ShipSAFE
CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies
Overview
CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies
7ecfb6c13649OBSERVED · 2026-09-28What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- description: Build, commit, push & version bump workflow - automates the complete release cycle allowed-tools: Read Write Edit Bash Grep Glob --- # Ship Release Systematic release workflow for RTK: build verification, version bump, changelog update, git tag, and push to trigger CI/CD. ## When to Use - **Manual invocation**: When ready to release a new version - **After feature completion**: Before tagging and publishing - **Before version bump**: To automate the release checklist ## Pre-Release Checklist (Auto-Verified) Before running `/ship`, verify: ### 1. Quality Checks Pass ```bash cargo fmt --all --check # Code formatted cargo clippy --all-targets # Zero warnings cargo test --all # All tests pass ``` ### 2. Performance Benchmarks Pass ```bash hyperfine 'target/release/rtk git status' --warmup 3 # Should show <10ms mean time /usr/bin/time -l target/release/rtk git status # Should show <5MB maximum resident set size ``` ### 3. Integration Tests Pass ```bash cargo install --path . --force # Install locally cargo test --ignored # Run integration tests ``` ### 4. Git Clean State ```bash git status # Should show "nothing to commit, working tree clean" ``` ## Release Workflow ### Step 1: Determine Version Bump **Semantic Versioning** (MAJOR.MINOR.PATCH): - **MAJOR** (v1.0.0): Breaking changes (rare for RTK) - **MINOR** (v0.X.0): New features, new filters, new commands - **PATCH** (v0.0.X): Bug fixes, performance improvements **Examples**: - New filter added (`rtk pytest`) → **MINOR** bump (v0.16.0 → v0.17.0) - Bug fix in `git log` filter → **PATCH** bump (v0.16.0 → v0.16.1) - Breaking CLI arg change → **MAJOR** bump (v0.16.0 → v1.0.0) ### Step 2: Update Version **Files to update**: 1. `Cargo.toml` (line 3): `version = "X.Y.Z"` 2. `README.md` (if version mentioned) > **Note**: `CHANGELOG.md` is auto-generated by release-please from conventional commit messages — do not edit manually. **Example**: ```toml # Cargo.toml (before) [package] name = "rtk" version = "0.16.0" # Current version # Cargo.toml (after - MINOR bump) [package] name = "rtk" version = "0.17.0" # New version ``` **CHANGELOG.md template**: ```markdown ## [0.17.0] - 2026-02-15 ### Added - `rtk pytest` command for Python test filtering (90% token reduction) - Support for `pytest` JSON output parsing - Integration with `uv` package manager auto-detection ### Fixed - Shell escaping for PowerShell on Windows - Memory leak in regex pattern caching ### Changed - Updated `cargo test` filter to show test names in failures ``` ### Step 3: Build and Verify ```bash # Clean build cargo clean cargo build --release # Verify binary target/release/rtk --version # Should show new version # Run full quality checks cargo fmt --all --check cargo clippy --all-targets cargo test --all # Benchmark performance hyperfine 'target/release/rtk git status' --warmup 3 # Should still be <10ms ``` ### Step 4: Commit Version Bump ```bash # Stage version files git add Cargo.toml Cargo.lock README.md # Commit with version tag git commit -m "chore(release): bump version to v0.17.0 - Updated Cargo.toml version - Verified all quality checks pass - Benchmarked performance (<10ms startup) Co-Authored-By: Claude Sonnet 4.5 <[email protected]>" ``` ### Step 5: Create Git Tag ```bash # Create annotated tag with changelog excerpt git tag -a v0.17.0 -m "Release v0.17.0 Added: - rtk pytest command (90% token reduction) - Support for uv package manager Fixed: - Shell escaping for PowerShell - Memory leak in regex caching Performance: <10ms startup, <5MB memory" ``` ### Step 6: Push to Remote ```bash # Push commit and tags git push origin main git push origin v0.17.0 # Trigger GitHub Actions release workflow # (CI/CD will build binaries, create GitHub release, publish to crates.io if configured) ``` ## Post-Release Verification After pushing, verify: ### 1. GitHub Actions CI/CD Pass ```bash # Check GitHub Actions workflow status gh run list --limit 1 # Watch latest run gh run watch ``` ### 2. GitHub Release Created ```bash # Check if release created gh release view v0.17.0 # Should show: # - Release notes from git tag # - Binaries attached (macOS, Linux x86_64/ARM64, Windows) # - Checksums for verification ``` ### 3. Installation Verification ```bash # Test installation from release curl -sSL https://github.com/rtk-ai/rtk/releases/download/v0.17.0/rtk-macos-latest -o rtk chmod +x rtk ./rtk --version # Should show v0.17.0 ``` ## Rollback Plan If release has critical issues: ### Option 1: Patch Release (Preferred) ```bash # Fix issue in new branch git checkout -b hotfix/v0.17.1 # Apply fix cargo test --all git commit -m "fix: critical issue in pytest filter" # Release v0.17.1 (PATCH bump) # Follow release workflow above ``` ### Option 2: Yank Release (crates.io only) ```bash # Yank broken version from crates.io cargo yank --vers 0.17.0 # Users can't download yanked version, but existing installs work ``` ### Option 3: Revert Tag (Last Resort) ```bash # Delete tag locally git tag -d v0.17.0 # Delete tag on remote git push origin :refs/tags/v0.17.0 # Delete GitHub release gh release delete v0.17.0 --yes # Revert commit git revert HEAD git push origin main ``` ## Automated Release Script (Optional) Save as `scripts/ship.sh`: ```bash #!/bin/bash set -euo pipefail # Parse version argument if [ $# -ne 1 ]; then echo "Usage: $0 <version>" echo "Example: $0 0.17.0" exit 1 fi NEW_VERSION=$1 echo "🚀 Starting release workflow for v$NEW_VERSION" # 1. Quality checks echo "📦 Running quality checks..." cargo fmt --all --check cargo clippy --all-targets cargo test --all # 2. Update version echo "🔢 Updating version to $NEW_VERSION..." sed -i '' "s/^version = .*/version = \"$NEW_VERSION\"/" Cargo.toml # 3. Build echo "🔨 Building release binary..." cargo build --release # 4. Verify version echo "✅ Verifying version..." target/release/rtk --version | grep "$NEW_VERSION" # 5. Commi
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
Gates applied: no_behavioural_pass.
7ecfb6c13649full audit observations/trust-audit/skill/rtk-ai__ship.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | 7ecfb6c13649 | SAFE | B | 89 | first audit |
Questions
What does the Ship skill do?
CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies
Is Ship safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Ship access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (7ecfb6c13649), read on 2026-09-28. The repository is watched, and a new audit runs when it changes — this is the first audit.