ship-gate
>
它会碰到什么
逐条看命中(30 条严重或高危)
- 严重
references/checks.md:44cred-paths| SEC-17 | No hardcoded secrets in .env committed to repo | auto | critical | all |
- 严重
references/checks.md:45cred-paths| SEC-18 | .env files listed in .gitignore | auto | critical | all |
- 严重
references/checks.md:132cred-paths### SEC-17: No hardcoded secrets in .env committed
- 严重
references/checks.md:134cred-pathsCheck git history for .env files: `git log --all --name-only | grep .env`
- 严重
references/checks.md:134cred-pathsCheck git history for .env files: `git log --all --name-only | grep .env`
- 严重
references/checks.md:135cred-pathsCheck if .env exists in the working tree and is not in .gitignore.
- 严重
references/checks.md:137cred-pathsRemediation: Add .env* to .gitignore. Rotate any exposed secrets.
- 严重
references/patterns.md:195cred-paths### SEC-17/18: .env in repo
- 严重
references/patterns.md:198cred-paths# Check if .env files exist in working tree
- 严重
references/patterns.md:199cred-pathsfind . -maxdepth 3 -name ".env*" -not -path "*/node_modules/*" \
- 严重
references/patterns.md:200cred-paths-not -name ".env.example" -not -name ".env.sample" 2>/dev/null
- 严重
references/patterns.md:200cred-paths-not -name ".env.example" -not -name ".env.sample" 2>/dev/null
- 严重
references/patterns.md:202cred-paths# Check if .env is in .gitignore
- 严重
references/patterns.md:203cred-pathsgrep -n "\.env" .gitignore 2>/dev/null
- 严重
references/patterns.md:205cred-paths# Check git history for .env commits
- 严重
references/patterns.md:206cred-pathsgit log --all --name-only --diff-filter=A 2>/dev/null | grep "\.env" || true
- 严重
scripts/ship_gate_scanner.py:310cred-paths"SEC-17": CheckDef("SEC-17", "No hardcoded secrets in .env committed to repo", Severity.CRITICAL, "SEC"), - 严重
scripts/ship_gate_scanner.py:311cred-paths"SEC-18": CheckDef("SEC-18", ".env files listed in .gitignore", Severity.CRITICAL, "SEC"), - 严重
scripts/ship_gate_scanner.py:390cred-pathsfindings += grep_files(root, pat, exts=JS_EXTS | {".env", ".json"}, - 严重
scripts/ship_gate_scanner.py:520cred-paths# Check for .env files that are not .example/.sample
- 严重
scripts/ship_gate_scanner.py:524cred-pathsif name.startswith(".env") and name not in (".env.example", ".env.sample", - 严重
scripts/ship_gate_scanner.py:524cred-pathsif name.startswith(".env") and name not in (".env.example", ".env.sample", - 严重
scripts/ship_gate_scanner.py:524cred-pathsif name.startswith(".env") and name not in (".env.example", ".env.sample", - 严重
scripts/ship_gate_scanner.py:525cred-paths".env.template", ".env.local.example"):
- 严重
scripts/ship_gate_scanner.py:525cred-paths".env.template", ".env.local.example"):
- 严重
scripts/ship_gate_scanner.py:534cred-pathsif ".env" in content:
- 严重
scripts/ship_gate_scanner.py:537cred-pathsf".env file(s) exist ({', '.join(env_files)}) and may not be gitignored", - 严重
scripts/ship_gate_scanner.py:547cred-pathsif re.search(r"\.env", content):
- 严重
scripts/ship_gate_scanner.py:549cred-pathsreturn Result(c, Status.FAIL, ".env not listed in .gitignore")
- 严重
scripts/ship_gate_scanner.py:577cred-pathsexts=ALL_CODE_EXTS | {".env", ".env.local", ".env.production"})
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Ship Gate
Pre-production audit that scans a codebase and reports pass/fail/manual
across 8 categories before anything ships.
Intercept Behavior
When the user says "push to production", "deploy", "ship it", "go live",
or similar deploy-intent phrases, do NOT proceed with deployment. Instead:
- Ask: "Have you run the ship gate? Want me to scan now?"
- If yes, run the full audit below.
- If the user says they already ran it, ask when. If more than 24 hours
ago or if code changed since, recommend re-running.
How It Works
Step 1: Detect Stack
Run these checks in order to identify the project stack:
Framework detection:
package.json exists -> Node.js project
"next" in dependencies -> Next.js
"react" in dependencies -> React (if not Next.js)
"vue" in dependencies -> Vue
"svelte" in dependencies -> Svelte
"astro" in dependencies -> Astro
"express" in dependencies -> Express
"fastify" in dependencies -> Fastify
"hono" in dependencies -> Hono
requirements.txt or pyproject.toml -> Python project
"django" present -> Django
"flask" present -> Flask
"fastapi" present -> FastAPI
go.mod exists -> Go project
Cargo.toml exists -> Rust project
Database detection:
"@supabase/supabase-js" in package.json -> Supabase
supabase/ directory exists -> Supabase
"prisma" in dependencies -> Prisma (check schema for DB type)
"mongoose" in dependencies -> MongoDB
"pg" or "postgres" in dependencies -> PostgreSQL
firebase.json or .firebaserc exists -> Firebase
Deploy target detection:
vercel.json or .vercel/ exists -> Vercel
netlify.toml exists -> Netlify
Dockerfile exists -> Docker/VPS
fly.toml exists -> Fly.io
railway.json exists -> Railway
.platform/applications.yaml -> Platform.sh
Auth detection:
"@clerk" in dependencies -> Clerk
"next-auth" in dependencies -> NextAuth
"@supabase/auth-helpers" in deps -> Supabase Auth
"firebase/auth" in imports -> Firebase Auth
AI/LLM detection:
"openai" in dependencies -> OpenAI
"@anthropic-ai/sdk" in dependencies -> Claude API
"@google/generative-ai" in deps -> Gemini
Report detected stack before proceeding. This determines which checks
are relevant. Checks tagged with a specific stack in references/checks.md
are skipped if that stack is not detected.
Step 2: Run Automated Checks
Run categories in this order: SEC, DB, CODE, DEP, AI, DEPLOY, FE, OBS.
Security and database first because they produce the most critical findings.
For each category, run every auto-scannable check from
references/checks.md using the patterns in references/patterns.md.
Report progress after each category completes:
[1/8] Security: 3 FAIL, 12 PASS, 3 SKIP
[2/8] Database: 1 FAIL, 5 PASS, 6 SKIP
...
Report results as:
- PASS: check passed
- FAIL: issue found (with file path and line number)
- SKIP: not applicable to this stack
Step 3: Manual Confirmation
For checks that cannot be automated (backup restore tested, rollback plan
exists, staging test passed), present them as a checklist and ask the user
to confirm each one.
Step 4: Verdict
Classify results into three severities:
- CRITICAL: must fix before shipping (secrets exposed, no auth on routes,
no HTTPS, SQL injection vectors, no RLS on Supabase tables)
- HIGH: should fix before shipping (no error boundaries, no rate limiting,
console.logs in production, no pagination)
- ADVISORY: recommended but not blocking (no OG tags, no custom 404,
no analytics, no SBOM)
Final output:
SHIP GATE REPORT
================
Stack: Next.js + Supabase + Vercel
Scan time: 12s
CRITICAL (3 items, must fix)
FAIL [SEC-01] API key found in src/lib/api.ts:14
FAIL [DB-07] RLS not enabled on "profiles" table
FAIL [SEC-05] No CSRF protection on /api/checkout
HIGH (5 items, should fix)
FAIL [CODE-01] 12 console.log statements in production code
FAIL [CODE-03] Empty catch block in src/utils/auth.ts:45
FAIL [DEP-04] 3 critical npm audit vulnerabilities
FAIL [DEPLOY-05] No rollback plan documented
MANUAL [DEPLOY-06] Staging test not confirmed
ADVISORY (4 items, recommended)
FAIL [FE-01] Missing OG meta tags
FAIL [FE-03] No custom 404 page
PASS [OBS-01] Error monitoring configured
SKIP [AI-01] No AI/LLM usage detected
VERDICT: DO NOT SHIP (3 critical issues)
Fix critical items and re-run.
If zero critical items remain, verdict is: CLEAR TO SHIP.
If only high items remain, verdict is: SHIP WITH CAUTION (acknowledge risks).
Categories
Eight categories, each with a code prefix. Full check details in
references/checks.md.
| Prefix | Category | Auto | Manual | Tool |
|--------|----------|------|--------|------|
| SEC | Security | 15 | 3 | 0 |
| DB | Database | 7 | 5 | 0 |
| DEPLOY | Deployment | 3 | 8 | 0 |
| CODE | Code Quality | 11 | 0 | 1 |
| AI | AI/LLM Security | 5 | 3 | 0 |
| DEP | Dependencies | 5 | 0 | 1 |
| FE | Frontend Quality | 7 | 3 | 0 |
| OBS | Observability | 2 | 5 | 0 |
Scope
This skill audits. It does not fix. When it finds issues, it reports
them with file locations and remediation guidance. The user or another
skill (systematic-debugging, backend-patterns, shadcn-stack) handles
the fix.
This skill does not:
- Set up CI/CD pipelines
- Provision infrastructure
- Configure monitoring tools
- Run after deployment (it is pre-deploy only)
Integration Points
- karpathy-coder: run ship-gate after karpathy-check passes — simplicity first, then production readiness
- adversarial-reviewer: deep security review for items ship-gate flags as critical
- security-pen-testing: penetration testing methodology for SEC-category findings
- code-reviewer: general code quality review complements ship-gate's automated checks
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。