Gate this skillHouseofmvps/ultraship123—~1kAutomated safety check: NotesMIT
Dev ReviewFHIR/fhir-codegen154—~5kAutomated safety check: PassMIT
Sonarcloud APIaehrc/pathling137—~1.2kAutomated safety check: PassApache-2.0
Quality CImanagedcode/dotnet-skills486—~2.1kAutomated safety check: PassMIT
Code Quality Crapmacalbert/envilder138—~468Automated safety check: PassMIT
Constraint-Driven Developmentaddyosmani/agent-skills103k2 repos~5.2kAutomated safety check: PassMIT

Similar skills

  • Dev Review

    FHIR/fhir-codegen

    Performs a two-track code-quality and QA review in the roles of a staff-level Engineering Lead and QA Lead, then synthesizes both critiques into a single analysis.md.

    154 GitHub stars~5k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Sonarcloud API

    aehrc/pathling

    Expert guidance for using the SonarCloud API to interact with code quality analysis, projects, issues, quality gates, and metrics.

    137 GitHub stars~1.2k tokensUpdated today
    Testing & QAAuto-check passed
  • Quality CI

    managedcode/dotnet-skills

    Set up or refine open-source .NET code-quality gates for CI: formatting, .editorconfig, SDK analyzers, third-party analyzers, coverage, mutation testing, architecture tests, and security scanning.

    486 GitHub stars~2.1k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Code Quality Crap

    macalbert/envilder

    CRAP score quality gate for code complexity and test coverage.

    138 GitHub stars~468 tokensUpdated 3 days ago
    Testing & QAAuto-check passed
  • Constraint-Driven Development

    addyosmani/agent-skills

    Records a project's quality bar in CONSTRAINTS.md and watches diffs for signs an agent quietly weakened it, such as suppressions, skipped tests or lowered thresholds.

    103k GitHub starsUsed in 2 repos~5.2k tokens
    DevelopmentAuto-check passed
  • Hydra Dev

    streamband/hydra-srt

    Run HydraSRT development workflows: mix q quality gate, Elixir unit/E2E tests, native Rust tests, web Vitest/Playwright, and make dev.

    146 GitHub stars~995 tokensUpdated 22 days ago
    Testing & QAAuto-check passed

More from Houseofmvps/ultraship

All 28 skills in this repo
  • Using Ultraship

    Houseofmvps/ultraship

    A skill your agent uses when starting any conversation - establishes how to find and use skills, requiring Skill tool invocation before ANY response including clarifying questions

    123 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • A11y

    Houseofmvps/ultraship

    Accessibility audit + auto-fix (WCAG 2.2 A/AA). An agent skill from Houseofmvps/ultraship.

    123 GitHub stars~1.2k tokensUpdated 3 mo ago
    Auto-check: notes
  • Architecture

    Houseofmvps/ultraship

    Living Architecture Map — auto-generate Mermaid diagrams of your codebase.

    123 GitHub stars~708 tokensUpdated 3 mo ago
    Auto-check: notes
  • Clone Patterns

    Houseofmvps/ultraship

    Learn From the Best — analyze patterns from any codebase and apply them to yours.

    123 GitHub stars~682 tokensUpdated 3 mo ago
    Auto-check: notes
  • Code Review

    Houseofmvps/ultraship

    Code review with principal-engineer-level depth. An agent skill from Houseofmvps/ultraship.

    123 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Compete

    Houseofmvps/ultraship

    Competitive X-Ray — analyze any competitor URL vs your site.

    123 GitHub stars~1.1k tokensUpdated 3 mo ago
    Auto-check: notes

Questions about Ship Gate

What does Ship Gate do?

Turn the /ship scorecard into a blocking, config-as-code quality gate. Ship Gate is an agent skill from Houseofmvps/ultraship. Turn the /ship scorecard into a blocking, config-as-code quality gate.

When should I use Ship Gate?

Ship Gate fits situations like: the user wants a merge gate; CI quality gate; enforce ship-readiness.

How do I install Ship Gate in Claude Code?

Run `npx skills add Houseofmvps/ultraship --skill ship-gate -a claude-code`. Or copy the skill folder (skills/ship-gate in Houseofmvps/ultraship) into .claude/skills/ship-gate in your project. Claude Code loads it when a task matches its description.

How do I install Ship Gate in Codex?

Run `npx skills add Houseofmvps/ultraship --skill ship-gate -a codex`. Or copy the skill folder (skills/ship-gate in Houseofmvps/ultraship) into .agents/skills/ship-gate in your project. Codex loads it when a task matches its description.

Can I use Ship Gate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Houseofmvps/ultraship --skill ship-gate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ship-gate, .gemini/skills/ship-gate, .github/skills/ship-gate and .opencode/skills/ship-gate in your project.

What does Ship Gate need to run?

Going by SKILL.md and its folder, Ship Gate needs the command-line tools its instructions call (node and git). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash, Read, Edit, Grep, Glob.

Does Ship Gate access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ship Gate safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ship Gate use?

Ship Gate is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ship Gate use?

About 1k tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ship Gate?

Skills that share tags, products or a category with Ship Gate: Dev Review (FHIR/fhir-codegen, 154 stars), Sonarcloud API (aehrc/pathling, 137 stars), Quality CI (managedcode/dotnet-skills, 486 stars) and Code Quality Crap (macalbert/envilder, 138 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ship Gate?

Houseofmvps (a GitHub user) maintains it in Houseofmvps/ultraship, which has 123 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on July 8, 2026.

Source: Houseofmvps/ultraship on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.