Agent skill

Ship It

by vectorize-io in vectorize-io/hindsight

Take a PR from review to merged — run the repo's code-review skill on it in a loop (review, fix, re-review) until nothing is left to fix, applying ALL fixes on the PR branch, wait for CI green, then…

MITAuto-check passedDevelopment

Install Ship It

skills CLI
$ npx skills add vectorize-io/hindsight --skill ship-it -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vectorize-io/hindsight ship-it --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vectorize-io/hindsight.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/ship-it .claude/skills/ship-it && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ship-it
GitHub stars
46k
Token cost
~1.9k tokens
SKILL.md length
1,092 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

Take a PR from review to merged — run the repo's code-review skill on it in a loop (review, fix, re-review) until nothing is left to fix, applying ALL fixes on the PR branch, wait for CI green, then…

  • Works in 7 steps: Blocker rule (applies at every step) → Load the PR → Check out the PR branch → …
  • Asked to ship it
  • SKILL.md covers 0b. A figure in the…, 0. Blocker rule (applies at…, 1. Load the PR and 2. Check out the PR branch, plus 5 more sections
  • Calls gh, git and jq; reaches raw.githubusercontent.com

What it does

Ship It is an agent skill from vectorize-io/hindsight. Take a PR from review to merged — run the repo's code-review skill on it in a loop (review, fix, re-review) until nothing is left to fix, applying ALL fixes on the PR branch, wait for CI green, then squash-merge. Use when asked to "ship it", "ship PR

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review. The repository describes itself as: Hindsight: Agent Memory That Learns. The licence is MIT.

When your agent uses it

  • Asked to ship it
  • Tasks that involve Code review

Example prompts

  • “ship it”
  • “/ship-it”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Blocker rule (applies at every step)
  2. Load the PR
  3. Check out the PR branch
  4. Review
  5. Apply ALL fixes
  6. Wait for CI green
  7. Restore the worktree, then merge

What it can do on your machine

Read from SKILL.md and the folder at commit 9269b88. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • raw.githubusercontent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ship It loads about 1.9k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 1,092 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vectorize-io/hindsight at commit 9269b88, republished under its MIT licence (© vectorize-io). 1,092 words, ~1,879 tokens.

Download SKILL.mdSave it as .claude/skills/ship-it/SKILL.md (or your agent's skills folder).
name
ship-it
description
Take a PR from review to merged — run the repo's code-review skill on it in a loop (review, fix, re-review) until nothing is left to fix, applying ALL fixes on the PR branch, wait for CI green, then squash-merge. Use when asked to "ship it", "ship PR
user_invocable
true

Ship It

Input: a PR number or URL, or nothing — then use the current branch's PR (gh pr view with no argument resolves it). If the current branch has no PR yet, push it and open one with gh pr create (maintainer branch only), then continue. Goal: the PR merged with every code-review finding fixed and CI green.

0b. A figure in the description, when the change has a shape

If the PR changes how something flows — a request path, a background job, what a feature does step by step — a picture explains it faster than the diff does. Use the figure skill: write a JSON spec, render one animated SVG, and put it at the top of the PR description. It plays in the description with no upload and no click.

Reference it by commit SHA, not branch name, or the image dies when the branch is deleted at merge: https://raw.githubusercontent.com/<owner>/<repo>/<sha>/<path>.svg. If the SVG is not part of the change itself, don't commit it to the repo — render it, commit it on the PR branch only if it belongs there, and otherwise keep the description's image pinned to the commit that carried it.

Skip it for a fix with no shape: a one-line guard, a dependency bump, a typo.

0. Blocker rule (applies at every step)

A blocker is a finding whose fix would go against the PR's goal — the code-review principles say the thing the PR sets out to do is wrong (e.g. the PR's whole point is a raw-SQL handler, a new advisory lock, a tuple-returning API, a test that asserts via SQL, dropping bank scoping), or fixing it would mean rewriting/removing the feature rather than polishing it.

On a blocker: stop immediately. Don't push, don't merge, don't partially fix. Tell the user what the PR is trying to do, which principle it conflicts with (quote the code-review section), and the options you see — then ask for confirmation with AskUserQuestion. Resume only on an explicit answer.

Everything else (must fix, should fix, nits) is not a blocker: fix it all.

1. Load the PR

Read the PR — title, body, linked issue, diff — so you know its goal; the blocker rule depends on it. If it's CONFLICTING, rebase onto origin/main first: a conflicting PR gets zero CI runs, silently.

Work out whether the author is a maintainer (write/maintain/admin on the repo, e.g. nicoloboschi).

2. Check out the PR branch

Work in the current worktree — don't create a new worktree or clone. Before switching, note its state (current branch/commit and any uncommitted changes) so you can restore it in step 6; set uncommitted work aside with a WIP commit or a uniquely tagged stash (never a bare git stash — the stash stack is shared across worktrees). Then check out the PR's branch (skip if you're already on it). On current-branch input, ask the user if uncommitted work isn't obviously part of the PR.

  • Maintainer PR: fixes are committed and pushed to this branch — the PR's own head. Never open a separate fix PR.
  • External (fork) PR: push to the fork branch too if maintainers can modify it; otherwise stop and ask the user how to proceed (follow-up PR vs. ask the contributor).

Before every push, make sure the author hasn't pushed meanwhile. If they have, read their new commits and rebase yours onto their head — never force-push over work you haven't read.

3. Review

Read and follow the repo's code-review skill at its absolute path, <repo>/.claude/skills/code-review/SKILL.md (<repo> = git rev-parse --show-toplevel), against the PR's changes (base = origin/<baseRefName>). Collect every finding: must fix, should fix, and nits.

Classify each against step 0. Any blocker → stop and ask.

Show full SKILL.md (486 more words)Show less

4. Apply ALL fixes

  • Fix every finding, not just the must-fixes. Stay in the PR's scope — don't refactor neighbouring code the review didn't flag.
  • Run ./scripts/hooks/lint.sh and the tests covering the touched code (see CLAUDE.md for commands). Regenerate OpenAPI/clients/docs-skill if the change requires it.
  • Loop until clean. One review pass is never enough: fixes introduce new findings, and the review only sees what the last pass changed. So repeat — review → fix everything → review again — until a full code-review pass returns zero findings of any severity (must fix, should fix, nits). Don't stop at "only nits left", don't stop because the last pass found fewer things, and don't declare done on a pass you didn't actually re-run. The only early exit is a blocker (step 0) → stop and ask.
  • Commit with a message that lists what was fixed, then push to the PR branch.

Don't post a review comment on a maintainer's PR — findings go in the chat reply and the commit message. On an external PR, one short comment summarising the fixes you pushed is fine.

5. Wait for CI green

The repo has no required status checks: gh pr merge --auto merges immediately, and gh pr checks reports only the checks registered so far (a lone early Strix check reads as "green"). Gate on the CI workflow run for the pushed head SHA:

bash
SHA=$(gh pr view <N> --json headRefOid --jq .headRefOid)
gh run list --branch <headRefName> --workflow CI --json databaseId,status,conclusion,headSha \
  | jq --arg s "$SHA" 'map(select(.headSha==$s)) | .[0] // empty'

No run yet → keep waiting (give up and report after ~15 min with no run). Once completed, judge per job (gh run view <id> --json jobs): zero failure. If the PR touches the API/engine, test-api (1..3/3), Core LLM tests, and the LLM acceptance matrix must be success, not skipped; for changes outside those paths the change filter skips them legitimately. The oracle-client jobs are known-flaky and may be cancelled — ignore those.

Fork PRs skip test-api and the LLM jobs (no secrets). Run the full suite on an upstream branch before merging — merging to main runs no CI at all:

bash
git push origin HEAD:ci/pr-<N>-verify
gh workflow run CI --ref ci/pr-<N>-verify   # exactly ONCE — a second dispatch cancels the first

A failure caused by the PR/fixes → fix, push, back to step 5. A known flake (check the job log isn't touching the PR's code) → gh run rerun <id> --failed once the run has completed. If CI still fails for reasons you can't attribute, stop and report — don't merge red.

6. Restore the worktree, then merge

First restore the worktree to how you found it: switch back to the original branch/commit and re-apply any work you set aside (undo the WIP commit / apply-then-drop your tagged stash). Do the same if you stop early on a blocker or failure. Restoring first also keeps --delete-branch from trying to check out main, which another worktree may hold.

bash
gh pr merge <N> --squash --delete-branch
git push origin --delete ci/pr-<N>-verify   # if you created it

Report: PR link, the findings fixed (one line each), anything deliberately left, and the CI run that gated the merge.

Note on gh pr edit

It fails on this repo — a GraphQL "Projects (classic)" deprecation aborts it and nothing changes, silently. To edit a description use the REST API instead:

bash
gh api -X PATCH repos/<owner>/<repo>/pulls/<N> -F body=@body.md

© vectorize-io, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/ship-it of vectorize-io/hindsight.

Open the folder on GitHubat commit 9269b88

Compare with similar skills

Ship It next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ship It compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ship It this skillvectorize-io/hindsight46k—~1.9kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Backend Code Reviewlangflow-ai/langflow156k—~3.5kAutomated safety check: NotesMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything85k1 repos~1.4kAutomated safety check: PassMIT
Mole Bug Patternstw93/Mole69k—~2kAutomated safety check: PassGPL-3.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Backend Code Review

    langflow-ai/langflow

    Review backend code for quality, security, maintainability, and best practices based on established checklist rules.

    156k GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.

    69k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Backend Code Review

    langgenius/dify

    Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.

    158k GitHub stars~676 tokensUpdated today
    DevelopmentAuto-check passed

More from vectorize-io/hindsight

All 17 skills in this repo
  • Hindsight Docs

    vectorize-io/hindsight

    Complete Hindsight documentation for AI agents. An agent skill from vectorize-io/hindsight.

    46k GitHub stars~928 tokensUpdated today
    Auto-check passed
  • Create Agent

    vectorize-io/hindsight

    Create a new Hindsight-powered subagent with long-term memory.

    46k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Figure

    vectorize-io/hindsight

    Draw an animated figure (boxes, arrows, moving data) as one self-contained SVG for a GitHub README, PR, issue or blog post.

    46k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Hindsight Local

    vectorize-io/hindsight

    Store user preferences, learnings from tasks, and procedure outcomes.

    46k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Hindsight Memory

    vectorize-io/hindsight

    Long-term memory for the agent via Hindsight. An agent skill from vectorize-io/hindsight.

    46k GitHub stars~688 tokensUpdated today
    Auto-check passed
  • Hs Release

    vectorize-io/hindsight

    Cut a core Hindsight release (vX.Y.Z) and open the changelog + blog PR.

    46k GitHub stars~1.5k tokensUpdated today
    Auto-check: notes

Categories

Questions about Ship It

What does Ship It do?

Take a PR from review to merged — run the repo's code-review skill on it in a loop (review, fix, re-review) until nothing is left to fix, applying ALL fixes on the PR branch, wait for CI green, then…. Ship It is an agent skill from vectorize-io/hindsight. Take a PR from review to merged — run the repo's code-review skill on it in a loop (review, fix, re-review) until nothing is left to fix, applying ALL fixes on the PR branch, wait for CI green, then squash-merge.

When should I use Ship It?

Ship It fits situations like: asked to ship it; tasks that involve Code review.

How do I install Ship It in Claude Code?

Run `npx skills add vectorize-io/hindsight --skill ship-it -a claude-code`. Or copy the skill folder (.claude/skills/ship-it in vectorize-io/hindsight) into .claude/skills/ship-it in your project. Claude Code loads it when a task matches its description.

How do I install Ship It in Codex?

Run `npx skills add vectorize-io/hindsight --skill ship-it -a codex`. Or copy the skill folder (.claude/skills/ship-it in vectorize-io/hindsight) into .agents/skills/ship-it in your project. Codex loads it when a task matches its description.

Can I use Ship It in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vectorize-io/hindsight --skill ship-it -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ship-it, .gemini/skills/ship-it, .github/skills/ship-it and .opencode/skills/ship-it in your project.

What does Ship It need to run?

Going by SKILL.md and its folder, Ship It needs the command-line tools its instructions call (gh, git and jq).

Does Ship It access the network?

SKILL.md names 1 domain. In commands or code: raw.githubusercontent.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Ship It safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ship It use?

Ship It is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ship It use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ship It?

Skills that share tags, products or a category with Ship It: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Backend Code Review (langflow-ai/langflow, 156k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 85k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ship It?

vectorize-io (a GitHub organization) maintains it in vectorize-io/hindsight, which has 46,453 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 7, 2026.

Source: vectorize-io/hindsight on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.