ship-gate

GitHub

将ship评分卡转化为阻塞式质量门禁,通过配置阈值和硬性失败规则(如密钥泄露),在CI或预提交钩子中强制执行代码发布标准。

skills/ship-gate/SKILL.md Houseofmvps/ultraship

Trigger Scenarios

用户希望设置合并门禁 需要CI质量检查 要求预提交保护 强制执行发布就绪状态

Install

npx skills add Houseofmvps/ultraship --skill ship-gate -g -y
More Options

Use without installing

npx skills use Houseofmvps/ultraship@ship-gate

指定 Agent (Claude Code)

npx skills add Houseofmvps/ultraship --skill ship-gate -a claude-code -g -y

安装 repo 全部 skill

npx skills add Houseofmvps/ultraship --all -g -y

预览 repo 内 skill

npx skills add Houseofmvps/ultraship --list

SKILL.md

Frontmatter
{
    "name": "ship-gate",
    "description": "Turn the \/ship scorecard into a blocking, config-as-code quality gate. Sets per-category score thresholds, hard-fails on leaked secrets or critical findings, and wires the gate into a pre-push hook and CI so nothing below the bar merges. Use when the user wants a merge gate, CI quality gate, pre-push check, or to enforce ship-readiness.",
    "allowed-tools": "Bash, Read, Edit, Grep, Glob",
    "argument-hint": "[init|run|ci|hook] [directory]"
}

Ship-Gate — Deterministic Quality Gate

The 2026 consensus on AI-written code is "did it pass the gates," not "did a senior read every line." This skill promotes the /ship scorecard from advisory to a blocking, deterministic gate: same scoring as /ship (shared tools/lib/ship-scoring.mjs), compared against thresholds in .ultraship/ship-gate.json, exiting non-zero so it can fail a push or a CI job.

When to use

The user wants a merge gate, a CI quality check, a pre-push guard, or to enforce a minimum ship-readiness score before code goes out.

Process

Phase 1: Initialize the config

node ${CLAUDE_PLUGIN_ROOT}/tools/ship-gate.mjs init <project-directory>

Writes .ultraship/ship-gate.json:

{
  "thresholds": { "overall": 80, "seo": 70, "a11y": 80, "security": 90, "quality": 70, "bundle": 70 },
  "hardFail": { "onLeakedSecrets": true, "onCriticalFindings": true },
  "skipMissing": true
}
  • thresholds — minimum score (0–100) per category and overall. Below it = fail.
  • hardFail.onLeakedSecrets — any secret finding fails the gate regardless of score.
  • hardFail.onCriticalFindings — any critical-severity finding (any audit) fails the gate.
  • skipMissing — categories that didn't run (e.g. no HTML → SEO/a11y skipped) are ignored rather than failing. Set false to require every category.

Tune thresholds to the project. Sensible starting points: backend API → drop seo/a11y/bundle or rely on skipMissing; marketing site → raise seo/a11y; pre-revenue MVP → lower overall to 70.

Phase 2: Run the gate

node ${CLAUDE_PLUGIN_ROOT}/tools/ship-gate.mjs run <project-directory>
# or, installed: npx ultraship ship-gate .
# machine-readable: ... run <dir> --json

It runs all six auditors (seo, a11y, secrets, code-profiler, deps, bundle), scores them, and prints a PASS/FAIL table with a merge-confidence number (the overall score). Exit 0 = pass, exit 1 = fail.

Phase 3: Explain and fix failures

When the gate fails, report exactly which checks were below the bar, then fix:

  • Score below a category threshold → run that category's fixer: /a11y, /secure, /seo, /profile apply fixes.
  • Leaked secret → remove it, rotate the key, move it to an env var (/secure).
  • Critical finding → resolve it before anything else.

Re-run the gate to confirm it now passes. Never lower a threshold just to pass — fix the issue, or change the threshold only with the user's explicit agreement and a reason.

Phase 4: Enforce it (CI + pre-push)

Wire the gate in so it runs automatically:

# GitHub Actions workflow at .github/workflows/ship-gate.yml
node ${CLAUDE_PLUGIN_ROOT}/tools/ship-gate.mjs ci <project-directory>

# Local git pre-push hook (.git/hooks/pre-push) — blocks a push that fails the gate
node ${CLAUDE_PLUGIN_ROOT}/tools/ship-gate.mjs hook <project-directory>

Tell the user how to bypass the local hook in an emergency: git push --no-verify. The CI gate has no bypass by design.

Key Principles

  • One source of truth. The gate and /ship share the same scoring module — the gate can never disagree with the scorecard.
  • Deterministic. Same input → same verdict. Auditable for SOC2/ISO/HIPAA, unlike an LLM-only "looks fine."
  • Fix, don't dodge. Failing the gate means fixing the code, not weakening the threshold.
  • Never block on a missing tool. A tool that can't run leaves its category skipped (or fails only if skipMissing:false), never crashes the gate.

Version History

  • ed232cb Current 2026-07-24 16:16

Same Skill Collection

skills/a11y/SKILL.md
skills/architecture/SKILL.md
skills/brainstorming/SKILL.md
skills/canary/SKILL.md
skills/clone-patterns/SKILL.md
skills/code-review/SKILL.md
skills/compete/SKILL.md
skills/cost/SKILL.md
skills/demo/SKILL.md
skills/deploy/SKILL.md
skills/dispatching-parallel-agents/SKILL.md
skills/evals/SKILL.md
skills/executing-plans/SKILL.md
skills/finishing-a-development-branch/SKILL.md
skills/frontend-design/SKILL.md
skills/grow/SKILL.md
skills/guard/SKILL.md
skills/index-fix/SKILL.md
skills/investigate/SKILL.md
skills/launch/SKILL.md
skills/learn/SKILL.md
skills/onboard/SKILL.md
skills/pentest/SKILL.md
skills/perf-audit/SKILL.md
skills/receiving-code-review/SKILL.md
skills/release/SKILL.md
skills/requesting-code-review/SKILL.md
skills/rescue/SKILL.md
skills/retro/SKILL.md
skills/revise-claude-md/SKILL.md
skills/security-audit/SKILL.md
skills/seo-audit/SKILL.md
skills/seo-strategy/SKILL.md
skills/sprint/SKILL.md
skills/staying-current/SKILL.md
skills/subagent-driven-development/SKILL.md
skills/systematic-debugging/SKILL.md
skills/test-driven-development/SKILL.md
skills/using-git-worktrees/SKILL.md
skills/using-ultraship/SKILL.md
skills/verification-before-completion/SKILL.md
skills/visual-diff/SKILL.md
skills/writing-plans/SKILL.md
skills/writing-skills/SKILL.md

Metadata

Files
0
Version
ed232cb
Hash
1bc7d37f
Indexed
2026-07-24 16:16

inicio - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-16 22:35
浙ICP备14020137号-1 $mapa de visitantes$