Agent skill

Shipping Build Artifacts

by kajisho5 in kajisho5/ffmpeg-skill

Make the build step a real gate on what you actually distribute — build scripts that warn and exit 0 on a missing input, size checks with only an upper bound, hand-maintained file lists that drift…

MITAuto-check passedMedia & Creative

Install Shipping Build Artifacts

skills CLI
$ npx skills add kajisho5/ffmpeg-skill --skill shipping-build-artifacts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kajisho5/ffmpeg-skill shipping-build-artifacts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kajisho5/ffmpeg-skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/build-artifacts .claude/skills/shipping-build-artifacts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
shipping-build-artifacts
GitHub stars
1.9k
Token cost
~2.1k tokens
SKILL.md length
964 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Make the build step a real gate on what you actually distribute — build scripts that warn and exit 0 on a missing input, size checks with only an upper bound, hand-maintained file lists that drift…

  • Works in 4 steps: Build. → List every entry in the artifact and… → Install or load it **from a directory… → …
  • Reviewing a build/package script
  • SKILL.md covers A script that warns and exits…, Bound the artifact size on…, Derive the file list, or check… and Committed build outputs go…, plus 4 more sections
  • Calls npx, python and jq

What it does

Shipping Build Artifacts is an agent skill from kajisho5/ffmpeg-skill. Make the build step a real gate on what you actually distribute — build scripts that warn and exit 0 on a missing input, size checks with only an upper bound, hand-maintained file lists that drift from the entrypoints they must cover, committed bundles that go stale when only the source changes, GNU-only shell in release scripts that aborts on the other OS, and verification that runs against the source tree instead of the artifact. Use when writing or reviewing a build/package script, a dist/ copy step, a release…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Media & Creative. The licence is MIT.

When your agent uses it

  • Reviewing a build/package script
  • A dist/ copy step
  • A release workflow that uploads a zip
  • A committed compiled asset

Example prompts

  • “/shipping-build-artifacts”

Requirements

  • Python 3
  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Build.
  2. List every entry in the artifact and assert the entrypoints are present.
  3. Install or load it **from a directory the source tree is not on the load path
  4. Only then upload.

What it can do on your machine

Read from SKILL.md and the folder at commit 1f7e7e3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • python
    • jq
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Shipping Build Artifacts loads about 2.1k tokens when it runs. Until then it costs about 155 tokens; SKILL.md has 964 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~155
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kajisho5/ffmpeg-skill at commit 1f7e7e3, republished under its MIT licence (© kajisho5). 964 words, ~2,103 tokens.

Download SKILL.mdSave it as .claude/skills/shipping-build-artifacts/SKILL.md (or your agent's skills folder).
name
shipping-build-artifacts
description
Make the build step a real gate on what you actually distribute — build scripts that warn and exit 0 on a missing input, size checks with only an upper bound, hand-maintained file lists that drift from the entrypoints they must cover, committed bundles that go stale when only the source changes, GNU-only shell in release scripts that aborts on the other OS, and verification that runs against the source tree instead of the artifact. Use when writing or reviewing a build/package script, a `dist/` copy step, a release workflow that uploads a zip or installer, or a committed compiled asset.

Shipping Build Artifacts

Lint, type-check, and tests run against the source tree. What users install is a different set of bytes — assembled by a script that most gates never look at, then uploaded by a workflow that trusts whatever the script left behind. Every failure below ships a broken or stale artifact under fully green CI.

A script that warns and exits 0 is not a gate

The shape is universal: a declared list of inputs, a copy loop, a friendly warning when one is missing.

js
for (const f of DIST_FILES) {
  if (!fs.existsSync(f)) {
    console.warn(`Warning: ${f} not found, skipping`);   // build "succeeds"
    continue;
  }
  fs.copyFileSync(f, path.join("dist", f));
}

Move one required file aside and the script prints a line nobody reads, exits 0, and produces a dist/ without it. Nothing downstream notices: the test job ran against the source tree, and the release job zips dist/ and attaches it to a public release. The artifact is wholly non-functional — the entrypoint imports a file that isn't there — and the failure is discovered by users.

js
const missing = DIST_FILES.filter((f) => !fs.existsSync(f));
if (missing.length) {
  console.error(`Missing build inputs: ${missing.join(", ")}`);
  process.exit(1);
}

The rule: inside a build script, warn may only describe something the artifact survives without. If you cannot say what still works when that file is absent, it is an error and the process must exit non-zero.

Bound the artifact size on both sides

A packaging check with only a ceiling — "fail if the zip exceeds 500 KB" — is a cost guard, not a correctness one. A build that silently dropped half its files is smaller, so it passes the only check that exists.

js
assert(bytes < 500 * 1024, "package too large");
assert(bytes > 20 * 1024, "package suspiciously small — inputs likely missing");
assert(entries.length === DIST_FILES.length, "package entry count mismatch");

Better still, assert on contents rather than a proxy: list the archive's entries and compare against the set the entrypoints require.

Derive the file list, or check it against the entrypoints

DIST_FILES — like a build backend's only-include, or a hand-written package_data — is a second copy of "what this app is made of." The first copy is the manifest, the entry HTML, and the import graph. They drift in one direction: someone adds utils.js, references it from the popup, and forgets the copy list. The build stays green and the feature is dead in the packaged app.

Either derive the list (bundle from the real entrypoints), or add a check that every path referenced by the manifest and by <script src> / importScripts exists in dist/ after the build. A hand-maintained allowlist with no such check is a bug scheduled for a future commit.

The same rule covers any place dependency or asset metadata is restated by hand — a standalone launcher script whose inline dependency header duplicates the project manifest's dependencies, for instance. If duplication is unavoidable, add a test that normalizes both lists and compares them, so drift fails in CI instead of at a user's install.

Committed build outputs go stale silently

When a compiled or minified bundle is committed and served directly, the bundle is the program and its source is a comment until someone rebuilds. Editing only the source ships nothing; the page keeps serving the previous bundle, and no test or linter says a word.

  • Rebuild in CI and diff against the committed output; fail on drift.
  • Pin the builder to an exact version — the diff is only meaningful if the output is byte-deterministic.
  • Confirm that determinism once across the environments people actually use (native toolchain vs. container image), so the check is runnable locally too.
bash
npx -y esbuild@0.24.2 src/app.jsx --jsx=transform --minify --outfile=/tmp/app.js
diff /tmp/app.js web/app.js

Rebuild and commit the output in the same commit as the source change. A "rebuild bundles" follow-up commit means every commit in between shipped code that does not match its source.

Show full SKILL.md (399 more words)Show less

Release scripts run on an OS you didn't write them on

Build scripts are written on a developer machine and executed on the runner. GNU-only tooling is the usual break, and set -e turns it into a total abort on a line that merely reads a version number:

bash
# Breaks under BSD grep (macOS): -P / lookbehind are GNU extensions.
VERSION=$(grep -Po '(?<=^version = ")[^"]+' pyproject.toml)

Read structured metadata with a parser instead of a regex, and prefer a runtime you already depend on:

bash
VERSION=$(python -c 'import tomllib;print(tomllib.load(open("pyproject.toml","rb"))["project"]["version"])')
VERSION=$(jq -r .version package.json)

Then pin it with a test: the version the build script extracts must equal the version declared in the project manifest. Without that, the failure mode is a release tagged v1.4.0 whose artifact reports 1.3.2, and nothing in the pipeline disagrees.

Verify the artifact, then publish — in that order, in that job

Attaching a file to a public release, pushing a tag, or uploading to a registry are the least reversible steps in the project. The verification must sit between the build and the upload, in the same job. A separate green "test" job proves nothing about the artifact: it ran against the source tree.

Minimum ordering:

  1. Build.
  2. List every entry in the artifact and assert the entrypoints are present.
  3. Install or load it from a directory the source tree is not on the load path of, and exercise one real symbol or command — not merely that a top-level name resolves.
  4. Only then upload.

Step 3 is the one that gets skipped, and it is the only step that distinguishes "the archive has files in it" from "the thing runs." Run it somewhere else on disk, or it passes against the sources and proves nothing.

Checklist

Build script:
- [ ] Missing declared input → non-zero exit, not a warning
- [ ] Size assertions have a floor as well as a ceiling
- [ ] File list is derived, or checked against manifest/entry-HTML references
- [ ] Duplicated dependency metadata has a drift test
- [ ] No GNU-only flags (grep -P, sed -i'' semantics) in scripts CI also runs
- [ ] Version extracted with a parser, and asserted equal to the declared version

Committed build outputs:
- [ ] CI rebuilds and diffs; drift fails
- [ ] Builder pinned to an exact version; output confirmed deterministic
- [ ] Output committed alongside the source change, not in a follow-up

Release:
- [ ] Artifact contents listed and asserted before upload
- [ ] Artifact installed/loaded from outside the repo and exercised
- [ ] Verification runs in the same job as the upload, before it

Note for this repository (ffmpeg-skill)

package.json's "files" list is the equivalent of DIST_FILES here — it must list exactly what ships (bin/, scripts/, mcp/, references/, SKILL.md, README.md, LICENSE), and .claude/ (this file included) must NEVER appear in it. npm publish --dry-run is the "list every entry and assert the entrypoints are present" step (step 2 above) — run it before every publish, and watch for stray __pycache__/.pyc files sneaking into the tarball from a local test run (this actually happened once this session and was caught by exactly this check). There is no separate "install from outside the repo and exercise a symbol" step in this repo's release process today (node bin/install.js --dir /tmp/skills from README's Development section is the closest equivalent) — worth doing before a real publish, not just a dry-run.

Source: wdm0006/python-skills (MIT).

© kajisho5, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/build-artifacts of kajisho5/ffmpeg-skill.

Open the folder on GitHubat commit 1f7e7e3

Compare with similar skills

Shipping Build Artifacts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Shipping Build Artifacts compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Shipping Build Artifacts this skillkajisho5/ffmpeg-skill1.9k—~2.1kAutomated safety check: PassMIT
Guizang Social Cardsop7418/guizang-social-card-skill7.4k1 repos~7.8kAutomated safety check: PassAGPL-3.0
Weekly Changelog Videoheygen-com/hyperframes60k—~3.3kAutomated safety check: PassApache-2.0
Anthropic Brand Stylinganthropics/skills180k30 repos~559Automated safety check: PassApache-2.0
MoneyPrinterTurbo Video Generatorharry0703/MoneyPrinterTurbo129k—~2.1kAutomated safety check: WarnMIT
HyperFrames Media Useheygen-com/hyperframes60k—~2.4kAutomated safety check: PassApache-2.0

Similar skills

  • Guizang Social Cards

    op7418/guizang-social-card-skill

    Produces social card sets for Xiaohongshu and WeChat: carousels, Live Photo motion cards and puzzle layouts, and WeChat cover pairs, rendered from single-file HTML.

    7.4k GitHub starsUsed in 1 repo~7.8k tokens
    Media & CreativeAuto-check passed
  • Weekly Changelog Video

    heygen-com/hyperframes

    Turns a weekly changelog markdown file into a branded HyperFrames video with voiceover, animated mock-UI scenes and captions, using fonts, background and scripts bundled in the skill.

    60k GitHub stars~3.3k tokensUpdated today
    Media & CreativeAuto-check passed
  • Anthropic Brand Styling

    anthropics/skills

    Official

    Applies Anthropic's brand colors and fonts to artifacts such as PowerPoint slides, using fixed hex values for text and accents, Poppins headings and Lora body text.

    180k GitHub starsUsed in 30 repos~559 tokens
    Media & CreativeAuto-check passed
  • MoneyPrinterTurbo Video Generator

    harry0703/MoneyPrinterTurbo

    Installs and runs MoneyPrinterTurbo to turn a topic or script into a finished short video with voice-over, subtitles, stock footage and music.

    129k GitHub stars~2.1k tokensUpdated yesterday
    Media & CreativeAuto-check: warnings
  • HyperFrames Media Use

    heygen-com/hyperframes

    Finds, generates and edits media for HyperFrames video projects: music, sound effects, images, icons, logos, voiceovers, captions and color grades.

    60k GitHub stars~2.4k tokensUpdated today
    Media & CreativeAuto-check passed
  • Holo Card Studio

    EverettFish/holo-card-studio

    Create collectible holographic foil cards and two-image lenticular flip cards with AI-generated full-color ukiyo-e and colored sumi-e anime artwork, layered Blender scenes, renders, GLB export, and…

    1.9k GitHub stars~1.4k tokensUpdated 19 days ago
    Media & CreativeAuto-check passed

More from kajisho5/ffmpeg-skill

All 14 skills in this repo
  • Ffmpeg Skill

    kajisho5/ffmpeg-skill

    Edit video and audio with local FFmpeg from natural-language requests: cut, trim, join, resize/reframe (9:16, 1:1), speed change, captions and subtitles (SRT/ASS, animated, karaoke), logos and text…

    1.9k GitHub stars~7.4k tokensUpdated yesterday
    Auto-check passed
  • CI Pipeline Synthesizer

    kajisho5/ffmpeg-skill

    Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.

    1.9k GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Reviewing Ffmpeg Skill Changes

    kajisho5/ffmpeg-skill

    Review a change to the ffmpeg-skill repository for the failures its own contract makes possible — a claim in a result document that is true at one layer and false at the layer a caller reads, a new…

    1.9k GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed
  • Building Python MCP Servers

    kajisho5/ffmpeg-skill

    Builds robust Python MCP (Model Context Protocol) servers with FastMCP — tool design, error contracts, event-loop-safe blocking work, subprocess/CLI wrapping, single-file vs packaged distribution…

    1.9k GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • Concurrent Branches

    kajisho5/ffmpeg-skill

    Resolve conflicts and merges when several branches are open against one repo at the same time — the hotspot files every change must touch (registry manifests, a single version field, shared tool…

    1.9k GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed
  • Guarding Destructive Operations

    kajisho5/ffmpeg-skill

    Add and review preconditions on operations that delete, overwrite, rewrite history, or resolve a caller-supplied name to a filesystem path — refusing instead of warning, placing the guard ahead of…

    1.9k GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed

Questions about Shipping Build Artifacts

What does Shipping Build Artifacts do?

Make the build step a real gate on what you actually distribute — build scripts that warn and exit 0 on a missing input, size checks with only an upper bound, hand-maintained file lists that drift…. Shipping Build Artifacts is an agent skill from kajisho5/ffmpeg-skill. Make the build step a real gate on what you actually distribute — build scripts that warn and exit 0 on a missing input, size checks with only an upper bound, hand-maintained file lists that drift from the entrypoints they must cover, committed bundles that go stale when only the source changes, GNU-only shell in release scripts that aborts on the other OS, and verification that runs against the source tree instead of the artifact.

When should I use Shipping Build Artifacts?

Shipping Build Artifacts fits situations like: reviewing a build/package script; A dist/ copy step; A release workflow that uploads a zip; A committed compiled asset.

How do I install Shipping Build Artifacts in Claude Code?

Run `npx skills add kajisho5/ffmpeg-skill --skill shipping-build-artifacts -a claude-code`. Or copy the skill folder (.claude/skills/build-artifacts in kajisho5/ffmpeg-skill) into .claude/skills/shipping-build-artifacts in your project. Claude Code loads it when a task matches its description.

How do I install Shipping Build Artifacts in Codex?

Run `npx skills add kajisho5/ffmpeg-skill --skill shipping-build-artifacts -a codex`. Or copy the skill folder (.claude/skills/build-artifacts in kajisho5/ffmpeg-skill) into .agents/skills/shipping-build-artifacts in your project. Codex loads it when a task matches its description.

Can I use Shipping Build Artifacts in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kajisho5/ffmpeg-skill --skill shipping-build-artifacts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/shipping-build-artifacts, .gemini/skills/shipping-build-artifacts, .github/skills/shipping-build-artifacts and .opencode/skills/shipping-build-artifacts in your project.

What does Shipping Build Artifacts need to run?

Going by SKILL.md and its folder, Shipping Build Artifacts needs the command-line tools its instructions call (npx, python, jq and npm). Our summary lists: Python 3; Node.js.

Does Shipping Build Artifacts access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Shipping Build Artifacts safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Shipping Build Artifacts use?

Shipping Build Artifacts is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Shipping Build Artifacts use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Shipping Build Artifacts?

Skills that share tags, products or a category with Shipping Build Artifacts: Guizang Social Cards (op7418/guizang-social-card-skill, 7.4k stars), Weekly Changelog Video (heygen-com/hyperframes, 60k stars), Anthropic Brand Styling (anthropics/skills, 180k stars) and MoneyPrinterTurbo Video Generator (harry0703/MoneyPrinterTurbo, 129k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Shipping Build Artifacts?

kajisho5 (a GitHub user) maintains it in kajisho5/ffmpeg-skill, which has 1,909 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 10, 2026.

Source: kajisho5/ffmpeg-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.