Source profileQuality 98/100Review permissions

terrylica/cc-skills/plugins/quality-tools/skills/pre-ship-review/SKILL.md

pre-ship-review

Run a structured quality review before shipping code at any checkpoint such as PRs, releases, or milestones. Use whenever the user says.

Source repository stars
61
Declared platforms
0
Static risk flags
1
Last source update
2026-08-26
Source checked
2026-08-28

Decision brief

What it does: where it fits

Structured quality review before shipping code at any checkpoint: PRs, releases, milestones. Catches the failures that occur at integration boundaries -- where contracts, examples, constants, and tests must all agree.

Best for

  • Pull requests with multiple new modules that wire together
  • Releases combining work from multiple contributors or branches
  • Milestones where quality gates must pass before proceeding

Not for

  • This skill is built on a taxonomy of 9 integration boundary anti-patterns. For the full catalog with examples, detection heuristics, and fix approaches, see Anti-Pattern Catalog.

Compatibility matrix

Platform support, with evidence labels

PlatformStatusEvidenceWhat to check
CodexNot declaredNo explicit evidencePortability before use
Claude CodeNot declaredNo explicit evidencePortability before use
CursorNot declaredNo explicit evidencePortability before use
Gemini CLINot declaredNo explicit evidencePortability before use
Open the compatibility checker

Installation

Inspect first. Install second.

The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

Source-detected install commandSource
npx skills add https://github.com/terrylica/cc-skills --skill "plugins/quality-tools/skills/pre-ship-review"
Safe inspection promptEditorial

Inspect the Agent Skill "pre-ship-review" from https://github.com/terrylica/cc-skills/blob/05f53c5b24a445c1895e9b0590212e66cd70f39e/plugins/quality-tools/skills/pre-ship-review/SKILL.md at commit 05f53c5b24a445c1895e9b0590212e66cd70f39e. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

Workflow

What the source asks the agent to do

  1. 01

    Three-Phase Workflow

    Run static analysis tools on changed files. Skip any tool that is not installed (graceful degradation).

    code-hardcode-audit -- Hardcoded values, magic numbers, leaked secretsdead-code-detector -- Polyglot dead code detection (Python, TypeScript, Rust)pr-gfm-validator -- PR description link validity (if creating a PR)
  2. 02

    Phase 1: External Tool Checks (15s, parallelizable)

    Run static analysis tools on changed files. Skip any tool that is not installed (graceful degradation).

    Run static analysis tools on changed files. Skip any tool that is not installed (graceful degradation).Graceful degradation: If a tool is not installed, log a warning and skip it. Never fail the entire review because one optional tool is missing.For detailed tool procedures, see Automated Checks Reference. For installation instructions, see Tool Install Guide.
  3. 03

    Phase 2: cc-skills Orchestration (30s, subagent-parallelizable)

    Invoke existing cc-skills that complement external tools.

    code-hardcode-audit -- Hardcoded values, magic numbers, leaked secretsdead-code-detector -- Polyglot dead code detection (Python, TypeScript, Rust)pr-gfm-validator -- PR description link validity (if creating a PR)
  4. 04

    Phase 3: Human Judgment Review (Claude-assisted)

    These checks require understanding intent, domain correctness, and architectural fitness. Go through each one manually.

    Does new code in a "core" layer reference names from a "plugin" or "capability" layer?Are there hardcoded lists of feature/plugin names? (Boundary violation)Would adding another instance of this feature type require modifying core code?
  5. 05

    When to Use This Skill

    Use before any significant code shipment:

    Pull requests with multiple new modules that wire togetherReleases combining work from multiple contributors or branchesMilestones where quality gates must pass before proceeding

Permission review

Static risk signals and limitations

Runs scripts

medium · line 79

The documentation asks the agent to run terminal commands or scripts.

git diff --name-only $(git merge-base HEAD main)...HEAD

Evidence record

Why each signal appears

EvidenceSourceComputedTestedEditorial
SignalValueEvidence typeMeaning
Quality score98/100ComputedDocumentation, specificity, maintenance, and trust rules
Repository stars61SourceRepository attention, not individual Skill quality
Compatibility0 platformsSourceDeclared in the catalog source record
Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

Pinned source

Provenance and original SKILL.md

Repository
terrylica/cc-skills
Skill path
plugins/quality-tools/skills/pre-ship-review/SKILL.md
Commit
05f53c5b24a445c1895e9b0590212e66cd70f39e
License
MIT
Collected
2026-08-28
Default branch
main
View the original SKILL.md

Pre-Ship Review

Structured quality review before shipping code at any checkpoint: PRs, releases, milestones. Catches the failures that occur at integration boundaries -- where contracts, examples, constants, and tests must all agree.

Core thesis: AI-generated code excels at isolated components but fails systematically at boundaries between components. This skill systematically checks those boundaries.

Self-Evolving Skill: This skill improves through use. If instructions are wrong, parameters drifted, or a workaround was needed — fix this file immediately, don't defer. Only update for real, reproducible issues.

When to Use This Skill

Use before any significant code shipment:

  • Pull requests with multiple new modules that wire together
  • Releases combining work from multiple contributors or branches
  • Milestones where quality gates must pass before proceeding
  • Any checkpoint where code with examples, constants across files, or interface extensions needs validation

NOT needed for: single-file cosmetic changes, documentation-only updates, dependency bumps.


TodoWrite Task Templates

MANDATORY: Select and load the appropriate template before starting review.

Template A: New Feature Ship

1. Detect changed files and scope (git diff --name-only against base branch)
2. Run Phase 1 - External tool checks (Pyright, Vulture, import-linter, deptry, Semgrep, Griffe)
3. Run Phase 2 - cc-skills orchestration (code-hardcode-audit, dead-code-detector, pr-gfm-validator)
4. Run Phase 2 conditional checks based on file types changed
5. Phase 3 - Verify every function parameter has at least one caller passing it by name
6. Phase 3 - Verify every config/example parameter maps to an actual function kwarg
7. Phase 3 - Check for architecture boundary violations (hardcoded feature lists, cross-layer coupling)
8. Phase 3 - Verify domain constants and formulas are correct (cross-reference cited sources)
9. Phase 3 - Audit test quality - do tests test what they claim (not side effects)?
10. Phase 3 - Check for implicit dependencies between new components
11. Phase 3 - Look for O(n^2) patterns where O(n) suffices
12. Phase 3 - Verify error messages give actionable guidance
13. Phase 3 - Confirm examples reflect actual behavior, not aspirational behavior
14. Compile findings report with severity and suggested fixes

Template B: Bug Fix Ship

1. Verify the fix addresses root cause, not symptom
2. Verify the fix does not mask information flow
3. Check that new test reproduces the original bug (fails without fix)
4. Run Phase 1 - External tool checks on changed files
5. Run Phase 2 - cc-skills checks on changed files
6. Verify constants consistency if any values changed
7. Compile findings report

Template C: Refactoring Ship

1. Verify all callers updated to match new signatures
2. Run Phase 1 - External tool checks (especially Griffe for API drift)
3. Run Phase 2 - cc-skills checks (especially dead-code-detector)
4. Verify examples/docs updated to match new parameter names
5. Verify no dead imports from removed features
6. Check for introduced cross-boundary coupling
7. Compile findings report

Three-Phase Workflow

Phase 1: External Tool Checks (~15s, parallelizable)

Run static analysis tools on changed files. Skip any tool that is not installed (graceful degradation).

Detect scope:
  git diff --name-only $(git merge-base HEAD main)...HEAD

Run in parallel:
  pyright --outputjson <changed_py_files>          # Type contracts
  vulture <changed_py_files> --min-confidence 80   # Dead code / YAGNI
  lint-imports                                      # Architecture boundaries
  deptry .                                          # Dependency hygiene
  semgrep --config .semgrep/ <changed_files>        # Custom pattern rules
  griffe check --against main <package>             # API signature drift

What each tool catches:

ToolAnti-PatternInstall
Pyright (strict)Interface contracts, return types, cross-file type errorspip install pyright
VultureDead code, unused constants/imports (YAGNI)pip install vulture
import-linterArchitecture boundary violations, forbidden importspip install import-linter
deptryUnused/missing/transitive dependenciespip install deptry
SemgrepNon-determinism, silent param absorption, banned patternsbrew install semgrep
GriffeBreaking API changes, signature drift vs base branchpip install griffe

Graceful degradation: If a tool is not installed, log a warning and skip it. Never fail the entire review because one optional tool is missing.

For detailed tool procedures, see Automated Checks Reference. For installation instructions, see Tool Install Guide.

Phase 2: cc-skills Orchestration (~30s, subagent-parallelizable)

Invoke existing cc-skills that complement external tools.

Always run:

  • code-hardcode-audit -- Hardcoded values, magic numbers, leaked secrets
  • dead-code-detector -- Polyglot dead code detection (Python, TypeScript, Rust)
  • pr-gfm-validator -- PR description link validity (if creating a PR)

Run conditionally based on changed file types:

ConditionSkill to invoke
Python files changedimpl-standards (error handling, constants, logging)
500+ lines changedcode-clone-assistant (duplicate code detection)
Plugin/hook files changedplugin-validator (structure, silent failures)
Markdown/docs changedlink-validation (broken links, path policy)

Phase 3: Human Judgment Review (Claude-assisted)

These checks require understanding intent, domain correctness, and architectural fitness. Go through each one manually.

Check 1: Architecture Boundaries

  • Does new code in a "core" layer reference names from a "plugin" or "capability" layer?
  • Are there hardcoded lists of feature/plugin names? (Boundary violation)
  • Would adding another instance of this feature type require modifying core code?

Check 2: Domain Correctness

  • Are mathematical formulas correct? Cross-reference with cited papers.
  • Are constants labeled correctly? (e.g., a "daily" constant should use the daily value)
  • Do units and time periods match? (annual vs daily rates, quarterly vs monthly lambdas)

Check 3: Test Quality

  • Does each test exercise the specific function it claims to test?
  • Or does it test a side-effect? (Function A tests function B which internally calls A)
  • Are edge cases covered? (Empty input, NaN, single element, division by zero)

Check 4: Dependency Transparency

  • If component A requires component B to run first, is this documented?
  • Are ordering requirements explicit in interfaces, not just in examples?

Check 5: Performance

  • Any nested loops over the same data? (Potential O(n^2))
  • Any expanding-window operations that could be rolling or full-sample?
  • Any per-element operations that could be vectorized?

Check 6: Error Message Quality

  • Do errors tell users what to DO, not just what went wrong?
  • Do validation errors reference the specific parameter/value that failed?

Check 7: Example Accuracy

  • Do examples demonstrate features that actually work in the code?
  • Are there parameters in examples that get silently absorbed by **kwargs or **_?

For detailed check procedures, see Judgment Checks Reference.


Universal Pre-Ship Checklist

Phase 1 (Tools):
- [ ] Pyright strict passes on changed files (no type errors)
- [ ] Vulture finds no unused code in new files (or allowlisted)
- [ ] import-linter passes (no architecture boundary violations)
- [ ] deptry passes (no unused/missing dependencies)
- [ ] Semgrep custom rules pass (no non-determinism, no silent param absorption)
- [ ] Griffe shows no unintended API breaking changes vs base branch

Phase 2 (cc-skills):
- [ ] code-hardcode-audit passes (no magic numbers or secrets)
- [ ] dead-code-detector passes (no unused code)
- [ ] PR description links valid (pr-gfm-validator)

Phase 3 (Judgment):
- [ ] No new cross-boundary coupling introduced
- [ ] Domain constants and formulas are mathematically correct
- [ ] Tests actually test what they claim (not side effects)
- [ ] Implicit dependencies between components are documented
- [ ] No O(n^2) where O(n) suffices
- [ ] Error messages give actionable guidance
- [ ] Examples reflect actual behavior, not aspirational behavior

Anti-Pattern Catalog

This skill is built on a taxonomy of 9 integration boundary anti-patterns. For the full catalog with examples, detection heuristics, and fix approaches, see Anti-Pattern Catalog.

#Anti-PatternDetection Method
1Interface contract violationPyright + Griffe + manual trace
2Misleading examplesSemgrep + manual config-to-code comparison
3Architecture boundary violationimport-linter + manual review
4Incorrect domain constantsSemgrep + domain expertise
5Testing gapsmutmut + manual test audit
6Non-determinismSemgrep custom rules
7YAGNIVulture + dead-code-detector
8Hidden dependenciesManual dependency trace
9Performance anti-patternsManual complexity analysis

Post-Change Checklist

After modifying THIS skill:

  • Anti-pattern catalog reflects real-world findings
  • Tool install guide has current versions and commands
  • TodoWrite templates cover the three ship types
  • Universal checklist is complete and non-redundant
  • All references/ links resolve correctly
  • Append changes to references/evolution-log.md

Troubleshooting

IssueCauseSolution
Tool not foundExternal tool not installedInstall per tool-install-guide.md or skip (graceful degradation)
Too many Vulture false positivesFramework entry points look unusedCreate allowlist: vulture --make-whitelist > whitelist.py
Semgrep too slowLarge codebase scanScope to changed files only: semgrep --include=<changed>
import-linter has no contractsProject not configuredAdd [importlinter] section to pyproject.toml
Griffe reports false breaking changesIntentional API changeUse griffe check --against main --allow-breaking
Phase 3 finds nothing but reviewer finds issuesNew anti-pattern categoryAdd to catalog and evolution-log.md
cc-skill not triggeringSkill not installed in marketplaceVerify with /plugin list

Reference Documentation

For detailed information, see:

Post-Execution Reflection

After this skill completes, reflect before closing the task:

  1. Locate yourself. — Find this SKILL.md's canonical path (Glob for this skill's name) before editing. All corrections target THIS file and its sibling references/ — never other documentation.
  2. What failed? — Fix the instruction that caused it. If it could recur, add it as an anti-pattern.
  3. What worked better than expected? — Promote it to recommended practice. Document why.
  4. What drifted? — Any script, reference, or external dependency that no longer matches reality gets fixed now.
  5. Log it. — Every change gets an evolution-log entry with trigger, fix, and evidence.

Do NOT defer. The next invocation inherits whatever you leave behind.



Frequently asked questions

What to verify before installation and use

What does the pre-ship-review source document cover?

Structured quality review before shipping code at any checkpoint: PRs, releases, milestones. Catches the failures that occur at integration boundaries -- where contracts, examples, constants, and tests must all agree.

How do I install pre-ship-review?

The source record exposes this install command: npx skills add https://github.com/terrylica/cc-skills --skill "plugins/quality-tools/skills/pre-ship-review". Inspect the command and pinned source before running it.

Which permission-related actions were detected?

Static rules flagged exec-script in the source; the page lists the matching lines and excerpts.

Alternatives

Compare before choosing

Computed 100147

oaustegard/claude-skills

featuring

Generate hierarchical _FEATURES.md files that describe what a codebase DOES from a user/consumer perspective, anchored to source symbols via tree-sitting. Supports large complex codebases through feature-driven decomposition into sub-feature files. Uses a multi-pass synthesis: orientation → detail → overview rewrite. Use when someone says "what does this do", "document features", "feature inventory", "_FEATURES.md", or needs to understand a codebase's purpose before modifying it. Complements tre

Computed 10017

dancingteeth/unified-code-review

unified-code-review

Risk-first code review for PRs and branch audits: blast-radius triage, agent-authored discipline (tests first, intent evidence), call-graph pincer for integration defects between modules, then structural code-judo bar. Use when reviewing PRs, auditing agent-written diffs, catching rubber-stamp green CI, or wiring bugs single-file review misses. Prefer over structure-only thermo-nuclear review alone. Do not use for unrelated coding tasks or as an always-on rule.

Computed 9970

PaulRBerg/agent-skills

skill-writing

Create/scaffold/init a project-local agent skill under `.agents/skills` in an ordinary repository; defer to repository instructions that define a source catalog and lifecycle.

Computed 9916

NintendaDev/unikit-ai

unikit-docs

Generate and maintain the project's TECHNICAL documentation from its codebase — scans the project structure, tech stack, and module boundaries, then writes a lean README landing page plus detailed topic pages (architecture, modules, setup, build, APIs), only the docs that are relevant. Use whenever the user wants to create, update, or validate documentation of the CODE or the project itself, e.g. "generate documentation", "create docs", "write the README", "update the project docs", "document th