Agent skill

Ship Pack

by MAGA2010 in MAGA2010/hackathon-run

Audits a project for submission readiness by checking README completeness, scanning for secret leaks, validating the submission checklist, and emitting a safe packaging command.

MITAuto-check: notesDevelopment

Install Ship Pack

skills CLI
$ npx skills add MAGA2010/hackathon-run --skill ship-pack -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MAGA2010/hackathon-run ship-pack --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MAGA2010/hackathon-run.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ship-pack .claude/skills/ship-pack && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ship-pack
GitHub stars
390
Token cost
~929 tokens
SKILL.md length
321 words
Files
2 (incl. scripts)
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Audits a project for submission readiness by checking README completeness, scanning for secret leaks, validating the submission checklist, and emitting a safe packaging command.

  • Works in 5 steps: README check → Secret scan → Submission checklist → …
  • Tasks that involve Technical documentation
  • SKILL.md covers Input contract, Execution, Output contract and Acceptance criteria, plus 2 more sections
  • Runs Python scripts from its folder; calls git; needs API_KEY and PRIVATE_KEY

What it does

Ship Pack is an agent skill from MAGA2010/hackathon-run. Audits a project for submission readiness by checking README completeness, scanning for secret leaks, validating the submission checklist, and emitting a safe packaging command. Use immediately before submitting.

Its SKILL.md is about 930 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/audit.py`).

It sits in Development, covering Technical documentation. The licence is MIT.

When your agent uses it

  • Tasks that involve Technical documentation

Example prompts

  • “Use the ship-pack skill to audit a project for submission readiness by checking README completeness, scanning for secret leaks, validating the…”
  • “/ship-pack”

Requirements

  • Python 3
  • A credential in API_KEY
  • A credential in PRIVATE_KEY

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. README check
  2. Secret scan
  3. Submission checklist
  4. Reproducibility test
  5. Packaging command

What it can do on your machine

Read from SKILL.md and the folder at commit de3bcfb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY
    • PRIVATE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ship Pack loads about 929 tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 321 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~929

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:52
    - `.env`, `.env.*` (except `.env.example`)
  • NoteMentions a .env fileSKILL.md:80
    - `.env`, `.env.*` (except `.env.example`)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from MAGA2010/hackathon-run at commit de3bcfb, republished under its MIT licence (© MAGA2010). 321 words, ~929 tokens.

Download SKILL.mdSave it as .claude/skills/ship-pack/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
ship-pack
description
Audits a project for submission readiness by checking README completeness, scanning for secret leaks, validating the submission checklist, and emitting a safe packaging command. Use immediately before submitting.
when_to_use
Trigger when the user is about to submit, mentions "shipping" or "packaging",", or asks "is this safe to commit". Do not invoke during development. Apply…
version
1
category
shipping
tags
audit, release, non-fatal-webhook
dependencies
judge-sim
side_effects
ship
triggers
ship it, submit, package the submission, final audit, release
capabilities
fs_read, fs_write, net, env

ship-pack

Input contract

Required:

  • repo_root: project root

Optional:

  • HACKATHON_SHIP_WEBHOOK: HTTP endpoint that receives the ship audit as JSON after it is written. Delivery is non-fatal; failure only prints a warning.
  • HACKATHON_SHIP_WEBHOOK_TIMEOUT_SECONDS: request timeout (default 3).

Execution

1. README check

For each of the following, mark present / missing:

  • Project name
  • One-liner description
  • Install steps
  • Run steps
  • Environment variables (with .env.example)
  • Demo steps
  • Tech stack
2. Secret scan

Walk the repo (excluding node_modules, .git, dist, build, .hackathon).

Search for:

  • .env, .env.* (except .env.example)
  • API_KEY=, SECRET=, TOKEN=, PASSWORD=, PRIVATE_KEY=
  • AWS / GCP / Azure credential patterns
  • Hard-coded JWTs (long base64 strings in code)

Emit one line per finding. Refuse to proceed if a finding exists.

3. Submission checklist
  • Source code committed
  • README present
  • Demo video / link present
  • Screenshots present
  • Deployment link present
  • Env var documentation present
  • Dependency files committed (package.json, requirements.txt, etc.)
  • Run commands documented
4. Reproducibility test

The judge must be able to git clone && <install> && <run> in < 5 minutes. Emit reproducible: yes | no with a one-line reason.

5. Packaging command

Generate a shell command that excludes:

  • node_modules, .venv, __pycache__
  • .env, .env.* (except .env.example)
  • Local caches (.cache, .next, .turbo)
  • Build artifacts (dist, build, coverage)

Default output: tar czf submit.tar.gz --exclude=... .

Output contract

Files written:

  • .hackathon/state/ship.json (matches src/state/schemas/ship.schema.json)
  • ship.sh (a single-line packaging command, only emitted on PASS)

Acceptance criteria

  • Checks for secret leaks (fails if any found).
  • Checks README for required sections.
  • Checks run steps are documented.
  • Checks submission checklist items.
  • Generates a safe packaging command.
  • Never includes real secrets in the submission package.

Failure modes

ModeBehavior
Secret leak detectedFAIL loud, print the offending line, refuse to ship
README.md missingFAIL loud; ask to write the README first
package.json has placeholderWARN; suggest a single sed/fix
Git working tree dirtyWARN; offer a git stash recipe, do not auto-stash
No .hackathon/state/ship.jsonRefuse; cannot audit what was never verified

Trigger phrases

  • "submit"
  • "ship it"
  • "package for submission"
  • "is it safe to commit"
  • "secret leak check"

© MAGA2010, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in skills/ship-pack of MAGA2010/hackathon-run.

  • SKILL.md
  • scripts/audit.py

Open the folder on GitHubat commit de3bcfb

Compare with similar skills

Ship Pack next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ship Pack compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ship Pack this skillMAGA2010/hackathon-run390—~929Automated safety check: NotesMIT
Meilisearch PHP PHPDoc Writermeilisearch/meilisearch-php757—~569Automated safety check: PassMIT
DDNS Provider DevelopmentNewFuture/DDNS4.7k—~558Automated safety check: PassMIT
Human Writingkataras/jwt212—~1.9kAutomated safety check: PassMIT
Nacos API Doc Updatenacos-group/nacos-group.github.io115—~3.3kAutomated safety check: PassApache-2.0
API Generatinghuangjia2019/claude-code-engineering1.1k—~426Automated safety check: PassNone

Similar skills

  • Meilisearch PHP PHPDoc Writer

    meilisearch/meilisearch-php

    Documents public methods of the meilisearch-php SDK with compact PHPDoc, including @see links, @since tags and the experimental-feature notice.

    757 GitHub stars~569 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Adds or changes a DNS provider in the DDNS project while keeping its code, schemas, tests and Chinese and English docs consistent.

    4.7k GitHub stars~558 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Human Writing

    kataras/jwt

    A skill your agent uses when writing or editing any prose in this repository - the book's preface, its chapters and epilogue, the brand kit notes, the agent skill documents, the changelog, and the…

    212 GitHub stars~1.9k tokensUpdated 26 days ago
    DevelopmentAuto-check passed
  • Nacos API Doc Update

    nacos-group/nacos-group.github.io

    Updates Nacos API documentation from Swagger api.json. An agent skill from nacos-group/nacos-group.github.io.

    115 GitHub stars~3.3k tokensUpdated 15 days ago
    DevelopmentAuto-check passed
  • API Generating

    huangjia2019/claude-code-engineering

    Generate API endpoint documentation from Express route files.

    1.1k GitHub stars~426 tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Mark Task Executed

    ethereum-optimism/superchain-ops

    Mark one or more superchain-ops tasks as EXECUTED by updating each task README's Status line to link the on-chain execution transaction, then open a PR.

    99 GitHub stars~679 tokensUpdated today
    DevelopmentAuto-check passed

More from MAGA2010/hackathon-run

All 15 skills in this repo
  • Decision Log

    MAGA2010/hackathon-run

    Writes every KEEP/CUT/DEFER/PIVOT scope decision into an append-only team log with rationale, author, and timestamp.

    390 GitHub stars~847 tokensUpdated yesterday
    Auto-check passed
  • Demo Coach

    MAGA2010/hackathon-run

    Drafts a 30, 60, or 90-second pitch script for the demo, structured as opening, pain, product, action, result, close.

    390 GitHub stars~895 tokensUpdated yesterday
    Auto-check passed
  • Judge Sim

    MAGA2010/hackathon-run

    Scores a hackathon project 0 to 5 across seven judging dimensions and produces a prioritized fix list for the last hour.

    390 GitHub stars~970 tokensUpdated yesterday
    Auto-check passed
  • Scope Knife

    MAGA2010/hackathon-run

    Forces a KEEP, CUT, or DEFER decision on every feature when scope is too large, no MVP consensus exists, or time is running out.

    390 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Time Box

    MAGA2010/hackathon-run

    Allocates time across the hackathon lifecycle (idea - scope - build - verify - demo - ship) and warns before each deadline slips.

    390 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Fast Verify

    MAGA2010/hackathon-run

    Verifies the demo path runs end-to-end by executing each step in order, recording the actual outcome, and stopping at the first failure with a diagnostic.

    390 GitHub stars~893 tokensUpdated yesterday
    Auto-check passed

Questions about Ship Pack

What does Ship Pack do?

Audits a project for submission readiness by checking README completeness, scanning for secret leaks, validating the submission checklist, and emitting a safe packaging command. Ship Pack is an agent skill from MAGA2010/hackathon-run. Audits a project for submission readiness by checking README completeness, scanning for secret leaks, validating the submission checklist, and emitting a safe packaging command.

When should I use Ship Pack?

Ship Pack fits situations like: tasks that involve Technical documentation.

How do I install Ship Pack in Claude Code?

Run `npx skills add MAGA2010/hackathon-run --skill ship-pack -a claude-code`. Or copy the skill folder (skills/ship-pack in MAGA2010/hackathon-run) into .claude/skills/ship-pack in your project. Claude Code loads it when a task matches its description.

How do I install Ship Pack in Codex?

Run `npx skills add MAGA2010/hackathon-run --skill ship-pack -a codex`. Or copy the skill folder (skills/ship-pack in MAGA2010/hackathon-run) into .agents/skills/ship-pack in your project. Codex loads it when a task matches its description.

Can I use Ship Pack in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MAGA2010/hackathon-run --skill ship-pack -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ship-pack, .gemini/skills/ship-pack, .github/skills/ship-pack and .opencode/skills/ship-pack in your project.

What does Ship Pack need to run?

Going by SKILL.md and its folder, Ship Pack needs Python for the scripts in its folder, the command-line tools its instructions call (git) and credentials named API_KEY and PRIVATE_KEY. Our summary lists: Python 3; A credential in API_KEY; A credential in PRIVATE_KEY.

Does Ship Pack access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ship Pack safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Ship Pack use?

Ship Pack is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ship Pack use?

About 929 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ship Pack?

Skills that share tags, products or a category with Ship Pack: Meilisearch PHP PHPDoc Writer (meilisearch/meilisearch-php, 757 stars), DDNS Provider Development (NewFuture/DDNS, 4.7k stars), Human Writing (kataras/jwt, 212 stars) and Nacos API Doc Update (nacos-group/nacos-group.github.io, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ship Pack?

MAGA2010 (a GitHub user) maintains it in MAGA2010/hackathon-run, which has 390 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 7, 2026.

Source: MAGA2010/hackathon-run on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.