# Ultraship

> "ULTRASHIP" Claude Code plugin — 39 skills, 33 tools, 11 agents for ship-ready workflows: planning, review, pentesting, safety guardrails, canary monitoring, SEO/AI-readiness check, penetration testing, code review, competitive analysis, incident response. 1 dependency. 180 tests. MIT.

- **Type:** MCP server
- **Install:** `agentstack add mcp-houseofmvps-ultraship`
- **Verified:** Pending review
- **Seller:** [Houseofmvps](https://agentstack.voostack.com/s/houseofmvps)
- **Installs:** 0
- **Category:** [Web & Browser](https://agentstack.voostack.com/c/web-and-browser)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [Houseofmvps](https://github.com/Houseofmvps)
- **Source:** https://github.com/Houseofmvps/ultraship
- **Website:** https://www.npmjs.com/package/ultraship

## Install

```sh
agentstack add mcp-houseofmvps-ultraship
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

### Claude Code plugin. 43 expert-level skills for building, shipping, and scaling production software. 37 audit tools (accessibility, vibe-coding security, AI evals, pentest, code quality, bundle size, SEO + AI Readiness check) plus a blocking ship-gate close the loop before deploy. A built-in Currency Guard keeps Claude on current docs, not stale training data.

[](https://www.npmjs.com/package/ultraship)
[](https://www.npmjs.com/package/ultraship)
[](https://www.npmjs.com/package/ultraship)
[](https://github.com/Houseofmvps/ultraship/stargazers)
[](LICENSE)
[](https://github.com/Houseofmvps/ultraship/actions)
[](https://github.com/sponsors/Houseofmvps)

---

[](https://x.com/kaileskkhumar)
[](https://www.linkedin.com/in/kailesk-khumar-soundararajan)
[](https://houseofmvps.com)
[](https://www.kailxlabs.co)

**Built by [Kaileskkhumar](https://www.linkedin.com/in/kailesk-khumar-soundararajan), founder of [HouseofMVPs](https://houseofmvps.com) and [Kailxlabs](https://www.kailxlabs.co)**

---

```
0 dependencies · 274 tests · Node.js ESM · MIT
```

## Install

```bash
# Claude Code plugin
claude plugin marketplace add Houseofmvps/ultraship
claude plugin install ultraship

# Or standalone via npx
npx ultraship ship .
npx ultraship seo .
npx ultraship security .
```

## How It Works

```mermaid
flowchart LR
    U["You type aslash command"] --> S["Skill(markdown instructions)"]
    S --> A["Agent(dispatched worker)"]
    S --> T["Tools(Node.js scripts)"]
    A --> T
    T --> O["JSON Results"]
    O --> R["Scorecard / Report /Actionable Fixes"]

    style U fill:#f59e0b,stroke:#d97706,color:#000
    style S fill:#8b5cf6,stroke:#7c3aed,color:#fff
    style A fill:#3b82f6,stroke:#2563eb,color:#fff
    style T fill:#10b981,stroke:#059669,color:#000
    style R fill:#ef4444,stroke:#dc2626,color:#fff
```

```mermaid
flowchart TD
    subgraph Lifecycle["Full Lifecycle Coverage"]
        direction LR
        I["Idea/brainstorm"] --> B["Build/sprint"]
        B --> AU["Audit/ship /seo /secure"]
        AU --> D["Ship/deploy"]
        D --> L["Launch/launch /compete"]
        L --> G["Grow/grow /cost"]
        G --> RE["Rescue/rescue /canary"]
    end

    style I fill:#8b5cf6,stroke:#7c3aed,color:#fff
    style B fill:#3b82f6,stroke:#2563eb,color:#fff
    style AU fill:#f59e0b,stroke:#d97706,color:#000
    style D fill:#10b981,stroke:#059669,color:#000
    style L fill:#06b6d4,stroke:#0891b2,color:#000
    style G fill:#84cc16,stroke:#65a30d,color:#000
    style RE fill:#ef4444,stroke:#dc2626,color:#fff
```

## What `/ship` Does

`/ship` runs 6 tools in parallel and outputs a scorecard:

```mermaid
flowchart LR
    SHIP["/ship"] --> SEO["seo-scanner63 rules"]
    SHIP --> A11Y["a11y-scannerWCAG 2.2"]
    SHIP --> SEC["secret-scanner+ npm audit"]
    SHIP --> CODE["code-profilerN+1, leaks, ReDoS"]
    SHIP --> BUNDLE["bundle-trackerJS/CSS/images"]
    SHIP --> ENV["env-validator+ migration-checker"]

    SEO --> SC["ScorecardREADY TO SHIP"]
    A11Y --> SC
    SEC --> SC
    CODE --> SC
    BUNDLE --> SC
    ENV --> SC

    style SHIP fill:#f59e0b,stroke:#d97706,color:#000
    style SC fill:#10b981,stroke:#059669,color:#000
    style SEO fill:#3b82f6,stroke:#2563eb,color:#fff
    style SEC fill:#3b82f6,stroke:#2563eb,color:#fff
    style CODE fill:#3b82f6,stroke:#2563eb,color:#fff
    style BUNDLE fill:#3b82f6,stroke:#2563eb,color:#fff
    style ENV fill:#3b82f6,stroke:#2563eb,color:#fff
```

```
+===========================================+
|      U L T R A S H I P   S C O R E       |
+===========================================+
|  SEO + AI Vis.  92/100  ############-    |
|  Security        95/100  ############-    |
|  Code Quality    88/100  ###########--    |
|  Bundle Size     97/100  ############-    |
+===========================================+
|   OVERALL         90/100                  |
|   STATUS          READY TO SHIP           |
+===========================================+
```

Demo

## Tools (40)

Each tool is a standalone Node.js script (`node tools/.mjs`). JSON output. Exit 0 always. No build step.

### Auditing

| Tool | What it checks |
|---|---|
| `seo-scanner` | 63 rules: 39 SEO (meta tags, canonicals, headings, OG tags, structured data, sitemap, cross-page duplicate/orphan detection), 20 GEO (AI bot access in robots.txt, snippet restrictions, llms.txt, structured data for AI extraction), 4 AEO (FAQPage/HowTo/speakable schema) |
| `a11y-scanner` | WCAG 2.2 A/AA static checks: missing alt text, unlabeled form controls, icon-only buttons, missing `lang`/`title`/`main`, heading order, positive tabindex, zoom disabled, duplicate ids, broken aria references. Zero false positives. |
| `ship-gate` | Blocking quality gate — scores all auditors (shared math with `/ship`), compares to `.ultraship/ship-gate.json` thresholds, hard-fails on leaked secrets / critical findings, **exits 1 on fail**. Generates a pre-push hook + GitHub Actions workflow. |
| `secret-scanner` | AWS keys, Stripe keys, JWT secrets, database URLs, private keys. Redacts values in output. |
| `vibe-security-scanner` | Vibe-Coding Security Sentinel — context secret-scanner misses: server-only secrets behind a `NEXT_PUBLIC_`/`VITE_` prefix, a decoded Supabase `service_role` key exposed to the client, service_role in a `"use client"` file, Supabase tables with no RLS. Zero false positives. |
| `eval-scanner` | Locates every LLM call site (Anthropic, OpenAI, Gemini, Mistral, Cohere, Ollama, Vercel AI SDK, LangChain) by provider + model id, detects the test runner and whether an eval suite exists. Flags AI features shipping with no evals. Seeds `/evals`. Zero false positives. |
| `code-profiler` | N+1 queries, sync I/O in handlers, unbounded queries, missing indexes, memory leaks, sequential awaits, ReDoS risk |
| `bundle-tracker` | JS/CSS/image sizes in build output. Detects heavy deps (`moment`→`dayjs`, `lodash`→native). History for before/after. Monorepo-aware. |
| `dep-doctor` | Unused dependencies via import graph analysis (not just grep). Dead wrapper files. Outdated packages. |
| `content-scorer` | Flesch-Kincaid readability, keyword density, thin content detection, GEO heading analysis |
| `lighthouse-runner` | Lighthouse via headless Chrome. Core Web Vitals, render-blocking resources, diagnostics. |

### Validation

| Tool | What it checks |
|---|---|
| `health-check` | HTTP status, response time, SSL certificate (issuer, expiry), 6 security headers |
| `env-validator` | Compares `.env.example` against actual `.env`. Catches missing/empty/placeholder vars. |
| `migration-checker` | Pending DB migrations for Drizzle, Prisma, Knex |
| `og-validator` | Open Graph tags, image reachability, size validation |
| `redirect-checker` | Redirect chains, loops, mixed HTTP/HTTPS. Sitemap-based bulk check. |
| `api-smoke-test` | Hit API endpoints, check status codes, response times, CORS headers |

### Generators

| Tool | What it creates |
|---|---|
| `sitemap-generator` | `sitemap.xml` from HTML files and routes |
| `robots-generator` | AI-friendly `robots.txt` (allows GPTBot, PerplexityBot, ClaudeBot) |
| `llms-txt-generator` | `llms.txt` for AI assistant discoverability |
| `structured-data-generator` | JSON-LD schema markup |

### Competitive & Launch

| Tool | What it does |
|---|---|
| `compete-analyzer` | Compares two URLs: tech stack, SEO score, security headers, response time. ASCII comparison card. |
| `launch-prep` | Reads project, generates PH/Twitter/LinkedIn/HN copy, 14-item checklist, press kit |
| `demo-prep` | Finds console.logs, TODOs, placeholder text, missing favicons. Scores demo readiness. |

### Operations

| Tool | What it does |
|---|---|
| `incident-commander` | Health check + git culprit analysis + error patterns + rollback commands + post-mortem template |
| `growth-tracker` | Uptime, git velocity, SEO trajectory, dep health. Stores snapshots for week-over-week comparison. |
| `cost-tracker` | Log AI token usage per feature/model. Built-in pricing for Claude, GPT-4o, Gemini. Daily trends. |
| `pentest-scanner` | Automated penetration testing: XSS, SQLi, SSTI, command injection, path traversal, CORS, JWT, GraphQL introspection, prototype pollution, race conditions, request smuggling. Zero false positives, every finding has proof-of-concept. |
| `canary-monitor` | Post-deploy canary monitoring: HTTP status, response time, error patterns, baseline regression detection. Auto-saves baselines for future comparison. |
| `retro-analyzer` | Sprint retrospective: git velocity, commit patterns (features vs fixes), test health, hot files, shipping cadence. Generates insights and recommendations. |
| `learnings-manager` | Project learnings CRUD: save, search, list, prune, export. Structured knowledge that compounds across sessions. |

### Project Analysis

| Tool | What it does |
|---|---|
| `onboard-generator` | Auto-generates developer guide: stack, directory tree, routes, schema, env vars, Mermaid diagram |
| `architecture-mapper` | 4 Mermaid diagrams: system overview, route tree, DB ER, data flow. Circular dependency + orphan detection. |
| `pattern-analyzer` | Analyzes testing, error handling, TypeScript usage, CI/CD, git practices. Cross-repo comparison. |
| `audit-history` | Saves/compares audit scores over time |

### Integrations (optional)

| Tool | What it does |
|---|---|
| `gsc-client` | Google Search Console: submit sitemaps, inspect URLs, query rankings (requires `ULTRASHIP_GSC_CREDENTIALS`) |
| `bing-webmaster` | Bing Webmaster: submit sitemaps/URLs, IndexNow instant push, keyword research, backlinks, site-scan, URL inspection (requires `ULTRASHIP_BING_KEY`). Powers ChatGPT Search + Microsoft Copilot. |
| `ga4-client` | Google Analytics 4: overview, top-pages, landing-pages, traffic-sources, conversions, user-journey, devices, realtime, **ai-traffic** (ChatGPT/Perplexity/Copilot tracking), **organic** (search-only). `--organic` flag. |
| `keyword-intelligence` | 12-command keyword engine: analyze, quick-wins, cannibalization, content-gaps, intent-map, trending, high-intent, page-keywords, content-decay, difficulty, **anomalies** (CTR anomalies), **cross-reference** (GSC↔GA4). `--brand` flag for non-brand filtering. |
| `index-doctor` | Index diagnosis: inspect URLs via GSC URL Inspection API, diagnose 15+ coverage states, auto-fix and submit to Bing. |

## Commands (16)

> **Every skill is also a slash command.** Claude Code merged commands into skills, so `/a11y`, `/sprint`, `/pentest`, `/compete`, `/canary`, `/launch`, `/rescue`, `/grow`, `/deploy`, `/learn`, `/guard`, `/retro`, `/investigate`, `/cost`, `/onboard`, `/architecture`, `/clone-patterns`, `/demo`, `/visual-diff`, `/release`, `/seo-strategy` and `/index-fix` all work too — they live in [Skills](#skills-41) above. The commands below are the remaining dedicated command files.

| Command | Description |
|---|---|
| `/ship` | Pre-deploy scorecard. Runs 6 auditors, scores 5 categories |
| `/seo` | SEO audit (63 rules) + AI visibility checks (bot access, snippet restrictions, schema) |
| `/secure` | Secret scanning + OWASP patterns + `npm audit` |
| `/perf` | Lighthouse + bundle size |
| `/review` | Code review with confidence-scored findings |
| `/health` | Production health check |
| `/codex` | Generate a compact codebase index (routes, schema, components, lib) to save AI tokens |
| `/content` | Readability + keyword density analysis |
| `/bundle` | Bundle size tracking |
| `/profile` | Static analysis for backend anti-patterns |
| `/deps` | Unused/outdated dependency detection |
| `/redirects` | Redirect chain/loop detection |
| `/revise-claude-md` | Update CLAUDE.md with session learnings |
| `/brainstorm` | Deprecated alias → use the `brainstorming` skill |
| `/write-plan` | Deprecated alias → use the `writing-plans` skill |
| `/execute-plan` | Deprecated alias → use the `executing-plans` skill |

## Skills (43)

Skills are markdown instruction files that shape Claude's behavior during your session. They activate based on context. When you're debugging, Claude uses the debugging skill. When you're building UI, it uses the frontend design skill.

**Workflow (19):** brainstorming, planning, TDD, implementation, code review, debugging, refactoring, frontend design, API design, data modeling, git workflow, deploy pipeline, release, CLAUDE.md management, verification, browser testing, **sprint pipeline**, **investigation**, **learnings management**

**Specialist (12):** SEO + AI visibility audit, **accessibility audit + auto-fix**, **deterministic ship-gate**, **AI eval harness**, security audit, **penetration testing**, performance audit, content quality, code profiling, parallel agent dispatching, **safety guardrails**, **staying current**

**Growth & Intelligence (12):** competitive analysis, launch prep, incident response, growth tracking, cost tracking, onboarding, architecture mapping, pattern analysis, demo readiness, visual regression, **canary monitoring**, **sprint retrospective**

## Agents (13)

Agents are dispatched by skills to run audits in parallel:

`code-reviewer` · `seo-auditor` · `seo-strategist` · `security-auditor` · `pentest-auditor` · `perf-auditor` · `a11y-auditor` · `browser-verifier` · `compete-analyzer` · `launch-auditor` · `incident-responder` · `growth-tracker` · `canary-monitor`

## MCP Servers (2)

| Server | Purpose |
|---|---|
| [Context7](https://github.com/upstash/context7) | Live library documentation. Fetches current docs for any framework/library. |
| [Playwright](https://github.com/anthropics/anthropic-quickstarts/tree/main/mcp-server-playwright) | Browser automation. Navigate, screenshot, fill forms, test deployed pages. |

Both lazy-start on first use. No background processes.

### Optional MCP integrations (detect-if-present)

Ultraship doesn't bundle these (they need your credentials and would slow every install), but several skills use them automatically *if you've connected them*:

| Connect | Sharpens |
|---|---|
| **Sentry** | `/rescue` pulls live production errors and maps stack traces to code instead of guessing the culprit. `/canary` confirms a post-deploy error spike before recommending rollback. |
| **Vercel** | `/deploy` reads real deployment status, build logs, and which commit is live (not just a single HTTP probe). |
| **Supabase** | `/deploy` verifies migration state against the actual database to catch dashboard-vs-repo drift. |

Add them with `claude mcp add` (or the `/plugin` browser). When connected, the skills detect the tools and use them; when not, they fall back to the built-in static checks.

## Sprint Workflow

Ultraship skills chain into a structured sprint pipeline. Each phase produces artifacts that feed the next.

```mermaid
flowchart LR
    P["/write-planPlan"] --> B["/execute-planBuild"]
    B --> T["TDDTest"]
    T --> R["/review + /secureReview"]
    R --> S["/ship + /deployShip"]
    S --> V["/canaryVerify"]
    V --> RE["/retro + /learnReflect"]

    style P fill:#8b5cf6,stroke:#7c3aed,color:#fff
    style B fill:#3b82f6,stroke:#2563eb,color:#fff
    style T fill:#06b6d4,stroke:#0891b2,color:#000
    style R fill:#f59e0b,stroke:#d97706,color:#000
    style S fill:#10b981,stroke:#059669,color:#000
    style V fill:#84cc16,stroke:#65a30d,color:#000
    style RE fill:#ec4899,stroke:#db2777,color:#fff
```

| Phase | Skill | Output |
|---|---|---|
| Plan | `/write-plan` | Implementation plan with file map and test strategy |
| Build | `/execute-plan` | Working code on a feature branch |
| Test | TDD skill | Passing test suite |
| Review | `/review` + `/secure` | Review report, security scan |
| Ship | `/ship` + `/deploy` | Scorecard + production deploy |
| Verify | `/canary` | Post-deploy health verification |
| Reflect | `/retro` + `/learn` | Retrospective + saved learnings |

Run `/sprint` to follow the full pipeline, or run individual phases as needed.

## Safety Guardrails

`/guard` activates PreToolUse hooks that block destructive commands before they execute:

```me

…

## Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [Houseofmvps](https://github.com/Houseofmvps)
- **Source:** [Houseofmvps/ultraship](https://github.com/Houseofmvps/ultraship)
- **License:** MIT
- **Homepage:** https://www.npmjs.com/package/ultraship

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** yes
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: flagged — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/mcp-houseofmvps-ultraship
- Seller: https://agentstack.voostack.com/s/houseofmvps
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
