All skills
garrytan avatar

/ship

@96764e8 official
by Garry Tangarrytan/gstack135k stars
20,051

Ship workflow: detect + merge base branch, run tests, review diff, bump VERSION, update CHANGELOG, commit, push, create PR. (gstack)

Use this Skill: https://skilld.dev/gh/garrytan/gstack/ship

This session only. Nothing lands on disk.

sectionsgreptile.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

<!-- AUTO-GENERATED from greptile.md.tmpl — do not edit directly --> <!-- Regenerate: bun run gen:skill-docs -->

Step 10: Address Greptile review comments (if PR exists)

Dispatch a subagent through Agent with subagent_type: "general-purpose" and run_in_background: false, using Step 7's shared foreground-dispatch rule. It fetches and classifies all Greptile comments, including escalation tiers; the parent handles decisions and queues approved fixes.

Subagent prompt:

You are classifying Greptile review comments for a /ship workflow. Read ~/.claude/skills/gstack/review/greptile-triage.md and follow the fetch, filter, classify, and escalation detection steps. Do NOT fix code, do NOT reply to comments, do NOT commit — report only.

For each comment, assign: classification (valid_actionable, already_fixed, false_positive, suppressed), escalation_tier (1 or 2), the file:line or [top-level] tag, body summary, and permalink URL.

Return one JSON object on the LAST LINE: {"status":"complete|no_pr|unavailable","total":N,"comments":[{"classification":"...","escalation_tier":N,"ref":"file:line","summary":"...","permalink":"url"},...],"reason":"..."} Use complete only after a successful fetch, including zero comments; no_pr only after confirming no PR exists; unavailable for gh/API errors or incomplete classification. The latter two return zero total and an empty array. State the failure reason for unavailable; otherwise use an empty reason.

Parent processing:

Parse the LAST line as JSON. Require the declared status, a nonnegative integer total matching the comments array, and the status/reason invariants above. An unknown or missing status is unavailable, never an empty successful review.

For no_pr, record "Greptile: no PR exists"; for complete with zero comments, record "Greptile: fetched, zero comments". Both continue to Step 11.

Unavailable triage: A returned unavailable, failed dispatch, invalid result, or missing completion after ~10 minutes takes this route. Stop a running child and confirm it stopped before continuing. Print Greptile triage did not complete — review the PR comments manually. Include Greptile triage: UNAVAILABLE (dispatch failed) and the actual reason in Step 19's review results; Step 20 has no triage field. Continue to Step 11 without claiming zero comments or completed triage. This optional triage does not block ship.

Otherwise, print: + {total} Greptile comments ({valid_actionable} valid, {already_fixed} already fixed, {false_positive} FP).

For each comment in comments:

VALID & ACTIONABLE: Use AskUserQuestion with:

  • The comment (file:line or [top-level] + body summary + permalink URL)
  • RECOMMENDATION: Choose A because [one-line reason]
  • Options: A) Fix now, B) Acknowledge and ship anyway, C) It's a false positive
  • If user chooses A: queue the approved fix without editing here. After that fix passes review and tests, use the Fix reply template from greptile-triage.md (inline diff + explanation) and save per-project/global greptile-history (type: fix).
  • If user chooses C: reply using the False Positive reply template from greptile-triage.md (include evidence + suggested re-rank), save to both per-project and global greptile-history (type: fp).

VALID BUT ALREADY FIXED: Reply using the Already Fixed reply template from greptile-triage.md — no AskUserQuestion needed:

  • Include what was done and the fixing commit SHA
  • Save to both per-project and global greptile-history (type: already-fixed)

FALSE POSITIVE: Use AskUserQuestion:

  • Show the comment and why you think it's wrong (file:line or [top-level] + body summary + permalink URL)
  • Options:
    • A) Reply to Greptile explaining the false positive (recommended if clearly wrong)
    • B) Fix it anyway (if trivial)
    • C) Ignore silently
  • If user chooses A: reply using the False Positive reply template from greptile-triage.md (include evidence + suggested re-rank), save to both per-project and global greptile-history (type: fp)
  • If user chooses B: queue the approved fix, as above.

SUPPRESSED: Skip silently — these are known false positives from previous triage.

After triage: If fixes were approved, save their approvals and comment references. Run Step 9's full review/fix loop, then return here. Finish the saved replies without asking again about completed fixes, and classify new comments. With no queued fixes, continue to Step 11.


Source: SKILL.md on GitHub

1 alert3d4 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    The 'ship' skill is a highly sophisticated automation workflow for shipping code, including merging, testing, and PR creation. It features robust security mitigations like redaction scans and trust boundaries for subagents. The primary security considerations involve its inherent attack surface for indirect prompt injection—processing untrusted data like PR bodies and plan files—and the use of dynamic execution to generate and run tests at runtime. These are core functionalities for the skill's purpose and are accompanied by safety gates.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer6mo

    1/1 file flagged

Signed by skilld at 96764e8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 16 hours ago.

Activeupdated 2 days ago
What it can do
Runs commands Reads files Edits files Network
preamble-tier
4
version
1.0.0
triggers
[
  "ship it",
  "create a pr",
  "push to main",
  "deploy this"
]
All 9 allowed tools
BashReadWriteEditGrepGlobAgentAskUserQuestionWebSearch

README badge

README badge for garrytan/gstack/ship

Orchestrates a complete release workflow: detects the base branch, merges it, runs tests, reviews the diff, bumps VERSION, updates CHANGELOG, commits, pushes, and creates a pull request. Built on the gstack tool and triggered by phrases like "ship it" or "create a PR".

Generated from the current SKILL.md.

What does this skill do?
The ship skill automates the full release workflow: detect and merge the base branch, run tests, review the diff, bump VERSION, update CHANGELOG, commit, push, and create a PR. Invoke it when code is ready to ship.
When should I invoke this skill instead of pushing manually?
Invoke ship proactively whenever the user says code is ready, asks to deploy, wants to push code up, or requests creating a PR. Do not push or create a PR directly — the skill handles the entire workflow.
What tools and permissions does this skill use?
The skill uses Bash, Read, Write, Edit, Grep, Glob, Agent, AskUserQuestion, and WebSearch. It requires git access and permission to commit, push, and create pull requests.
Does this skill work in plan mode?
Yes. In plan mode, treat the skill file as executable instructions and follow it step-by-step. The first AskUserQuestion call satisfies plan mode's end-of-turn requirement. Do not call ExitPlanMode until the workflow completes.

Generated from the current SKILL.md. These answers refresh after source changes.