Agent skill

Kc Ship PR

by imran31415 in imran31415/kube-coder

Commit local changes and open a pull request against kube-coder from inside a workspace pod.

MITAuto-check: notesDevelopment

Install Kc Ship PR

skills CLI
$ npx skills add imran31415/kube-coder --skill kc-ship-pr -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install imran31415/kube-coder kc-ship-pr --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/imran31415/kube-coder.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/kc-ship-pr .claude/skills/kc-ship-pr && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kc-ship-pr
GitHub stars
388
Token cost
~2k tokens
SKILL.md length
723 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Commit local changes and open a pull request against kube-coder from inside a workspace pod.

  • Works in 5 steps: Commit locally → Re-sync onto current origin/main (avoid… → Push the branch → …
  • The user wants to push a branch
  • SKILL.md covers Steps, Before shipping and See also
  • Calls git, gh and python3; reaches github.com and api.github.com; needs GITHUB_TOKEN and GH_TOKEN

What it does

Kc Ship PR is an agent skill from imran31415/kube-coder. Commit local changes and open a pull request against kube-coder from inside a workspace pod. Use when the user wants to push a branch or open/update a PR with the workspace GitHub App token.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests. It works with GitHub and Git. The repository describes itself as: helm chart for a isolated dev coding environment pod in kubernetes. The licence is MIT.

When your agent uses it

  • The user wants to push a branch
  • Open/update a PR with the workspace GitHub App token

Example prompts

  • “/kc-ship-pr”

Requirements

  • Python 3
  • A credential in GITHUB_TOKEN
  • Pre-approved tools (allowed-tools): Bash, Read

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Commit locally
  2. Re-sync onto current origin/main (avoid a stale base)
  3. Push the branch
  4. Open the PR
  5. Link the issue (if the PR resolves one)

What it can do on your machine

Read from SKILL.md and the folder at commit fc0b886. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh
    • python3
    • curl
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • api.github.com
    • claude.com

    Also links to:

    • github.com.helper

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • GH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kc Ship PR loads about 2k tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 723 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from imran31415/kube-coder at commit fc0b886, republished under its MIT licence (© imran31415). 723 words, ~2,004 tokens.

Download SKILL.mdSave it as .claude/skills/kc-ship-pr/SKILL.md (or your agent's skills folder).
name
kc-ship-pr
description
Commit local changes and open a pull request against kube-coder from inside a workspace pod. Use when the user wants to push a branch or open/update a PR with the workspace GitHub App token.
allowed-tools
Bash, Read
user-invocable
true
argument-hint
[PR title] (optional; inferred from the commit if omitted)

Ship a PR from a kube-coder workspace

The only GitHub credential here is the App installation token (/home/dev/.credentials/.github-token, ghs_…). The token-refresh sidecar installs a self-refreshing global credential.helper that reads that file fresh on every call, so ordinary git push works — no Git Data API dance needed. gh api also works (it reads GITHUB_TOKEN from ~/.github-env).

There is no user-level gh auth login and no SSH key here, so do not suggest gh auth login or a fork — the App token pushes to origin directly.

If git push is wedged — remote: Invalid username or token or could not read Username — something is shadowing that helper with a point-in-time token. The token file itself is almost never the problem (curl -H "Authorization: token $(cat /home/dev/.credentials/.github-token)" https://api.github.com/user proves it in one line). Diagnose in this order:

bash
git config --show-origin --get-all credential.helper
git config --show-origin --get-all credential.https://github.com.helper
printf 'protocol=https\nhost=github.com\n\n' | git credential fill  # vs. the token file
grep github.com ~/.git-credentials

Three known causes, all "a token frozen an hour ago":

  1. A stale baked http.<host>.extraheader in .git/config — git sends it verbatim and it shadows the helper: git config --unset-all http.https://github.com/.extraheader.
  2. A host-scoped helper chain reset (issue #454) — gh auth setup-git writes an empty helper = under [credential "https://github.com"], which clears the chain and drops the self-refreshing reader; gh auth git-credential then answers with the stale GH_TOKEN your long-lived shell captured before the last rotation. The workspace re-asserts that section every 50 min, so this self-heals — to fix it now, run python3 /github-app/github-app-token.py --configure-git (or --once, which also asks the github-app-token sidecar for a fresh token; the private key lives only in that sidecar since #558, so nothing in your shell can mint one).
  3. A stale github.com line in ~/.git-credentials (persistent on the PVC, so a captured ghs_… outlives its 1-hour validity). The daemon purges these in app mode; delete by hand if you're ahead of it.

One-shot escape hatch that bypasses all three:

bash
git -c credential.helper= \
    -c 'credential.helper=!f() { echo username=x-access-token; echo "password=$(cat /home/dev/.credentials/.github-token)"; }; f' \
    push -u origin <branch>

Only if push is still broken after that, fall back to the Git Data API (§3b). See your github-auth memory for the full background.

Steps

Given the working tree already has the changes staged/committed on a feature branch (create one first if the user is on main):

1. Commit locally
bash
cd /home/dev/kube-coder   # or your worktree
git add -A            # or specific paths
git commit -m "<type>(<scope>): <summary>

<body>

Co-Authored-By: Claude <noreply@anthropic.com>"
2. Re-sync onto current origin/main (avoid a stale base)
bash
git fetch origin main && git rebase origin/main

If the credential helper is somehow unavailable, the repo is public so an unauthenticated fetch also works: git -c credential.helper= -c http.https://github.com/.extraheader= fetch https://github.com/imran31415/kube-coder.git main

3. Push the branch
bash
git push -u origin <branch>
Show full SKILL.md (299 more words)Show less
3b. Fallback — push via the Git Data API (only if git push stays wedged)

Run this Python (token from env or the credential file). Set BRANCH and list the changed files in FILES:

bash
source /home/dev/.credentials/.github-env   # exports GITHUB_TOKEN
python3 - <<'PY'
import os, json, base64, urllib.request, subprocess
TOKEN = os.environ["GITHUB_TOKEN"]; REPO = "imran31415/kube-coder"
API = f"https://api.github.com/repos/{REPO}"
BRANCH = "REPLACE-branch-name"
FILES = subprocess.check_output(
    ["git", "diff", "--name-only", "main", "HEAD"]).decode().split()

def api(method, url, body=None):
    d = json.dumps(body).encode() if body is not None else None
    r = urllib.request.Request(url, data=d, method=method)
    r.add_header("Authorization", f"token {TOKEN}")
    r.add_header("Accept", "application/vnd.github+json")
    if d: r.add_header("Content-Type", "application/json")
    with urllib.request.urlopen(r) as x: return json.load(x)

base = api("GET", f"{API}/git/refs/heads/main")["object"]["sha"]
tree = api("GET", f"{API}/git/commits/{base}")["tree"]["sha"]
entries = []
for f in FILES:
    blob = api("POST", f"{API}/git/blobs",
               {"content": base64.b64encode(open(f, "rb").read()).decode(),
                "encoding": "base64"})
    entries.append({"path": f, "mode": "100644", "type": "blob", "sha": blob["sha"]})
t = api("POST", f"{API}/git/trees", {"base_tree": tree, "tree": entries})
msg = subprocess.check_output(["git", "log", "-1", "--format=%B"]).decode().strip()
commit = api("POST", f"{API}/git/commits",
             {"message": msg, "tree": t["sha"], "parents": [base]})
# New branch: POST a ref. To UPDATE an existing branch (add a commit), use
# PATCH {API}/git/refs/heads/{BRANCH} with {"sha": commit["sha"]} instead.
api("POST", f"{API}/git/refs",
    {"ref": f"refs/heads/{BRANCH}", "sha": commit["sha"]})
print("pushed", commit["sha"][:8], "->", BRANCH)
PY

Notes:

  • New branch → POST /git/refs. Add a commit to an existing PR branch → read the branch's current head first, base the tree on it, then PATCH /git/refs/heads/{BRANCH} with the new commit sha.
  • The commit author is the App (bot), not the user — expected and fine for a PR.
  • Only the files in FILES change; everything else is inherited from base_tree.
4. Open the PR
bash
source /home/dev/.credentials/.github-env
BODY=$(cat <<'EOF'
## What & why
...

## Testing
...

🤖 Generated with [Claude Code](https://claude.com/claude-code)
EOF
)
gh api repos/imran31415/kube-coder/pulls \
  -f title="$ARGUMENTS" -f head="REPLACE-branch-name" -f base="main" -f body="$BODY" \
  --jq '.html_url'

If gh fails, the same works with curl -X POST -H "Authorization: token $GITHUB_TOKEN".

The PR body/title referencing (#N) cross-links but does not auto-close. To close on merge, add Fixes #N to the PR body, or close the issue after merge:

bash
gh api repos/imran31415/kube-coder/issues/N/comments -f body="Resolved by #<pr>."
gh api -X PATCH repos/imran31415/kube-coder/issues/N -f state=closed -f state_reason=completed

Before shipping

Two skills, in this order:

  1. kc-scope-pr — what the diff actually reaches, which tests cover it, what it made worse, what it left untested. Its impacted= and untested= numbers belong in the PR body when they are large: a reviewer who sees "3 files changed" reads the diff differently than one who also sees the blast radius.
  2. kc-preflight — runs the suites for real, so CI is green on the first push.

Never push a branch you haven't at least bash -n/typecheck/test-run locally — CI round-trips are slow.

See also

  • kc-scope-pr for the numbers that make a PR body reviewable, and the tests to run before this one.
  • Your github-auth memory has the full background on the App-token auth setup and the stale-extraheader footgun.
  • To add a commit to an already-open PR, just git push again; if you're using the §3b fallback, repeat it in PATCH mode onto the branch head.

© imran31415, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/kc-ship-pr of imran31415/kube-coder.

Open the folder on GitHubat commit fc0b886

Compare with similar skills

Kc Ship PR next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kc Ship PR compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kc Ship PR this skillimran31415/kube-coder388—~2kAutomated safety check: NotesMIT
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Create Pull Requestcline/cline70k1 repos~1.6kAutomated safety check: PassApache-2.0
Pull Request Title and Body Writeropeninterpreter/openinterpreter69k2 repos~1.1kAutomated safety check: PassApache-2.0
PR Review State Fetchprisma/orm48k—~767Automated safety check: PassApache-2.0
Create Pull Request with Work Item IDmakeplane/plane61k—~824Automated safety check: PassAGPL-3.0

Similar skills

  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Pull Request Title and Body Writer

    openinterpreter/openinterpreter

    Rewrites the title and body of one or more pull requests with gh, leading with why the change was made, then what changed, and describing only the net result.

    69k GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Opens a pull request for the current branch using the repo's template, a work item ID in the title and a description filled in from the actual diff.

    61k GitHub stars~824 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Official

    Generate a clear, concise GitHub PR title and description from the diff between two local git branches, and save it to prDescription.md in the repo root.

    12k GitHub stars~838 tokensUpdated today
    DevelopmentAuto-check passed

More from imran31415/kube-coder

All 8 skills in this repo
  • Kc Entrypoint Change

    imran31415/kube-coder

    Safely edit the workspace pod's boot scripts (start.sh, the entrypoint/ssh-server configmaps) in kube-coder.

    388 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check: notes
  • Kc Issue

    imran31415/kube-coder

    Spin up an isolated agent to work a GitHub issue of kube-coder or any other repo checked out in the workspace.

    388 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check: notes
  • Kc Screenshot

    imran31415/kube-coder

    Capture desktop + mobile, dark + light screenshots of the kube-coder dashboard SPA for visual QA of a UI change.

    388 GitHub stars~870 tokensUpdated 2 days ago
    Auto-check: notes
  • Remote Task

    imran31415/kube-coder

    Launch a Claude task on a remote kube-coder workspace, check task status, or attach to a running session.

    388 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check: notes
  • Kc Preflight

    imran31415/kube-coder

    Run kube-coder's full CI suite locally before pushing — helm lint + unit tests, server.py tests, dashboard + controller SPA builds + vitest, and shell syntax checks.

    388 GitHub stars~1k tokensUpdated 2 days ago
    Auto-check: notes
  • Kc Scope PR

    imran31415/kube-coder

    Scope a kube-coder change before you open or update a PR — what the diff actually touches, which tests reach it, what the change made worse, and what is left untested.

    388 GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check: notes

Works with

Categories

Questions about Kc Ship PR

What does Kc Ship PR do?

Commit local changes and open a pull request against kube-coder from inside a workspace pod. Kc Ship PR is an agent skill from imran31415/kube-coder. Commit local changes and open a pull request against kube-coder from inside a workspace pod.

When should I use Kc Ship PR?

Kc Ship PR fits situations like: the user wants to push a branch; open/update a PR with the workspace GitHub App token.

How do I install Kc Ship PR in Claude Code?

Run `npx skills add imran31415/kube-coder --skill kc-ship-pr -a claude-code`. Or copy the skill folder (.claude/skills/kc-ship-pr in imran31415/kube-coder) into .claude/skills/kc-ship-pr in your project. Claude Code loads it when a task matches its description.

How do I install Kc Ship PR in Codex?

Run `npx skills add imran31415/kube-coder --skill kc-ship-pr -a codex`. Or copy the skill folder (.claude/skills/kc-ship-pr in imran31415/kube-coder) into .agents/skills/kc-ship-pr in your project. Codex loads it when a task matches its description.

Can I use Kc Ship PR in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add imran31415/kube-coder --skill kc-ship-pr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kc-ship-pr, .gemini/skills/kc-ship-pr, .github/skills/kc-ship-pr and .opencode/skills/kc-ship-pr in your project.

What does Kc Ship PR need to run?

Going by SKILL.md and its folder, Kc Ship PR needs the command-line tools its instructions call (git, gh, python3, curl and bash) and credentials named GITHUB_TOKEN and GH_TOKEN. Our summary lists: Python 3; A credential in GITHUB_TOKEN. Its frontmatter pre-approves these tools: Bash, Read.

Does Kc Ship PR access the network?

SKILL.md names 4 domains. In commands or code: github.com, api.github.com and claude.com; the agent is likely to contact these when it follows the instructions. As links in the text: github.com.helper. This is read from the text; nothing was executed.

Is Kc Ship PR safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Kc Ship PR use?

Kc Ship PR is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kc Ship PR use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kc Ship PR?

Skills that share tags, products or a category with Kc Ship PR: Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars), Create Pull Request (cline/cline, 70k stars), Pull Request Title and Body Writer (openinterpreter/openinterpreter, 69k stars) and PR Review State Fetch (prisma/orm, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kc Ship PR?

imran31415 (a GitHub user) maintains it in imran31415/kube-coder, which has 388 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 8, 2026.

Source: imran31415/kube-coder on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.