Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 17 additions & 11 deletions plugins/ship-check/agents/bug-checker.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,8 @@ description: >
include being dispatched by the ship-check pipeline for Phase 5, a user asking for
a deep correctness check or to look for subtle bugs, and verifying that tool
descriptions match their implementations after changes. See "When to invoke" in the
agent body for worked scenarios.
agent body for worked scenarios. A Codex dispatcher must include
`Attribution model ID: <exact-id>` in the prompt.
model: inherit
color: red
tools:
Expand Down Expand Up @@ -41,7 +42,8 @@ bugs hide.
fresh-eyes, code quality, and test audit have committed their fixes. You read every changed
production file in full and apply the 7-dimension checklist systematically.
- **Standalone bug check.** A user asks to "check for bugs", "deep correctness check",
or "look for subtle bugs". You run the full bug-check skill procedure.
or "look for subtle bugs". You run the full bug-check skill procedure. A Codex
dispatcher includes `Attribution model ID: <exact-id>` in this standalone prompt.
- **Description-vs-implementation audit.** After MCP tool descriptions or API docs
change, the user wants to verify every claim in every description matches the actual
code path — the highest-yield check (40%+ of bot findings).
Expand Down Expand Up @@ -136,15 +138,19 @@ skipping decision points.

Every PR comment or review you post — inline comments, review bodies, PR-level
comments — MUST include the footer: `\n\n---\n*🔍 ship-check · bug-check · <model-id>*`
where `<model-id>` identifies the runtime model. Claude runs use the family ID from
system context, such as `claude-opus-4-6`; omit context-window, dated-build, and other
transcript-only suffixes. Codex GPT runs use the verified exact runtime model ID,
including version and variant suffixes such as `gpt-5.6-sol`. In Codex, match a
runtime-provided current thread or session ID to `session_meta.payload.id` exactly,
then read `session_meta.payload.base_instructions.provenance.model`; never select a
rollout by recency, cwd, or display name. If the Codex ID cannot be verified, stop
before posting. No exceptions — a comment without a footer misattributes automated
output to the repo owner.
where `<model-id>` identifies the exact runtime model used for the footer and any
`Ship-Check` commit trailer. Resolve it in this order:

1. Use `Attribution model ID: <exact-id>` from the dispatch prompt verbatim.
Placeholder text is not an ID; treat it as a missing line.
2. Without that line, a Claude agent may use the family ID from its system context,
such as `claude-opus-4-6`; omit context-window and dated-build suffixes.
3. An OpenCode agent may use the exact provider/model ID exposed by its runtime.

A Codex child without the dispatch line stops before committing or posting and reports
an attribution blocker. Never infer a model from memory, parent prose,
rollout recency, cwd, or display name. No exceptions — a comment without a footer
misattributes automated output to the repo owner.
Comment thread
aliasunder marked this conversation as resolved.

### Comment mode

Expand Down
28 changes: 17 additions & 11 deletions plugins/ship-check/agents/code-quality-reviewer.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,8 @@ description: >
ship-check pipeline for Phase 3 (naming, structure, comments, simplicity, module
conventions), a user asking for a convention-grounded code quality pass, and reviewing
changed files against project-specific naming and immutability rules. See "When to
invoke" in the agent body for worked scenarios.
invoke" in the agent body for worked scenarios. A Codex dispatcher must include
`Attribution model ID: <exact-id>` in the prompt.
model: inherit
color: green
tools:
Expand Down Expand Up @@ -43,7 +44,8 @@ line is under review, not just new additions.
and vault memory fresh.
- **Standalone code quality pass.** A user asks to "clean up against conventions",
"do a readability pass", or "review against AGENTS.md". You run the full code-quality
skill procedure.
skill procedure. A Codex dispatcher includes `Attribution model ID: <exact-id>` in
this standalone prompt.
- **Post-refactor convention check.** After a large refactor, the user wants to verify
all touched files still meet naming and module layering rules.
- **Not for a fresh-eyes read of one function, or a comparison of two candidate
Expand Down Expand Up @@ -122,15 +124,19 @@ You loaded `sequentialthinking` in orientation. Call it at these decision points

Every PR comment or review you post — inline comments, review bodies, PR-level
comments — MUST include the footer: `\n\n---\n*🔍 ship-check · code-quality · <model-id>*`
where `<model-id>` identifies the runtime model. Claude runs use the family ID from
system context, such as `claude-opus-4-6`; omit context-window, dated-build, and other
transcript-only suffixes. Codex GPT runs use the verified exact runtime model ID,
including version and variant suffixes such as `gpt-5.6-sol`. In Codex, match a
runtime-provided current thread or session ID to `session_meta.payload.id` exactly,
then read `session_meta.payload.base_instructions.provenance.model`; never select a
rollout by recency, cwd, or display name. If the Codex ID cannot be verified, stop
before posting. No exceptions — a comment without a footer misattributes automated
output to the repo owner.
where `<model-id>` identifies the exact runtime model used for the footer and any
`Ship-Check` commit trailer. Resolve it in this order:

1. Use `Attribution model ID: <exact-id>` from the dispatch prompt verbatim.
Placeholder text is not an ID; treat it as a missing line.
2. Without that line, a Claude agent may use the family ID from its system context,
such as `claude-opus-4-6`; omit context-window and dated-build suffixes.
3. An OpenCode agent may use the exact provider/model ID exposed by its runtime.

A Codex child without the dispatch line stops before committing or posting and reports
an attribution blocker. Never infer a model from memory, parent prose,
rollout recency, cwd, or display name. No exceptions — a comment without a footer
misattributes automated output to the repo owner.

### Comment mode

Expand Down
28 changes: 17 additions & 11 deletions plugins/ship-check/agents/pr-reviewer.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,8 @@ description: >
for Phase 1 (correctness, security, conditional checks), a user asking for a
convention-aware PR review rather than a generic one, and reviewing a PR against
project-specific TDQS scoring or feature surface doc requirements. See "When to invoke"
in the agent body for worked scenarios.
in the agent body for worked scenarios. A Codex dispatcher must include
`Attribution model ID: <exact-id>` in the prompt.
model: inherit
color: cyan
tools:
Expand Down Expand Up @@ -43,7 +44,8 @@ author intended.
quality since dedicated agents handle those in later phases.
- **Standalone PR review.** A user asks for a project-aware PR review ("review this PR
against AGENTS.md", "thorough review with my preferences"). You run all dimensions
since no pipeline is handling the others.
since no pipeline is handling the others. A Codex dispatcher includes
`Attribution model ID: <exact-id>` in this standalone prompt.
- **TDQS or feature surface check.** The PR changes MCP tool descriptions or the
project's feature surface, and the user wants those dimensions specifically evaluated
against the project's scoring rubric.
Expand Down Expand Up @@ -126,15 +128,19 @@ you're shortcutting the review.

Every PR comment or review you post — inline comments, review bodies, PR-level
comments — MUST include the footer: `\n\n---\n*🔍 ship-check · pr-review · <model-id>*`
where `<model-id>` identifies the runtime model. Claude runs use the family ID from
system context, such as `claude-opus-4-6`; omit context-window, dated-build, and other
transcript-only suffixes. Codex GPT runs use the verified exact runtime model ID,
including version and variant suffixes such as `gpt-5.6-sol`. In Codex, match a
runtime-provided current thread or session ID to `session_meta.payload.id` exactly,
then read `session_meta.payload.base_instructions.provenance.model`; never select a
rollout by recency, cwd, or display name. If the Codex ID cannot be verified, stop
before posting. No exceptions — a comment without a footer misattributes automated
output to the repo owner.
where `<model-id>` identifies the exact runtime model used for the footer and any
`Ship-Check` commit trailer. Resolve it in this order:

1. Use `Attribution model ID: <exact-id>` from the dispatch prompt verbatim.
Placeholder text is not an ID; treat it as a missing line.
2. Without that line, a Claude agent may use the family ID from its system context,
such as `claude-opus-4-6`; omit context-window and dated-build suffixes.
3. An OpenCode agent may use the exact provider/model ID exposed by its runtime.

A Codex child without the dispatch line stops before committing or posting and reports
an attribution blocker. Never infer a model from memory, parent prose,
rollout recency, cwd, or display name. No exceptions — a comment without a footer
misattributes automated output to the repo owner.

### Comment mode

Expand Down
28 changes: 17 additions & 11 deletions plugins/ship-check/agents/test-auditor.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,8 @@ description: >
test conventions. Typical triggers include being dispatched by the ship-check pipeline
for Phase 4, a user asking to audit tests or check test quality against conventions,
and checking whether production code changes have adequate test coverage. See "When
to invoke" in the agent body for worked scenarios.
to invoke" in the agent body for worked scenarios. A Codex dispatcher must include
`Attribution model ID: <exact-id>` in the prompt.
model: inherit
color: yellow
tools:
Expand Down Expand Up @@ -41,7 +42,8 @@ Every `it()` block gets individual evaluation. No shortcuts, no "the rest look f
AND run coverage gap analysis on changed production files to find missing tests.
- **Standalone test audit.** A user asks to "audit tests", "check test quality", "review
tests against AGENTS.md", or "are there missing tests". You run the full test-audit
skill procedure.
skill procedure. A Codex dispatcher includes `Attribution model ID: <exact-id>` in
this standalone prompt.
- **Coverage gap check.** After production code changes, the user wants to know whether
new functions, branches, or bug fixes have adequate test coverage — and wants the
missing tests written, not just reported.
Expand Down Expand Up @@ -98,15 +100,19 @@ You loaded `sequentialthinking` in orientation. Call it at these decision points

Every PR comment or review you post — inline comments, review bodies, PR-level
comments — MUST include the footer: `\n\n---\n*🔍 ship-check · test-audit · <model-id>*`
where `<model-id>` identifies the runtime model. Claude runs use the family ID from
system context, such as `claude-opus-4-6`; omit context-window, dated-build, and other
transcript-only suffixes. Codex GPT runs use the verified exact runtime model ID,
including version and variant suffixes such as `gpt-5.6-sol`. In Codex, match a
runtime-provided current thread or session ID to `session_meta.payload.id` exactly,
then read `session_meta.payload.base_instructions.provenance.model`; never select a
rollout by recency, cwd, or display name. If the Codex ID cannot be verified, stop
before posting. No exceptions — a comment without a footer misattributes automated
output to the repo owner.
where `<model-id>` identifies the exact runtime model used for the footer and any
`Ship-Check` commit trailer. Resolve it in this order:

1. Use `Attribution model ID: <exact-id>` from the dispatch prompt verbatim.
Placeholder text is not an ID; treat it as a missing line.
2. Without that line, a Claude agent may use the family ID from its system context,
such as `claude-opus-4-6`; omit context-window and dated-build suffixes.
3. An OpenCode agent may use the exact provider/model ID exposed by its runtime.

A Codex child without the dispatch line stops before committing or posting and reports
an attribution blocker. Never infer a model from memory, parent prose,
rollout recency, cwd, or display name. No exceptions — a comment without a footer
misattributes automated output to the repo owner.

### Comment mode

Expand Down
19 changes: 11 additions & 8 deletions plugins/ship-check/skills/bug-check/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -538,14 +538,17 @@ REVIEW
```

Replace `OWNER_REPO` and `PR_NUMBER` with values from the dispatch prompt. Replace
`MODEL_ID` with the runtime model label. Claude runs use the family ID from system
context, such as `claude-opus-4-6`; omit context-window, dated-build, and other
transcript-only suffixes. Codex GPT runs use the verified exact runtime model ID,
including version and variant suffixes such as `gpt-5.6-sol`. In Codex, match a
runtime-provided current thread or session ID to `session_meta.payload.id` exactly,
then read `session_meta.payload.base_instructions.provenance.model`; never select a
rollout by recency, cwd, or display name. If the Codex ID cannot be verified, stop
before posting.
`MODEL_ID` with the exact runtime model:

1. Use `Attribution model ID: <exact-id>` from the dispatch prompt verbatim.
Placeholder text is not an ID; treat it as a missing line.
2. Without that line, a Claude agent may use its system-context family ID, and an
OpenCode agent may use its runtime-exposed provider/model ID.
3. An inline standalone run may use the current session's verified exact model source.

A Codex child without the dispatch line stops before committing or posting and reports
an attribution blocker. Never infer a model from memory, parent prose, rollout recency,
cwd, or display name.

5. **If 0 findings and no dismissals**, skip the API call — report "0 findings"
to the orchestrator only. With 0 findings but cleared suspicions, post a
Expand Down
19 changes: 11 additions & 8 deletions plugins/ship-check/skills/code-quality/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -549,14 +549,17 @@ REVIEW
```

Replace `OWNER_REPO` and `PR_NUMBER` with values from the dispatch prompt. Replace
`MODEL_ID` with the runtime model label. Claude runs use the family ID from system
context, such as `claude-opus-4-6`; omit context-window, dated-build, and other
transcript-only suffixes. Codex GPT runs use the verified exact runtime model ID,
including version and variant suffixes such as `gpt-5.6-sol`. In Codex, match a
runtime-provided current thread or session ID to `session_meta.payload.id` exactly,
then read `session_meta.payload.base_instructions.provenance.model`; never select a
rollout by recency, cwd, or display name. If the Codex ID cannot be verified, stop
before posting.
`MODEL_ID` with the exact runtime model:

1. Use `Attribution model ID: <exact-id>` from the dispatch prompt verbatim.
Placeholder text is not an ID; treat it as a missing line.
2. Without that line, a Claude agent may use its system-context family ID, and an
OpenCode agent may use its runtime-exposed provider/model ID.
3. An inline standalone run may use the current session's verified exact model source.

A Codex child without the dispatch line stops before committing or posting and reports
an attribution blocker. Never infer a model from memory, parent prose, rollout recency,
cwd, or display name.

4. **If 0 findings and no dismissals**, skip the API call — report "0 findings"
to the orchestrator only. With 0 findings but cleared suspicions, post a
Expand Down
15 changes: 7 additions & 8 deletions plugins/ship-check/skills/pr-monitor/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -271,14 +271,13 @@ For each unresolved bot thread, do ALL of these in order:
5. **Reply to the comment** -- do this BEFORE resolving, for EVERY bot comment.

Since `gh` posts as the user's account, every reply MUST include an attribution
footer. Claude runs use the family ID from system context, such as
`claude-opus-4-6`; omit context-window, dated-build, and other transcript-only
suffixes. Codex GPT runs use the verified exact runtime model ID, including version
and variant suffixes such as `gpt-5.6-sol`. In Codex, match a runtime-provided
current thread or session ID to `session_meta.payload.id` exactly, then read
`session_meta.payload.base_instructions.provenance.model`; never select a rollout
by recency, cwd, or display name. If the Codex ID cannot be verified, stop before
posting and report the attribution blocker. The footer format is:
footer. Use the pipeline's verified `Attribution model ID` when ship-check supplied
one. A standalone run uses the current session's exact runtime model: Claude reads
the family ID from system context; OpenCode uses its exact runtime identifier; Codex
matches its own `CODEX_THREAD_ID` to `session_meta.payload.id` before reading
`session_meta.payload.base_instructions.provenance.model`. Never select a rollout by
recency, cwd, or display name. If the exact ID cannot be verified, keep monitoring
but stop before posting and report the attribution blocker. The footer format is:
`\n\n---\n*🔍 ship-check · pr-monitor · <model-id>*`

```
Expand Down
19 changes: 11 additions & 8 deletions plugins/ship-check/skills/pr-review/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -270,14 +270,17 @@ REVIEW
```

Replace `OWNER_REPO` and `PR_NUMBER` with values from the dispatch prompt. Replace
`MODEL_ID` with the runtime model label. Claude runs use the family ID from system
context, such as `claude-opus-4-6`; omit context-window, dated-build, and other
transcript-only suffixes. Codex GPT runs use the verified exact runtime model ID,
including version and variant suffixes such as `gpt-5.6-sol`. In Codex, match a
runtime-provided current thread or session ID to `session_meta.payload.id` exactly,
then read `session_meta.payload.base_instructions.provenance.model`; never select a
rollout by recency, cwd, or display name. If the Codex ID cannot be verified, stop
before posting.
`MODEL_ID` with the exact runtime model:

1. Use `Attribution model ID: <exact-id>` from the dispatch prompt verbatim.
Placeholder text is not an ID; treat it as a missing line.
2. Without that line, a Claude agent may use its system-context family ID, and an
OpenCode agent may use its runtime-exposed provider/model ID.
3. An inline standalone run may use the current session's verified exact model source.

A Codex child without the dispatch line stops before committing or posting and reports
an attribution blocker. Never infer a model from memory, parent prose, rollout recency,
cwd, or display name.

5. **If 0 findings and no dismissals**, skip the API call — report "0 findings"
to the orchestrator only. With 0 findings but cleared suspicions, post a
Expand Down
Loading
Loading