SKILL: Ship-Safe Audit
SkillSecurityRun ship-safe security and quality audit on the current project. Executes npx ship-safe audit . and reports findings by severity. Use before shipping any feature or PR.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the SKILL: Ship-Safe Audit skill
What this skill tells your AI
The instructions your AI receives, as published by kinncj/heimdall in .claude/skills/ship-safe/SKILL.md and read by ahel’s review.
What It Does
Runs ship-safe — a pre-ship security and quality scanner that checks for secrets, vulnerabilities, and risky patterns before code reaches production.
Usage
npx ship-safe audit .
Run from the project root. No install required (npx fetches it on demand).
Opt-In
Ship-safe is disabled by default. To enable it:
- CI/CD: set the repository variable
ENABLE_SHIP_SAFE=truein GitHub → Settings → Variables - Agents / local: set env var
ENABLE_SHIP_SAFE=truebefore invoking/ship-safe
When to Use
Only run if ENABLE_SHIP_SAFE=true is set. When enabled, appropriate moments are:
- Before opening a PR
- After adding new dependencies
- Before merging any feature branch to main
- After touching auth, secrets handling, or infra config
Output Interpretation
| Symbol / keyword | Severity | Action |
|---|---|---|
✓ PASS / ok / no issues | Clean | Safe to ship |
⚠ WARN / MEDIUM / LOW | Advisory | Review before shipping |
✗ FAIL / ERROR / CRITICAL / HIGH | Blocker | Must fix before shipping |
Agent Instructions
- Run
npx ship-safe audit .from the repo root. - Parse stdout for CRITICAL/HIGH findings — these are blockers.
- For each blocker: report the file, line, and finding description.
- For MEDIUM/LOW: report as advisory, do not block.
- If all checks pass: confirm "ship-safe: clean" and proceed.
- If blockers found: halt the task, report findings to Orchestrator.
Example Integration (architect / pre-ship checklist)
/ship-safe
The skill runs the audit, colors findings by severity, and surfaces blockers before any merge action.
Signals
- GitHub stars
- 66
- Forks
- 4
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
ship-safe- Source
- github.com/kinncj/heimdall