Install
$ agentstack add skill-epicsagas-epic-harness-ship ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Ship — Ship It
CRITICAL: Run HARNESS_DIR=$(epic-harness path) first. NEVER use .harness/ in the project directory.
Process
Step 0: Prerequisites
Load the spec for PR content:
ls -t $HARNESS_DIR/specs/SPEC-*.md | head -1
Gate: audit must have passed. If no audit report exists, invoke the audit skill before continuing.
Step 1: Pre-ship Verification
1a. Isolated Integration Test Launch an agent with isolation: "worktree" to verify in a clean environment:
- Run full build from scratch (
cargo build --release/npm run build/ etc.) - Run complete test suite
- Run linter and formatter checks
- Verify no uncommitted artifacts
Gate: If isolated test fails → STOP. "Fix with /go, then re-run /audit before shipping."
Step 2: Git Hygiene
- Ensure all changes are committed (Conventional Commits)
- Rebase on latest base branch if needed
- Squash fixup commits if appropriate
Step 3: Create PR
gh pr create --title "" --body "$(cat
## Spec
- Spec ID: SPEC-{timestamp}
- Requirements: R1, R2, ...
## Changes
## Acceptance Criteria Verified
- AC1: ✅
- AC2: ✅
## Audit Report
## Test Plan
- [ ] Unit tests pass
- [ ] Integration tests pass
- [ ] Manual verification done
EOF
)"
Step 4: CI Verification
gh pr checks --watch
If CI fails, diagnose and fix automatically. Retry up to 2 times.
Step 5: Report
## Ship Report
- Spec: SPEC-{timestamp} ({goal_slug})
- PR:
- CI: [PASS/FAIL/N/A]
- Ready to merge: [YES/NO]
- Action needed:
If inside /orbit: Return control to orbit — it will run evolve automatically.
If standalone: Suggest "Run /evolve to analyze this session."
Anti-Rationalization
| Excuse | Rebuttal | What to do instead | |--------|----------|-------------------| | "CI will catch it" | CI doesn't catch everything | Run isolated test locally first | | "The PR description doesn't matter" | It's the permanent record of why | Include spec + audit report | | "I'll merge without CI" | CI is a safety net | Wait for CI, fix failures |
Evidence Required
- [ ] Isolated test passed in clean worktree
- [ ] PR created with spec + audit report in body
- [ ] CI status checked (PASS, FAIL with fix, or N/A)
- [ ] All Conventional Commits applied
Red Flags
- Shipping without a PASS audit report
- PR description that says "various fixes" or "updates"
- Force-pushing to main
- Merging with failing CI
- PR body missing the Audit Report section
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: epicsagas
- Source: epicsagas/epic-harness
- License: Apache-2.0
- Homepage: https://crates.io/crates/epic-harness
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.