Agent skill

Ship Safety

by polarsource in polarsource/polar

Check whether a diff is safe to deploy — schema changes that break the currently running code, blocking DDL, renaming or moving background task actors while jobs are in flight, queue priority, cron…

MITAuto-check passedData & Analytics

Install Ship Safety

skills CLI
$ npx skills add polarsource/polar --skill ship-safety -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install polarsource/polar ship-safety --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/polarsource/polar.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ship-safety .claude/skills/ship-safety && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ship-safety
GitHub stars
10k
Token cost
~1.4k tokens
SKILL.md length
725 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

Check whether a diff is safe to deploy — schema changes that break the currently running code, blocking DDL, renaming or moving background task actors while jobs are in flight, queue priority, cron…

  • Works in 5 steps: Schema ahead of code → Blocking DDL → Tasks already in flight → …
  • Tasks that involve Scheduled and recurring tasks
  • SKILL.md covers Scope, Checks and Output
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ship Safety is an agent skill from polarsource/polar. Check whether a diff is safe to deploy — schema changes that break the currently running code, blocking DDL, renaming or moving background task actors while jobs are in flight, queue priority, cron catch-up, locking, batch size, and whether the change should be split into more than one PR. Use before merging a PR that touches migrations, tasks.py, models, or removes an endpoint.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Data & Analytics, covering Scheduled and recurring tasks and DataFrames. The repository describes itself as: Polar — A billing platform for the intelligence era. The licence is MIT.

When your agent uses it

  • Tasks that involve Scheduled and recurring tasks
  • Tasks that involve DataFrames

Example prompts

  • “/ship-safety”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Schema ahead of code
  2. Blocking DDL
  3. Tasks already in flight
  4. Locks and volume
  5. Split this PR

What it can do on your machine

Read from SKILL.md and the folder at commit 71c1ac6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ship Safety loads about 1.4k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 725 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from polarsource/polar at commit 71c1ac6, republished under its MIT licence (© polarsource). 725 words, ~1,399 tokens.

Download SKILL.mdSave it as .claude/skills/ship-safety/SKILL.md (or your agent's skills folder).
name
ship-safety
description
Check whether a diff is safe to deploy — schema changes that break the currently running code, blocking DDL, renaming or moving background task actors while jobs are in flight, queue priority, cron catch-up, locking, batch size, and whether the change should be split into more than one PR. Use before merging a PR that touches migrations, tasks.py, models, or removes an endpoint.
license
MIT
metadata.author
polar
metadata.version
1.0.0

Ship Safety (Polar)

The handle is the diff. The evidence is what breaks between the moment this merges and the moment it is fully deployed.

Every check here is about that gap. Polar does not deploy atomically: migrations run first, the API deploys before the workers, the old frontend can be live against the new backend, and the queues already hold jobs enqueued under the old names. Code that is correct in its final state can still take production down on the way there.

Scope

Diffs touching server/migrations/versions/, **/tasks.py, polar/models/, server/scripts/; or that remove or rename an endpoint; or that span server/ and clients/ with a dependency between them.

Owned elsewhere. ADR-0006 covers the migration rules — lock timeout (5s for lock-taking DDL, 5min for CREATE INDEX CONCURRENTLY), nullable → batched run_batched_update script → NOT NULL across separate PRs, the unconditional UPDATE in the enforce migration, and keeping migration PRs isolated from code. CI enforces it with the Migration Isolation Check. adr-check reports violations; do not restate ADR-0006 here. Reinvented helpers → reuse-check. Billing-specific lock and cycle rules → billing-review.

What is left for you is everything ADR-0006 does not say.

Checks

1. Schema ahead of code

ADR-0006 stops code shipping ahead of its schema. The reverse still bites: between the migration and the new code, the old code runs against the new schema.

  • Dropping a column or table breaks the running app immediately — SQLAlchemy maps every model to a table at import, so a dropped table can fail before any query runs. Stop using it, deploy, drop in a later PR.
  • Renaming is always two steps.

Ask of every schema change: is the currently-deployed code still correct against this?

2. Blocking DDL
  • postgresql_concurrently=True for an index on a large table, with the migration outside a transaction. Size is not the test: a concurrent build waits for every concurrent transaction in the database, so it is slow on a busy database even when the table is empty. Flag any CONCURRENTLY still carrying the template's 5s timeout — that is a failed deploy, not a fast-fail (ADR-0006).
  • For NOT NULL on a large table, prefer CHECK ... NOT VALID then VALIDATE CONSTRAINT, so Postgres skips the full-table lock. On a small table this is ceremony — say which you think applies.
  • New foreign keys on money tables get ondelete="restrict".
Show full SKILL.md (345 more words)Show less
3. Tasks already in flight

When the PR merges, the queues hold jobs enqueued by the old code.

  • Renaming an actor strands every queued job — the worker looks for the old actor_name and finds nothing. Sequence: add order.invoice.v2, start enqueueing it, deploy, wait for the old queue to drain, then remove the old actor and swap the name back. Moving an actor to a different queue is the same problem.
  • Changing a signature breaks jobs enqueued with the old arguments. New parameters need defaults.
  • Queue priority. TaskPriority.HIGH is checkout-path only. Analytics, exports and backfills go LOW. Slow work on HIGH starves checkout.
  • Cron actors. A new cron_trigger needs an answer for a missed run. A catch-up loop that walks forward through skipped periods usually computes state wrong; prefer an invariant alert that the run did not happen.
  • Retries. Polar relies on automatic retries. A new failure path must raise, not swallow, and max_retries=0 must be deliberate.
4. Locks and volume
  • A new with_for_update belongs in the task or service that owns the unit of work, not inside a processor-specific helper. Every lock needs an answer to what releases this if the process dies?
  • Release on one path only. A lock released on two paths is a bug waiting to happen.
  • Loading every matching row into memory does not survive production volume.
  • A scheduled sweep that scans an entire busy table needs an index or a bounded window.
5. Split this PR

Flag for splitting when the diff:

  • removes a backend endpoint and updates its frontend caller — the old frontend can be live against the new backend;
  • renames an actor and removes the old one together;
  • changes native mobile code alongside TypeScript — native blocks an over-the-air release, so ship the TS-only change first;
  • was already flagged in review as "should move to another module". A follow-up PR is a fine answer, but say so rather than silently deferring.

Output

## Ship Safety

### 🔴 Blocking
- `file:line` — <what breaks, in which window>. Fix: <fix>

### 🟠 Should fix
- `file:line` — <what happens under load>. Fix: <fix>

### 🟡 Question
- `file:line` — <question, including "split this PR?">

### Notes
- run before merge: <script path, or none>
- manual step after deploy: <e.g. "remove order.invoice v1 after 4h", or none>

### Verdict
✅ Safe to ship  |  ❌ n blocking, n should-fix

Fill in Notes even when the verdict is green. A required script run that is not written down is a required script run that does not happen.

© polarsource, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/ship-safety of polarsource/polar.

Open the folder on GitHubat commit 71c1ac6

Compare with similar skills

Ship Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ship Safety compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ship Safety this skillpolarsource/polar10k—~1.4kAutomated safety check: PassMIT
Chdb Datastorevemetric/vemetric3952 repos~1.4kAutomated safety check: PassApache-2.0
CSV Data Summarizercoffeefuelbump/csv-data-summarizer-claude-skill4682 repos~1.4kAutomated safety check: PassNone
Pandas ProJeffallan/claude-skills12k1 repos~1.5kAutomated safety check: PassMIT
Paper FiguresEvoScientist/EvoSkills4761 repos~4.4kAutomated safety check: PassApache-2.0
Python Executorcortega26/chile-hub1132 repos~1.5kAutomated safety check: PassMIT

Similar skills

  • Chdb Datastore

    vemetric/vemetric

    A skill your agent uses when the user has tabular data (pandas DataFrame, parquet, csv, Arrow, json) and wants to filter, group, aggregate, join, or speed up slow pandas.

    395 GitHub starsUsed in 2 repos~1.4k tokens
    Data & AnalyticsAuto-check passed
  • CSV Data Summarizer

    coffeefuelbump/csv-data-summarizer-claude-skill

    Analyzes CSV files, generates summary stats, and plots quick visualizations using Python and pandas.

    468 GitHub starsUsed in 2 repos~1.4k tokens
    Data & AnalyticsAuto-check passed
  • Pandas Pro

    Jeffallan/claude-skills

    Handles pandas DataFrame work: cleaning, merging, groupby aggregation, pivots, time-series resampling and memory tuning, with checks on dtypes, shapes and nulls.

    12k GitHub starsUsed in 1 repo~1.5k tokens
    Data & AnalyticsAuto-check passed
  • Paper Figures

    EvoScientist/EvoSkills

    A skill your agent uses to produce standalone, publication-ready PNG graphics and reproducible matplotlib scripts from tabular data (CSVs or DataFrames).

    476 GitHub starsUsed in 1 repo~4.4k tokens
    Data & AnalyticsAuto-check passed
  • Python Executor

    cortega26/chile-hub

    Execute Python code in a safe sandboxed environment via [inference.sh](https://inference.sh).

    113 GitHub starsUsed in 2 repos~1.5k tokens
    Data & AnalyticsAuto-check passed
  • Dataframely

    Quantco/dataframely

    Best practices for polars data processing with dataframely. An agent skill from Quantco/dataframely.

    619 GitHub stars~2.4k tokensUpdated today
    Data & AnalyticsAuto-check passed

More from polarsource/polar

All 17 skills in this repo
  • Polar Python SDK

    polarsource/polar

    Integrate Polar billing in server-side Python applications using the versioned Polar and PolarAsync clients.

    10k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Polar Typescript SDK

    polarsource/polar

    Integrate Polar billing in server-side TypeScript applications using the versioned createPolar and createPolarCore clients.

    10k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Adr Check

    polarsource/polar

    Check a code change against the repo's Accepted Architecture Decision Records (ADRs) in handbook/engineering/decisions/ and report violations with citations.

    10k GitHub stars~771 tokensUpdated today
    Auto-check passed
  • API Surface Review

    polarsource/polar

    Review changes to Polar's API contract — Pydantic schemas, FastAPI endpoints, OpenAPI output and the generated SDKs.

    10k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Billing Review

    polarsource/polar

    Review a diff that touches Polar's billing domain — subscriptions, cycles and crons, orders, billing entries, meters and usage, discounts, checkout, payments and dunning, refunds, disputes, payouts…

    10k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Interview Task

    polarsource/polar

    Prepare an interview task for a candidate, as part of our hiring process.

    10k GitHub stars~933 tokensUpdated today
    Auto-check passed

Questions about Ship Safety

What does Ship Safety do?

Check whether a diff is safe to deploy — schema changes that break the currently running code, blocking DDL, renaming or moving background task actors while jobs are in flight, queue priority, cron…. Ship Safety is an agent skill from polarsource/polar. Check whether a diff is safe to deploy — schema changes that break the currently running code, blocking DDL, renaming or moving background task actors while jobs are in flight, queue priority, cron catch-up, locking, batch size, and whether the change should be split into more than one PR.

When should I use Ship Safety?

Ship Safety fits situations like: tasks that involve Scheduled and recurring tasks; tasks that involve DataFrames.

How do I install Ship Safety in Claude Code?

Run `npx skills add polarsource/polar --skill ship-safety -a claude-code`. Or copy the skill folder (.agents/skills/ship-safety in polarsource/polar) into .claude/skills/ship-safety in your project. Claude Code loads it when a task matches its description.

How do I install Ship Safety in Codex?

Run `npx skills add polarsource/polar --skill ship-safety -a codex`. Or copy the skill folder (.agents/skills/ship-safety in polarsource/polar) into .agents/skills/ship-safety in your project. Codex loads it when a task matches its description.

Can I use Ship Safety in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add polarsource/polar --skill ship-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ship-safety, .gemini/skills/ship-safety, .github/skills/ship-safety and .opencode/skills/ship-safety in your project.

What does Ship Safety need to run?

SKILL.md names no scripts, command-line tools or credentials: Ship Safety is instructions for the agent only.

Does Ship Safety access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ship Safety safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ship Safety use?

Ship Safety is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ship Safety use?

About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ship Safety?

Skills that share tags, products or a category with Ship Safety: Chdb Datastore (vemetric/vemetric, 395 stars), CSV Data Summarizer (coffeefuelbump/csv-data-summarizer-claude-skill, 468 stars), Pandas Pro (Jeffallan/claude-skills, 12k stars) and Paper Figures (EvoScientist/EvoSkills, 476 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ship Safety?

polarsource (a GitHub organization) maintains it in polarsource/polar, which has 10,343 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 9, 2026.

Source: polarsource/polar on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.