Agent skill

Shipping Artifacts

by phuryn in phuryn/pm-skills

The durable documentation set that makes an AI-built (vibe-coded) app reviewable before shipping.

MITAuto-check passedTesting & QA

Install Shipping Artifacts

skills CLI
$ npx skills add phuryn/pm-skills --skill shipping-artifacts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install phuryn/pm-skills shipping-artifacts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/phuryn/pm-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/pm-ai-shipping/skills/shipping-artifacts .claude/skills/shipping-artifacts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
shipping-artifacts
GitHub stars
27k
Token cost
~2.2k tokens
SKILL.md length
1,163 words
Files
1
Skills in repo
60
Repo updated
First seen
Licence
MIT

At a glance

The durable documentation set that makes an AI-built (vibe-coded) app reviewable before shipping.

  • Works in 5 steps: architecture.md — what the system is and… → flows.md — the journeys where… → permissions.md — who is allowed to do… → …
  • Documenting a codebase for handoff
  • SKILL.md covers Purpose, How the set is organized, Core documents and Conditional documents (include…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Shipping Artifacts is an agent skill from phuryn/pm-skills. The durable documentation set that makes an AI-built (vibe-coded) app reviewable before shipping. A small core every app needs — architecture, user/permission flows, permissions, variables/secrets, and a test-coverage map — plus conditional docs added only when they apply: emails, scheduled work, SEO, and embedded agents/automation. Defines what each doc must capture and how a reviewer or auditor uses it. Use when documenting a codebase for handoff, mapping user journeys and trust-boundary crossings, planning…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Test coverage and Customer journey mapping. The repository describes itself as: PM Skills Marketplace: 100+ agentic skills, commands, and plugins — from discovery to strategy, execution, launch, and growth. The licence is MIT.

When your agent uses it

  • Documenting a codebase for handoff
  • Mapping user journeys and trust-boundary crossings
  • Planning test coverage
  • Preparing for a security

Example prompts

  • “/shipping-artifacts”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. architecture.md — what the system is and how it hangs together.
  2. flows.md — the journeys where permissions and side effects are actually exercised.
  3. permissions.md — who is allowed to do what.
  4. variables.md — configuration and secrets, mapped to risk.
  5. tests.md — the verification map: which documented rules are actually checked, which are only proposed, and which are checked by nothing.

What it can do on your machine

Read from SKILL.md and the folder at commit 8607e3b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Shipping Artifacts loads about 2.2k tokens when it runs. Until then it costs about 150 tokens; SKILL.md has 1,163 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~150
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from phuryn/pm-skills at commit 8607e3b, republished under its MIT licence (© phuryn). 1,163 words, ~2,181 tokens.

Download SKILL.mdSave it as .claude/skills/shipping-artifacts/SKILL.md (or your agent's skills folder).
name
shipping-artifacts
description
The durable documentation set that makes an AI-built (vibe-coded) app reviewable before shipping. A small core every app needs — architecture, user/permission flows, permissions, variables/secrets, and a test-coverage map — plus conditional docs added only when they apply: emails, scheduled work, SEO, and embedded agents/automation. Defines what each doc must capture and how a reviewer or auditor uses it. Use when documenting a codebase for handoff, mapping user journeys and trust-boundary crossings, planning test coverage, or preparing for a security or performance audit.

Shipping Artifacts: The Docs That Make AI-Built Code Reviewable

Purpose

AI agents write code fast, but they leave no durable record of intent — what the system is supposed to do, who is allowed to do what, where the secrets live, which rules are actually verified. Without that record, no human (and no auditing agent) can tell whether the code is safe to ship. This skill defines the small set of documents that restore reviewability.

These docs live in documentation/ at the repo root and are written for two readers: a human reviewer and the next AI coding agent. They are the intended-state half of every later audit — a security or performance review is only as good as the intent it can compare the code against.

How the set is organized

The set is not a fixed list — it is a small core plus conditional docs you add only when the capability exists.

  • Core docs — every reviewable app has these surfaces, so always produce them.
  • Conditional docs — include one only if the app actually has that capability. If it doesn't, write a single line in architecture.md ("No scheduled work — no cron.md.") rather than inventing an empty document. Reviewability comes from an honest map, and "we don't do X" is part of the map.
  • Most docs are reverse-engineered from code by /document-app. The one exception is tests.md, which is derived from the other docs by /derive-tests — it is the verification map, not a description of a subsystem.

Be brutally honest about the current state without being paranoid. The job is an accurate map, not a clean bill of health. Each doc is short, table-and-bullet heavy, and skips generic theory.

Core documents

Each entry: file · one-line purpose · what it must capture · how a reviewer uses it.

  1. architecture.md — what the system is and how it hangs together.

    • Must capture: product overview + key assumptions; tech stack; how auth/sessions/claims flow end to end; the trust boundaries (e.g. service-role vs. client); a short Known risks / assumptions list (each entry backed by where it shows up in the code, not a generic checklist); a "Related Documents" index of every other doc produced.
    • Reviewer use: the root document — everything else is cross-referenced from here.
  2. flows.md — the journeys where permissions and side effects are actually exercised.

    • Must capture: each load-bearing flow as actor + precondition + success outcome; the step-by-step sequence across UI → server → data → jobs → providers → agents; the authz check at each protected step (which claim/role/scope, on which resource, and the expected deny case); the trust-boundary crossings (browser→server, server→provider, job→app, agent→tool, webhook→app); the state changes and side effects each step causes (writes, emails queued, jobs triggered, outbound calls).
    • Reviewer use: the runtime view a static permissions.md matrix can't show — where and in what order authorization is enforced, and where it can be skipped.
    • Anti-PRD rule: a flow that doesn't touch permissions, data integrity, external side effects, money, privacy, or operational safety does not belong here. This is a security/operations map, not a feature spec.
  3. permissions.md — who is allowed to do what.

    • Must capture: roles/claims; where scope is derived (token vs. DB); a resource × operation × role matrix; which tables have row-level security and which rely on code-enforced checks.
    • Reviewer use: the baseline an access-control audit compares the code against. flows.md shows it in motion; this is the static reference.
  4. variables.md — configuration and secrets, mapped to risk.

    • Must capture: a table of Name · used-by · scope (server/client) · source · rotation · risk; explicit confirmation that no secret is bundled client-side; a pre-go-live checklist.
    • Reviewer use: the secrets/PII-leak surface and the rotation plan during incident response.
  5. tests.md — the verification map: which documented rules are actually checked, which are only proposed, and which are checked by nothing.

    • Must capture, in three clearly separated sections so the map can't read falsely green:
      • Existing coverage — tests that are in the repo today, each tied to the rule it pins (so the map reflects reality, not a wish-list).
      • Proposed tests — recommended cases not yet written, marked by test type (automated unit/integration · guarded live · manual review).
      • Gaps — documented rules with no verification at all, ranked by what crossing them exposes.
    • Each row carries: use-case → rule → expected behavior (including the deny/negative case) → evidence source (doc + code) → status (existing / proposed / none). It also notes which checks are CI-required and gate merges to main.
    • Reviewer use: the operational form of "documented == implemented" — it shows whether each rule the other docs claim is actually pinned by a test today, only proposed, or unverified.
    • Produced by /derive-tests (not /document-app), because it is derived from the other docs and the existing test suite rather than read off a subsystem.
Show full SKILL.md (397 more words)Show less

Conditional documents (include only when the capability exists)

  1. emails.md — every notification the system sends. Include only if the app sends transactional or automated email.

    • Must capture: the queue → processor → provider path; templates and the variables they accept; retry/backoff behavior; where to look when a send fails.
    • Reviewer use: spotting unvalidated template inputs and PII exposure boundaries.
  2. cron.md — all scheduled work and how to operate it safely. Include only if scheduled or background jobs exist.

    • Must capture: an inventory table (job → schedule → function → secrets → limits → retry); how each job stays idempotent; how internal calls authenticate; where to see last runs.
    • Reviewer use: finding forgeable triggers and unbounded background jobs.
  3. seo.md — how a single-page app handles SEO and social previews. Include only if there are public/indexable or bot-facing routes.

    • Must capture: the preview approach (static meta / prerender / edge HTML); a route → needs-SEO → public-data-only table; how dynamic metadata is sanitized; bot-vs-human routing.
    • Reviewer use: catching public-data-only violations and metadata injection on bot routes.
  4. automation.md — embedded agents and other automation paths. Include only if the app embeds AI agents, LLM workflows, tool-calling, webhooks, or external automation.

    • Must capture, per automation/agent: trigger + owner + whether it runs automatically or only after approval; the inputs it may read and the exact tools/APIs it may call (the tool surface is itself a hard guardrail); where steering lives (the prompt) vs. the non-prompt hard guardrails; the output contract back to the app (schema, validation, failure handling); app-owned side effects vs. agent-owned suggestions; and the controls — approval gates, audit/timeline logging, rate limits, retries, kill switch.
    • Reviewer use: makes hidden automation paths visible and draws the line between what an agent proposes and what the app enforces — the highest-risk surface in modern AI-built apps.

Notes

  • Each produced doc adds a reference to itself in architecture.md under a "Related Documents" section, so the set stays discoverable.
  • Skip any conditional document that doesn't apply, and say so in one line rather than inventing content.
  • Keep examples and finished templates out of these docs — they describe this system, not the general method.
  • The agent operating-context file (CLAUDE.md / AGENTS.md) is a different artifact — instructions derived from these docs, not system documentation. It is produced at the handoff step by /ship-check, not here.
  • tests.md is produced by /derive-tests; the rest are produced by /document-app.
  • Do not include an "updated date" line; the file's history is the source of truth.

© phuryn, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in pm-ai-shipping/skills/shipping-artifacts of phuryn/pm-skills.

Open the folder on GitHubat commit 8607e3b

Compare with similar skills

Shipping Artifacts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Shipping Artifacts compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Shipping Artifacts this skillphuryn/pm-skills27k—~2.2kAutomated safety check: PassMIT
Write Testsgrafana/synthetic-monitoring-app171—~1.2kAutomated safety check: PassAGPL-3.0
Prd V07 Test Planningmattgierhart/PRD-driven-context-engineering180—~3.5kAutomated safety check: NotesMIT
Requirementsrizsotto/Bear6.5k—~2kAutomated safety check: PassGPL-3.0
Crap Analysisardalis/RiverBooks1352 repos~3.4kAutomated safety check: PassNone
Code Coverages3s-project/s3s311—~789Automated safety check: PassApache-2.0

Similar skills

  • Write Tests

    grafana/synthetic-monitoring-app

    Official

    Write Jest integration and unit tests for the Grafana Synthetic Monitoring app using React Testing Library, MSW, and src/test helpers.

    171 GitHub stars~1.2k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Prd V07 Test Planning

    mattgierhart/PRD-driven-context-engineering

    Define test cases BEFORE implementation, ensuring every API, business rule, and user journey has verifiable acceptance criteria during PRD v0.7 Build Execution.

    180 GitHub stars~3.5k tokensUpdated 1 mo ago
    Testing & QAAuto-check: notes
  • Requirements

    rizsotto/Bear

    Write, modify, or review a requirement file under docs/requirements -- pick the single owning file, keep the text contract-only, name IDs so they need no explanation, and verify cross-references and…

    6.5k GitHub stars~2k tokensUpdated 2 days ago
    Testing & QAAuto-check passed
  • Crap Analysis

    ardalis/RiverBooks

    Analyze code coverage and CRAP (Change Risk Anti-Patterns) scores to identify high-risk code.

    135 GitHub starsUsed in 2 repos~3.4k tokens
    Testing & QAAuto-check passed
  • Code Coverage

    s3s-project/s3s

    Measure and grow the line coverage of the s3s crate. An agent skill from s3s-project/s3s.

    311 GitHub stars~789 tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Verify Bb

    get-bb/bb

    Verify BB user journeys in an isolated source dev app using dev-browser@next and the matching source CLI.

    4.2k GitHub stars~3.2k tokensUpdated yesterday
    Testing & QAAuto-check passed

More from phuryn/pm-skills

All 60 skills in this repo
  • Reviews a diff by anchoring on agreements between two sides of a boundary, forcing a concrete violating execution, and refuting each finding before reporting it.

    27k GitHub stars~3.6k tokensUpdated 24 days ago
    Auto-check passed
  • A/B Test Analysis

    phuryn/pm-skills

    Validates an experiment's setup, works out lift, p-value and confidence interval from A/B test data, and recommends whether to ship, extend or stop.

    27k GitHub stars~893 tokensUpdated 24 days ago
    Auto-check passed
  • Team OKR Brainstorm

    phuryn/pm-skills

    Drafts three alternative sets of team OKRs, each with an inspiring objective and measurable key results, tied to the company strategy you provide.

    27k GitHub stars~1.1k tokensUpdated 24 days ago
    Auto-check passed
  • Analyzes uploaded cohort data to compute retention curves and feature adoption trends, builds heatmaps and charts, and suggests qualitative follow-up research.

    27k GitHub stars~1.3k tokensUpdated 24 days ago
    Auto-check passed
  • Dummy Dataset Generator

    phuryn/pm-skills

    Generates realistic test datasets with custom columns, row counts and business constraints, output as CSV, JSON, SQL inserts or a runnable Python script.

    27k GitHub stars~983 tokensUpdated 24 days ago
    Auto-check passed
  • Grammar and Flow Checker

    phuryn/pm-skills

    Reviews a draft for grammar, logic and flow problems and returns located, prioritized fix suggestions without rewriting the whole text.

    27k GitHub stars~2.4k tokensUpdated 24 days ago
    Auto-check passed

Categories

Questions about Shipping Artifacts

What does Shipping Artifacts do?

The durable documentation set that makes an AI-built (vibe-coded) app reviewable before shipping. Shipping Artifacts is an agent skill from phuryn/pm-skills. The durable documentation set that makes an AI-built (vibe-coded) app reviewable before shipping.

When should I use Shipping Artifacts?

Shipping Artifacts fits situations like: documenting a codebase for handoff; mapping user journeys and trust-boundary crossings; planning test coverage; preparing for a security.

How do I install Shipping Artifacts in Claude Code?

Run `npx skills add phuryn/pm-skills --skill shipping-artifacts -a claude-code`. Or copy the skill folder (pm-ai-shipping/skills/shipping-artifacts in phuryn/pm-skills) into .claude/skills/shipping-artifacts in your project. Claude Code loads it when a task matches its description.

How do I install Shipping Artifacts in Codex?

Run `npx skills add phuryn/pm-skills --skill shipping-artifacts -a codex`. Or copy the skill folder (pm-ai-shipping/skills/shipping-artifacts in phuryn/pm-skills) into .agents/skills/shipping-artifacts in your project. Codex loads it when a task matches its description.

Can I use Shipping Artifacts in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add phuryn/pm-skills --skill shipping-artifacts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/shipping-artifacts, .gemini/skills/shipping-artifacts, .github/skills/shipping-artifacts and .opencode/skills/shipping-artifacts in your project.

What does Shipping Artifacts need to run?

SKILL.md names no scripts, command-line tools or credentials: Shipping Artifacts is instructions for the agent only.

Does Shipping Artifacts access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Shipping Artifacts safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Shipping Artifacts use?

Shipping Artifacts is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Shipping Artifacts use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Shipping Artifacts?

Skills that share tags, products or a category with Shipping Artifacts: Write Tests (grafana/synthetic-monitoring-app, 171 stars), Prd V07 Test Planning (mattgierhart/PRD-driven-context-engineering, 180 stars), Requirements (rizsotto/Bear, 6.5k stars) and Crap Analysis (ardalis/RiverBooks, 135 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Shipping Artifacts?

phuryn (a GitHub user) maintains it in phuryn/pm-skills, which has 26,825 GitHub stars. The repository holds 60 skills in this directory. The repository was last updated on September 14, 2026.

Source: phuryn/pm-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.