Install
$ agentstack add skill-tmusser-ai-engineering-skills-ship-mini ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Ship Mini
Purpose
Decide whether a small project, dashboard, ML workflow, or agent workflow is ready to use.
When to use
Use before user-facing release, scheduled runs, autonomous agent execution, decision-impacting analysis, or sharing outputs with others. Use when an agent will write, send, trigger, or act with tools on your behalf.
Inputs
SPEC.mdVERIFY.md- Changed files
- Test/build/lint results
- Data/model/agent context if relevant
- Allowed tools
- Forbidden tools or actions
- Destructive operations
- Secrets and credentials
- PII or sensitive data access
- Dry-run mode
- Human approval gates
- Audit logging
- Rollback path
- Owner notification
- Stop conditions
Workflow
- Create or update
SHIP.md. - Check user-facing behavior or the scheduled/autonomous action.
- If the run can write, send, or trigger actions, record allowed tools, forbidden tools or actions, destructive operations, secrets and credentials, PII or sensitive data access, dry-run mode, human approval gates, audit logging, rollback path, owner notification, and stop conditions.
- Check test, build, and lint commands.
- Check data freshness if relevant.
- Check row counts, nulls, and metric deltas if relevant.
- Check model artifact/version if relevant.
- Check agent tool permissions if relevant.
- Decide GO or NO-GO.
Outputs
SHIP.md- GO / NO-GO decision
- Blockers
- Accepted risks
- Rollback plan
Stop conditions
- A GO / NO-GO decision is recorded.
- A required approval, dry-run, or rollback path is still unclear.
- A blocker requires more implementation or verification.
Anti-patterns
- Calling something shipped just because the implementation task passed.
- Ignoring data freshness or permissions for automated workflows.
- Shipping without a rollback path.
- Treating autonomous or scheduled runs like interactive sessions.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: tmusser
- Source: tmusser/ai-engineering-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.