Skip to content
ship-code logo

Ship Code

ship-code

Reviews code, tests, documentation, and configuration against 20 production-grade quality rules. Checks error handling, security boundaries, test validity, architecture, documentation clarity, naming conventions, and code structure. Use when writing code, reviewing code, fixing bugs, refactoring,...

Honkware/ship-code0installs0stars

SKILL.md

Full skill instructions

ship-code

Code quality reviewer. 20 rules across 7 categories. Checks code before it ships.

When to Apply

Apply this skill when:

  • Writing or editing code, tests, documentation, or configuration
  • Reviewing code (your own or someone else's, including AI-generated)
  • Fixing bugs or refactoring existing code
  • Adding features to a codebase
  • Writing tests, READMEs, API docs, or inline comments
  • Handling secrets, credentials, or environment configuration
  • Validating external inputs
  • Choosing or installing dependencies
  • Naming variables, functions, classes, or files
  • Structuring or reorganizing a project

Also applies when the user mentions:

  • Code review, quality, or standards
  • AI-generated code, vibe coding, or Copilot output
  • Clean code, production readiness, or maintainability
  • Security review or input validation

Instructions

  1. Read the relevant rule files based on the task:

    • Error handling issues → rules/​error-*.md
    • Security or dependency issues → rules/​sec-*.md
    • Testing issues → rules/​test-*.md
    • Architecture or structure issues → rules/​arch-*.md or rules/​struct-*.md
    • Documentation issues → rules/​doc-*.md
    • Naming issues → rules/​name-*.md
  2. For each rule, compare the user's code against the ❌ and ✓ examples.

  3. Flag violations with:

    • The rule prefix (e.g., error-fail-fast)
    • A one-line explanation of the problem
    • A concrete fix following the ✓ example pattern
  4. Prioritize by severity:

    • CRITICAL (error-, sec-, test-): Must fix before shipping
    • HIGH (arch-, doc-): Should fix before merging
    • MEDIUM (name-, struct-): Fix when touching nearby code
  5. After reviewing, suggest 1-3 specific refactors with the biggest impact.

Rules

CRITICAL: Error Handling & Resilience

RuleChecks
error-fail-fastExplicit errors returned, not swallowed into defaults
error-no-empty-catchEvery catch block does real work, no log-and-continue
error-calibrated-defenseExpectable errors handled, preventable errors crash

CRITICAL: Security & Dependencies

RuleChecks
sec-env-for-secretsSecrets in env vars, validated at startup
sec-validate-inputsEvery external input sanitized at boundaries
sec-verify-depsDependencies verified, stdlib preferred, versions pinned

CRITICAL: Testing & Verification

RuleChecks
test-behavior-not-coverageTests verify business logic, not just execute code
test-edge-casesBoundaries tested: empty, null, zero, max, wrong types

HIGH: Architecture & Abstraction

RuleChecks
arch-match-complexitySolution complexity matches problem complexity
arch-boundariesBusiness logic separate from I/​O, thin HTTP adapters
arch-no-duplicationOne canonical implementation, no copy-paste
arch-refactor-as-you-goComplexity consolidated every 2-3 features

HIGH: Documentation & Communication

RuleChecks
doc-why-not-whatComments explain decisions, not code mechanics
doc-de-aiConcrete specifics, no mood words or filler
doc-readme-testedREADMEs with tested steps, troubleshooting, known issues

MEDIUM: Naming & Readability

RuleChecks
name-reveals-intentNames answer why something exists
name-consistent-vocabularyOne name per concept across codebase

MEDIUM: Code Structure

RuleChecks
struct-single-purposeOne function, one job
struct-prefer-immutableNew state returned, not shared mutation
struct-domain-structureFolders organized by business domain

Output Format

Report findings as:

[SEVERITY] rule-prefix: one-line problem description
  Fix: concrete correction

Example:

[CRITICAL] error-no-empty-catch: catch block logs but continues execution
  Fix: handle PaymentDeclined specifically, re-throw unexpected errors
[HIGH] arch-no-duplication: input validation copied in 3 endpoints
  Fix: extract into require_fields() utility, use everywhere
[MEDIUM] name-reveals-intent: variable 'data' doesn't indicate content type
  Fix: pending_orders = order_repo.fetch_pending()

Examples

Example 1: Reviewing a route handler

User submits:

app.get("/​report", async (req, res) => {
  const user = await db.query("SELECT * FROM users WHERE id = ?", [req.session.userId]);
  if (!user.isAdmin && req.query.scope === "all") return res.status(403).json({error: "no"});
  const data = await db.query("SELECT * FROM reports WHERE scope = ?", [req.query.scope]);
  res.json(data);
});

Review output:

[CRITICAL] sec-validate-inputs: req.query.scope interpolated directly into SQL
  Fix: use parameterized queries or an ORM. Validate scope against allowed values.
[HIGH] arch-boundaries: business logic (admin check, query building) mixed with HTTP handler
  Fix: move admin check and report generation to a service function. Keep route thin.
[MEDIUM] name-reveals-intent: 'data' is generic
  Fix: reports = await report_service.generate(scope, current_user)

Example 2: Reviewing a README

User submits a README with: "A comprehensive, robust solution for modern web development."

Review output:

[HIGH] doc-de-ai: "comprehensive" and "robust" are AI tells without specifics
  Fix: "Payment webhook processor. Handles 5k Stripe events/​min at peak."
[HIGH] doc-readme-tested: no troubleshooting section, no tested setup steps
  Fix: add Prerequisites, install commands, and a troubleshooting table

Rule Files

Full rules with code examples:

rules/​error-fail-fast.md
rules/​error-no-empty-catch.md
rules/​error-calibrated-defense.md
rules/​sec-env-for-secrets.md
rules/​sec-validate-inputs.md
rules/​sec-verify-deps.md
rules/​test-behavior-not-coverage.md
rules/​test-edge-cases.md
rules/​arch-match-complexity.md
rules/​arch-boundaries.md
rules/​arch-no-duplication.md
rules/​arch-refactor-as-you-go.md
rules/​doc-why-not-what.md
rules/​doc-de-ai.md
rules/​doc-readme-tested.md
rules/​name-reveals-intent.md
rules/​name-consistent-vocabulary.md
rules/​struct-single-purpose.md
rules/​struct-prefer-immutable.md
rules/​struct-domain-structure.md

Full Compiled Document

All rules expanded with examples: AGENTS.md