Setting Up the AI Shipping Kit for Vibe-Coded App Review with PM Skills
The AI Shipping Kit provides a /ship-check command that automatically generates architecture documentation, security audits, and test coverage maps for AI-generated (vibe-coded) applications before deployment.
The phuryn/pm-skills repository hosts an extensible collection of product management plugins that transform AI assistants into structured PM toolkits. Among its nine domain-specific plugins, the pm-ai-shipping plugin delivers a complete AI shipping kit specifically designed to review, document, and validate vibe-coded applications—codebases generated rapidly by AI coding agents that require rigorous documentation before production deployment.
What Is the AI Shipping Kit?
The AI shipping kit is a specialized plugin within the PM Skills Marketplace that enforces documentation standards for AI-built software. According to the phuryn/pm-skills source code, the kit operates through the shipping-artifacts skill defined in pm-ai-shipping/skills/shipping-artifacts/SKILL.md.
This skill mandates five core documentation files that make any vibe-coded repository reviewable:
architecture.md— System overview and component relationshipsflows.md— Permission-aware user flow diagramspermissions.md— Role-based access control matricesvariables.md— Environment secrets and configuration inventorytests.md— Test coverage mapping and gap analysis
Architecture of the PM Skills Marketplace
The marketplace follows a plugin-first architecture where installing pm-ai-shipping automatically registers its skills and commands with the host AI.
| Layer | Description | Key Files |
|---|---|---|
| Marketplace Metadata | Central registry file that tells Claude Code and compatible agents where to find plugin packages | pm-ai-shipping/.claude-plugin/plugin.json |
| Skills | Markdown-formatted knowledge units encoding PM frameworks | pm-ai-shipping/skills/shipping-artifacts/SKILL.md |
| Commands | Slash-style workflows that chain skills into end-to-end processes | pm-ai-shipping/commands/ship-check.md |
| Validation | Unit tests ensuring skill definitions parse correctly | tests/test_validator.py |
Skills are invoked implicitly when the AI's knowledge base requires them, or explicitly via /plugin:skill syntax. Commands trigger with a leading slash (/).
Installing the AI Shipping Plugin
You can install the AI shipping kit through multiple interfaces depending on your AI coding environment.
Claude Cowork (GUI):
Navigate to Customize → Browse plugins → Personal → + → Add marketplace from GitHub, then enter:
phuryn/pm-skills
Claude Code (CLI):
claude plugin marketplace add phuryn/pm-skills
claude plugin install pm-ai-shipping@pm-skills
This registers the marketplace and pulls the shipping plugin, making the /ship-check command available immediately.
Using the /ship-check Command for Vibe-Coded Apps
The /ship-check command is the primary interface for reviewing vibe-coded repositories. Located at pm-ai-shipping/commands/ship-check.md, this command chains the shipping-artifacts skill to generate a complete shipping packet.
Syntax:
/ship-check the payments service
Output Generation:
The command produces a documentation package in the documentation/ directory:
- System Architecture (
architecture.md): Component diagrams and data flow - Security Flows (
flows.md): Authentication and authorization pathways - Access Control (
permissions.md): User roles and privilege matrices - Configuration (
variables.md): Environment variables and secrets inventory - Test Coverage (
tests.md): Existing tests, proposed coverage, and critical gaps
This packet serves as a mandatory review checkpoint before deploying AI-generated code to production.
Cross-Platform Setup for Other AI Agents
While optimized for Claude Code, the PM Skills Marketplace supports portability to other AI coding assistants through direct file copying.
OpenCode, Gemini CLI, or Cursor:
for plugin in pm-*/; do
mkdir -p .opencode/skills/
cp -r "$plugin/skills/"* .opencode/skills/ 2>/dev/null
done
This shell script copies all skills from the pm-ai-shipping and other plugins into the local workspace, enabling agents like OpenCode to invoke shipping-artifacts directly without marketplace registration.
Validating Skill Integrity
The repository includes automated testing to ensure shipping kit reliability. The tests/test_validator.py file validates that:
- All
SKILL.mdfiles contain required metadata headers (name,description) - Command manifests are syntactically correct
- Cross-references between skills and commands resolve correctly
Run these tests before deploying custom modifications to the shipping kit.
Summary
- The AI Shipping Kit is part of the
pm-ai-shippingplugin in thephuryn/pm-skillsmarketplace - Install via
claude plugin install pm-ai-shipping@pm-skillsor copy skills manually for other platforms - Use
/ship-checkto generate five mandatory documentation artifacts for vibe-coded apps - Documentation standards include architecture, flows, permissions, variables, and test coverage
- All skills are validated by
tests/test_validator.pyto ensure parsing consistency
Frequently Asked Questions
What is a "vibe-coded" app and why does it need special review?
Vibe-coded applications are software projects generated rapidly by AI coding agents where human developers focus on intent rather than implementation details. Because the underlying code may contain architectural assumptions invisible to the AI generator, the shipping kit enforces explicit documentation of architecture, security flows, and test coverage before deployment.
Can I use the AI shipping kit with Cursor or GitHub Copilot?
Yes. While the /ship-check command is native to Claude Code, the underlying skills in pm-ai-shipping/skills/ follow a universal Markdown format. Copy these files to your agent's skills directory (e.g., .cursor/skills/ or .opencode/skills/) to access the documentation standards without marketplace integration.
How do I customize the documentation requirements for my organization?
Modify the shipping-artifacts skill definition in pm-ai-shipping/skills/shipping-artifacts/SKILL.md. The skill uses a standard Markdown header format with name and description fields. After editing, run tests/test_validator.py to ensure your custom skill maintains parser compatibility with the marketplace framework.
Does the shipping kit integrate with existing CI/CD pipelines?
The /ship-check command generates Markdown documentation that can be committed to version control and parsed by CI systems. The tests.md artifact specifically identifies test coverage gaps, allowing pipeline scripts to fail builds when critical paths lack AI-generated or human-written tests.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →