- Home
- Skills
- Agents & Orchestration
- ShipGuard — AI Output Quality & Production Readiness Auditor
More screenshots
Works with the AI tools you already use
ShipGuard — AI Output Quality & Production Readiness Auditor
AI coding agents can write code incredibly fast—but fast code is not necessarily working code .
$9.99
ShipGuard — AI Output Quality & Production Readiness Auditor
Example session with this skill installed
I've updated the authentication flow to include MFA. Is this ready to ship to production? Audit the changes.
- Read your context and instructions
- Compiled the shipguard
- Generated the document
SHIPGUARD REPORT: MFA Authentication Flow
Evidence recovered for PR #442. The system detected a React/Node.js stack with Jest and Playwright.
Requirement Traceability Matrix
| Requirement | Implementation | Evidence | Status |
|---|---|---|---|
| TOTP Secret Generation | services/auth.ts:L45 | E2 (Unit Test) | PASS |
| Recovery Code Backup | components/MfaSetup.tsx | E1 (Static) | INSUFFICIENT |
| Rate Limiting on MFA | middleware/rateLimit.ts | E3 (Runtime Logs) | PASS |
| Session Invalidation | api/mfa/verify.ts:L89 | E0 (Claim) | FAIL |
Critical Findings
False Completion: The MfaSetup.tsx component contains a TODO for generating backup codes. The UI displays the button, but the handler is an empty arrow function.
- Requirement Drift: Original spec required SMS fallback; implementation only provides TOTP.
Security Risk: No evidence found that existing sessions are invalidated upon MFA enablement, allowing session hijacking for already-logged-in users.
Evidence Ledger
- E3 (Strong): Observed 429 Too Many Requests response during brute-force simulation on
/api/mfa/verify. - E1 (Weak): Code structure for TOTP generation follows RFC 6238, but no integration test exercises the full flow.
Production Readiness Score
Readiness: 45/100 | Verification Coverage: 60%
Ship Decision
🔴 DO NOT SHIP
Blockers: Missing backup code implementation and session invalidation logic.
Next steps
- Implement the
generateBackupCodeslogic inservices/auth.ts. - Add an integration test in Playwright to verify the full setup-to-login user flow.
- Fix the session invalidation vulnerability in the MFA verification endpoint.
shipguard-ai-output-quality-production-r.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
🛡️ ShipGuard Pro — The Quality Gate for AI-Built Software
Don’t trust “Done.” Verify it.
AI coding agents can write code incredibly fast—but fast code is not necessarily working code. A green build doesn't prove a feature works. Passing tests don't prove requirements were satisfied. And an AI agent saying “completed” doesn't mean your product is ready to ship.
ShipGuard Pro is an evidence-first AI verification skill designed to challenge those assumptions before they become production problems.
🔍 What ShipGuard Pro Does
ShipGuard acts like a skeptical principal engineer + QA lead + security reviewer + release engineer inside your AI coding workflow.
Instead of asking “Does the code look correct?”, it asks:
- ✅ Was the actual requirement satisfied?
- 🧪 Is there real evidence that the feature works?
- 🔎 Are tests actually testing behavior?
- 🚨 Are there hidden security or reliability risks?
- 🧩 Did implementation drift from the original requirement?
- 🎭 Is the AI claiming something is complete when it isn't?
- 🚀 Is this genuinely ready to ship?
⚙️ Powerful Verification Modes
- 🔬 Full Audit — Comprehensive project health and production-readiness review.
- 🎯 Task Verification — Verify whether a specific feature or requirement is actually complete.
- 🚦 Pre-Ship Gate — Get a clear SHIP, WARNINGS, DO NOT SHIP, or INSUFFICIENT EVIDENCE decision.
- 🧠 Claim Verification — Challenge claims such as “fixed,” “tested,” “secure,” or “production-ready.”
- 🔀 PR / Diff Gate — Analyze changed code, impact radius, regressions, and merge risk.
📊 Evidence-Based, Not Guess-Based
ShipGuard uses a graded E0–E5 evidence model to distinguish assertions from actual verification.
E0 = AI assertion
E1 = Static evidence
E2 = Automated verification
E3 = Runtime evidence
E4 = Full user-flow verification
E5 = Requirement + implementation + runtime + tests + edge cases
Missing evidence is never treated as a pass. ShipGuard clearly identifies what is verified, what remains uncertain, and what cannot responsibly be confirmed.
🛠️ What It Audits
Depending on your project, ShipGuard can evaluate:
🔹 Functional correctness 🔹 Regression risks
🔹 Test effectiveness 🔹 Security & secret exposure
🔹 UX & accessibility 🔹 Performance signals
🔹 Reliability & error handling 🔹 Observability
🔹 Dependencies & environment 🔹 Documentation
🔹 Requirement drift 🔹 False-completion patterns
🎯 Get a Real Ship Decision
Every serious audit ends with a practical decision:
🟢 SHIP — Critical paths have adequate evidence.
🟡 SHIP WITH WARNINGS — Residual risks remain but no critical blockers were found.
🔴 DO NOT SHIP — A blocker, critical risk, or major unverified requirement exists.
⚫ INSUFFICIENT EVIDENCE — There isn't enough access or evidence to make a responsible decision.
🤖 Built for AI Coding Workflows
ShipGuard Pro is a portable SKILL.md-based agent skill that can work with compatible AI coding environments such as Claude Code, Cursor, Codex, Grok, Gemini CLI, and other skill-compatible agents.
🚫 No API keys required.
📦 Portable skill package.
🧾 Machine-readable evidence ledger.
📋 Markdown reports with optional interactive HTML dashboards.
🔐 Security-conscious verification model.
🧠 Bounded project learning and self-healing.
🚀 Stop Shipping AI Confidence. Start Shipping Verified Software.
Whether you're building a SaaS, API, dashboard, automation, internal tool, or AI-generated application, ShipGuard Pro gives your AI workflow a critical final question:
“You say it's done. Now prove it.” 🛡️
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
4 people have installed this skill.
Trust & safety
Security scanned
Verified clean 21 days ago
- Passed all security checks, Safe to install