AgentStack
SKILL verified Apache-2.0 Self-run

Ship

skill-urmzd-dotfiles-ship · by urmzd

>

No reviews yet
0 installs
12 views
0.0% view→install

Install

$ agentstack add skill-urmzd-dotfiles-ship

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets Used
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README — it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-urmzd-dotfiles-ship)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
26d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming — see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps — measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Ship? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Ship

Commit, push, and watch the CI pipeline.

Steps

  1. Stage changes: Run git status --porcelain. If there are unstaged/untracked changes, stage them (prefer specific files over git add -A; never stage .env or credential files).
  1. Commit: If a message argument is provided, use it. Otherwise, generate a conventional commit message from the diff (feat:, fix:, chore:, docs:, refactor:, test:). Use the repo's recent git log --oneline -10 to match style.
  1. Push (optional): Only if the user wants to push. Run git push. If no upstream is set, use git push -u origin HEAD. If the user only asked for a commit, stop here and report the commit.
  1. Watch CI (optional): After push, run gh run list --branch $(git branch --show-current) --limit 1 --json databaseId,status,conclusion in a loop (max 5 minutes, poll every 15s). Report the final status.
  1. On failure: If CI fails, run gh run view --log-failed and show the relevant error output so the user can decide next steps.

Rules

  • Never commit files that look like secrets (.env, credentials.json, .pem, .key).
  • Never force push.
  • If there are no changes to commit, say so and stop.
  • If CI isn't set up (no workflows found), just push and report that there's no CI to watch.

Gotchas

  • The gh run is not registered immediately after git push. Poll with retry (a few attempts, a couple seconds apart) before concluding "no run found" -- the run may take several seconds to appear.
  • If git push is rejected by branch protection (protected branch, required reviews, required status checks), stop and report the rejection. Do not retry, force push, or attempt to bypass protection.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.