codex/skills/ship/SKILL.md
Finalize validated work into a proof-backed pull request without merging, and return immutable SHIP-v1 publication evidence to Actuating without taking architecture, review, or closure authority. Use for $ship, opening or updating a PR, promoting a draft, publishing validation proof, or producing a PR handoff.
npx skillsauth add tkersey/dotfiles shipInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Publish validated work through a concise, non-destructive proof trail. $ship
may create, update, or promote a pull request. It never merges.
Within Actuating, Ship is the sole public-effect owner. SHIP-v1 is external
publication evidence, not a Goal, Counterexample, Construction, Evidence event,
review decision, or closure artifact.
Validated complete work -> ready PR
Incomplete work with an explicit warrant -> draft PR
Use Ship when the user asks to create, update, finalize, or promote a PR, or
when Actuating supplies a current ready-to-ship handoff.
Do not use Ship when implementation is incomplete without explicit early- visibility intent, validation failure lacks an accepted draft warrant, the user wants merge/landing, or no public effect was requested.
ship_input:
source: direct | actuation
repository: owner/name
base:
branch:
sha:
head:
branch:
sha:
existing_pr:
exists:
url:
draft:
validation:
build: pass | fail | missing | not-run
lint: pass | fail | missing | not-run
tests: pass | fail | missing | not-run
language_specific: pass | fail | missing | not-run
acceptance: pass | fail | missing | not-run
task_state:
complete:
blocked:
deferred:
open:
proof_summary:
actuation:
closure_receipt:
schema: actuating-closure-receipt/v1
receipt_id:
goal_contract_ref:
construction_ref:
subject_digest:
evidence_head:
review_contract_digest:
closure_route: final-closeout
verdict: ready-to-ship
cited_premise_refs: []
blockers: []
actuation_binding:
closure_receipt_ref:
goal_contract_ref:
construction_ref:
subject_digest:
evidence_head:
review_contract_digest:
closure_route: final-closeout
user_requested_pr_mode: ready | draft | update-existing | promote-draft | none
repo_policy_pr_mode: ready | draft | unknown
Direct shipping omits actuation. For Actuating input, require the current
owner-supplied readiness receipt, exact published subject, and
closure_route: final-closeout. Reject local-implementation receipts: that
route has no public-effect premise. Ship does not rederive closure, inspect or
revise the Construction, classify findings, count review credit, or choose
Actuating's next action.
Before publication, canonicalize the complete closure_receipt with only
receipt_id replaced by JSON null, recompute its SHA-256 identity, and require
exact equality with receipt_id. Missing or extra receipt fields, including
cited_premise_refs or blockers, block; Ship must not validate a truncated
projection of the receipt.
Actuating supplies this exact publication binding:
actuation_binding.closure_receipt_ref = closure_receipt.receipt_id
actuation_binding.goal_contract_ref = closure_receipt.goal_contract_ref
actuation_binding.construction_ref = closure_receipt.construction_ref
actuation_binding.subject_digest = closure_receipt.subject_digest
actuation_binding.evidence_head = closure_receipt.evidence_head
actuation_binding.review_contract_digest = closure_receipt.review_contract_digest
actuation_binding.closure_route = closure_receipt.closure_route
closure_receipt.closure_route = final-closeout
Ship validates and copies these values verbatim. It never synthesizes, relabels, or revises them.
Keep operation and final state separate:
pr_decision:
operation: create | update | update-and-promote | blocked
final_state: ready | draft | preserve
Default to ready when validation is complete and no task remains blocked,
deferred, or open. Draft requires explicit user intent, incomplete or accepted-
caveat validation, an open task, or repository policy. Actuating input cannot
take the early-draft route because draft publication has no lawful closure
re-entry; conflicting repository policy blocks.
For an existing exact repository/base/head PR, update rather than duplicate it.
Preserve its current ready/draft state unless explicit policy authorizes a
transition. Promotion is update-and-promote: update the proof block first,
then mark ready.
Read pr-readiness-policy.md.
Only replace content between:
<!-- ship-proof:start -->
<!-- ship-proof:end -->
Preserve all human-authored content outside the markers byte-for-byte. Create the marker block when absent. Duplicated, nested, reversed, or unbalanced markers block mutation. Read pr-body-proof.md.
Before any public effect:
pr_decision and build the complete managed proof block.operation.A zero exit status is not publication proof. If mutation succeeds but readback fails, report the partial public effect and block; re-read live state before retrying.
For Actuating input, emit immutable SHIP-v1 after successful readback and
return it to Actuating. Actuating decides how it affects publication currentness
and records the evidence event. Ship never appends Actuating Evidence or
interprets its receipt as architecture, review, or closure authority.
Return the complete canonical SHIP-v1 bytes together with their SHA-256
digest. Actuating retains those immutable bytes as the supporting attachment,
records that digest as publication_observed.receipt_ref, and must dereference
and exact-match the record, readback, and actuation_binding before treating
publication as current.
Follow ship-record.md. actuation_binding is
required for Actuating ready/update/promote records and omitted for direct
shipping. Each SHIP-v1 describes one publication epoch and is immutable.
End with:
Ship Bottom Line:
- Operation:
- Final state:
- PR:
- Head:
- Validation:
- Publication readback:
- SHIP-v1:
- Next owner:
tools
Invokes Apple's macOS 27 fm command-line tool from a local Mac to use the on-device system model or Private Cloud Compute, including instructions, image prompts, schema-constrained JSON, and noninteractive automation. Use when the user asks to run Apple Foundation Models through fm, compare system versus pcc, generate structured output, or automate fm without Swift or an app.
development
Compile historical Codex sessions into governed counterfactual evidence, evaluate an existing owner-applied candidate through blinded paired HCTP trials, and fold observable evidence into RUN, OBSERVE, or STOP. Use for `$hylo`, CRF extraction, counterfactual replay, source-governed direct or historical trials, sealed evidence, paired baseline/candidate evaluation, causal frontiers, or evidence-governed improvement.
testing
Ensure a `ledger` command is available on PATH; materialize, validate, record, replay, and project requested Actuating artifacts without taking semantic or execution authority; coordinate the shared Learnings/Synesthesia/Negative Ledger lifecycle checkpoint and repo-local source-memory reconciliation; address Universalist plans and receipts; and perform pure artifact validation.
testing
Classify and quotient review findings, failing tests, incidents, bug reports, migration failures, and other witnessed falsifiers against accepted intent and the current Construction. Author counterexample-set/v1 without selecting repairs, counting review credit, or granting mutation.