# Setting Up the AI Shipping Kit for Vibe-Coded App Review with PM Skills

> Learn how to set up the AI Shipping Kit for vibe coded app review. Automate documentation, security audits, and test coverage for your AI apps with this PM skills guide.

- Repository: [Pawel Huryn/pm-skills](https://github.com/phuryn/pm-skills)
- Tags: how-to-guide
- Published: 2026-07-05

---

**The AI Shipping Kit provides a `/ship-check` command that automatically generates architecture documentation, security audits, and test coverage maps for AI-generated (vibe-coded) applications before deployment.**

The `phuryn/pm-skills` repository hosts an extensible collection of product management plugins that transform AI assistants into structured PM toolkits. Among its nine domain-specific plugins, the **pm-ai-shipping** plugin delivers a complete AI shipping kit specifically designed to review, document, and validate vibe-coded applications—codebases generated rapidly by AI coding agents that require rigorous documentation before production deployment.

## What Is the AI Shipping Kit?

The AI shipping kit is a specialized plugin within the PM Skills Marketplace that enforces documentation standards for AI-built software. According to the `phuryn/pm-skills` source code, the kit operates through the `shipping-artifacts` skill defined in [`pm-ai-shipping/skills/shipping-artifacts/SKILL.md`](https://github.com/phuryn/pm-skills/blob/main/pm-ai-shipping/skills/shipping-artifacts/SKILL.md).

This skill mandates five core documentation files that make any vibe-coded repository reviewable:

- [`architecture.md`](https://github.com/phuryn/pm-skills/blob/main/architecture.md) — System overview and component relationships
- [`flows.md`](https://github.com/phuryn/pm-skills/blob/main/flows.md) — Permission-aware user flow diagrams  
- [`permissions.md`](https://github.com/phuryn/pm-skills/blob/main/permissions.md) — Role-based access control matrices
- [`variables.md`](https://github.com/phuryn/pm-skills/blob/main/variables.md) — Environment secrets and configuration inventory
- [`tests.md`](https://github.com/phuryn/pm-skills/blob/main/tests.md) — Test coverage mapping and gap analysis

## Architecture of the PM Skills Marketplace

The marketplace follows a **plugin-first** architecture where installing `pm-ai-shipping` automatically registers its skills and commands with the host AI.

| Layer | Description | Key Files |
|------|-------------|-----------|
| **Marketplace Metadata** | Central registry file that tells Claude Code and compatible agents where to find plugin packages | [`pm-ai-shipping/.claude-plugin/plugin.json`](https://github.com/phuryn/pm-skills/blob/main/pm-ai-shipping/.claude-plugin/plugin.json) |
| **Skills** | Markdown-formatted knowledge units encoding PM frameworks | [`pm-ai-shipping/skills/shipping-artifacts/SKILL.md`](https://github.com/phuryn/pm-skills/blob/main/pm-ai-shipping/skills/shipping-artifacts/SKILL.md) |
| **Commands** | Slash-style workflows that chain skills into end-to-end processes | [`pm-ai-shipping/commands/ship-check.md`](https://github.com/phuryn/pm-skills/blob/main/pm-ai-shipping/commands/ship-check.md) |
| **Validation** | Unit tests ensuring skill definitions parse correctly | [`tests/test_validator.py`](https://github.com/phuryn/pm-skills/blob/main/tests/test_validator.py) |

Skills are invoked implicitly when the AI's knowledge base requires them, or explicitly via `/plugin:skill` syntax. Commands trigger with a leading slash (`/`).

## Installing the AI Shipping Plugin

You can install the AI shipping kit through multiple interfaces depending on your AI coding environment.

**Claude Cowork (GUI):**

Navigate to Customize → Browse plugins → Personal → + → Add marketplace from GitHub, then enter:

```text
phuryn/pm-skills

```

**Claude Code (CLI):**

```bash
claude plugin marketplace add phuryn/pm-skills
claude plugin install pm-ai-shipping@pm-skills

```

This registers the marketplace and pulls the shipping plugin, making the `/ship-check` command available immediately.

## Using the `/ship-check` Command for Vibe-Coded Apps

The `/ship-check` command is the primary interface for reviewing vibe-coded repositories. Located at [`pm-ai-shipping/commands/ship-check.md`](https://github.com/phuryn/pm-skills/blob/main/pm-ai-shipping/commands/ship-check.md), this command chains the `shipping-artifacts` skill to generate a complete shipping packet.

**Syntax:**

```text
/ship-check the payments service

```

**Output Generation:**

The command produces a documentation package in the `documentation/` directory:

- **System Architecture** ([`architecture.md`](https://github.com/phuryn/pm-skills/blob/main/architecture.md)): Component diagrams and data flow
- **Security Flows** ([`flows.md`](https://github.com/phuryn/pm-skills/blob/main/flows.md)): Authentication and authorization pathways  
- **Access Control** ([`permissions.md`](https://github.com/phuryn/pm-skills/blob/main/permissions.md)): User roles and privilege matrices
- **Configuration** ([`variables.md`](https://github.com/phuryn/pm-skills/blob/main/variables.md)): Environment variables and secrets inventory
- **Test Coverage** ([`tests.md`](https://github.com/phuryn/pm-skills/blob/main/tests.md)): Existing tests, proposed coverage, and critical gaps

This packet serves as a mandatory review checkpoint before deploying AI-generated code to production.

## Cross-Platform Setup for Other AI Agents

While optimized for Claude Code, the PM Skills Marketplace supports portability to other AI coding assistants through direct file copying.

**OpenCode, Gemini CLI, or Cursor:**

```bash
for plugin in pm-*/; do
  mkdir -p .opencode/skills/
  cp -r "$plugin/skills/"* .opencode/skills/ 2>/dev/null
done

```

This shell script copies all skills from the `pm-ai-shipping` and other plugins into the local workspace, enabling agents like OpenCode to invoke `shipping-artifacts` directly without marketplace registration.

## Validating Skill Integrity

The repository includes automated testing to ensure shipping kit reliability. The [`tests/test_validator.py`](https://github.com/phuryn/pm-skills/blob/main/tests/test_validator.py) file validates that:

- All [`SKILL.md`](https://github.com/phuryn/pm-skills/blob/main/SKILL.md) files contain required metadata headers (`name`, `description`)
- Command manifests are syntactically correct
- Cross-references between skills and commands resolve correctly

Run these tests before deploying custom modifications to the shipping kit.

## Summary

- The **AI Shipping Kit** is part of the `pm-ai-shipping` plugin in the `phuryn/pm-skills` marketplace
- Install via `claude plugin install pm-ai-shipping@pm-skills` or copy skills manually for other platforms
- Use **`/ship-check`** to generate five mandatory documentation artifacts for vibe-coded apps
- Documentation standards include architecture, flows, permissions, variables, and test coverage
- All skills are validated by [`tests/test_validator.py`](https://github.com/phuryn/pm-skills/blob/main/tests/test_validator.py) to ensure parsing consistency

## Frequently Asked Questions

### What is a "vibe-coded" app and why does it need special review?

Vibe-coded applications are software projects generated rapidly by AI coding agents where human developers focus on intent rather than implementation details. Because the underlying code may contain architectural assumptions invisible to the AI generator, the shipping kit enforces explicit documentation of architecture, security flows, and test coverage before deployment.

### Can I use the AI shipping kit with Cursor or GitHub Copilot?

Yes. While the `/ship-check` command is native to Claude Code, the underlying skills in `pm-ai-shipping/skills/` follow a universal Markdown format. Copy these files to your agent's skills directory (e.g., `.cursor/skills/` or `.opencode/skills/`) to access the documentation standards without marketplace integration.

### How do I customize the documentation requirements for my organization?

Modify the `shipping-artifacts` skill definition in [`pm-ai-shipping/skills/shipping-artifacts/SKILL.md`](https://github.com/phuryn/pm-skills/blob/main/pm-ai-shipping/skills/shipping-artifacts/SKILL.md). The skill uses a standard Markdown header format with `name` and `description` fields. After editing, run [`tests/test_validator.py`](https://github.com/phuryn/pm-skills/blob/main/tests/test_validator.py) to ensure your custom skill maintains parser compatibility with the marketplace framework.

### Does the shipping kit integrate with existing CI/CD pipelines?

The `/ship-check` command generates Markdown documentation that can be committed to version control and parsed by CI systems. The [`tests.md`](https://github.com/phuryn/pm-skills/blob/main/tests.md) artifact specifically identifies test coverage gaps, allowing pipeline scripts to fail builds when critical paths lack AI-generated or human-written tests.