{"id":51223062,"url":"https://github.com/Houseofmvps/ultraship","last_synced_at":"2026-07-16T19:01:03.607Z","repository":{"id":346858330,"uuid":"1190879722","full_name":"Houseofmvps/ultraship","owner":"Houseofmvps","description":"\"ULTRASHIP\" Claude Code plugin — 39 skills, 33 tools, 11 agents for ship-ready workflows: planning, review, pentesting, safety guardrails, canary monitoring, SEO/AI-readiness check, penetration testing, code review, competitive analysis, incident response. 1 dependency. 180 tests. MIT.","archived":false,"fork":false,"pushed_at":"2026-06-28T01:42:20.000Z","size":1318,"stargazers_count":109,"open_issues_count":0,"forks_count":13,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-06-28T02:19:29.427Z","etag":null,"topics":["aeo","ai","claude","claude-code","claude-code-plugin","claude-code-plugins","code-review","competitive-analysis","developer-tools","generative-engine-optimization","geo","indie-hackers","lighthouse","llms-txt","mcp","performance","playwright","saas","security","seo"],"latest_commit_sha":null,"homepage":"https://www.npmjs.com/package/ultraship","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Houseofmvps.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":"CITATION.cff","codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null},"funding":{"github":"Houseofmvps"}},"created_at":"2026-03-24T17:54:10.000Z","updated_at":"2026-06-28T01:42:24.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/Houseofmvps/ultraship","commit_stats":null,"previous_names":["houseofmvps/ultraship"],"tags_count":22,"template":false,"template_full_name":null,"purl":"pkg:github/Houseofmvps/ultraship","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Houseofmvps%2Fultraship","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Houseofmvps%2Fultraship/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Houseofmvps%2Fultraship/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Houseofmvps%2Fultraship/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Houseofmvps","download_url":"https://codeload.github.com/Houseofmvps/ultraship/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Houseofmvps%2Fultraship/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35555509,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-07-16T02:00:06.687Z","response_time":83,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["aeo","ai","claude","claude-code","claude-code-plugin","claude-code-plugins","code-review","competitive-analysis","developer-tools","generative-engine-optimization","geo","indie-hackers","lighthouse","llms-txt","mcp","performance","playwright","saas","security","seo"],"created_at":"2026-06-28T09:00:31.116Z","updated_at":"2026-07-16T19:01:03.593Z","avatar_url":"https://github.com/Houseofmvps.png","language":"JavaScript","funding_links":["https://github.com/sponsors/Houseofmvps"],"categories":["Source Catalog"],"sub_categories":[],"readme":"\u003cdiv align=\"center\"\u003e\n\n\u003cimg src=\"assets/hero-banner.jpg\" alt=\"Ultraship — Claude Code Plugin\" width=\"100%\"/\u003e\n\n### Claude Code plugin. 43 expert-level skills for building, shipping, and scaling production software. 37 audit tools (accessibility, vibe-coding security, AI evals, pentest, code quality, bundle size, SEO + AI Readiness check) plus a blocking ship-gate close the loop before deploy. A built-in Currency Guard keeps Claude on current docs, not stale training data.\n\n[![npm version](https://img.shields.io/npm/v/ultraship?style=for-the-badge\u0026logo=npm\u0026color=CB3837)](https://www.npmjs.com/package/ultraship)\n[![npm downloads](https://img.shields.io/npm/dm/ultraship?style=for-the-badge\u0026logo=npm\u0026color=blue\u0026label=Monthly%20Downloads)](https://www.npmjs.com/package/ultraship)\n[![npm total](https://img.shields.io/npm/dt/ultraship?style=for-the-badge\u0026logo=npm\u0026color=cyan\u0026label=Total%20Downloads)](https://www.npmjs.com/package/ultraship)\n[![GitHub stars](https://img.shields.io/github/stars/Houseofmvps/ultraship?style=for-the-badge\u0026logo=github\u0026color=gold)](https://github.com/Houseofmvps/ultraship/stargazers)\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow?style=for-the-badge\u0026logo=opensourceinitiative)](LICENSE)\n[![CI](https://img.shields.io/github/actions/workflow/status/Houseofmvps/ultraship/ci.yml?style=for-the-badge\u0026logo=github\u0026label=Tests)](https://github.com/Houseofmvps/ultraship/actions)\n[![Sponsor](https://img.shields.io/badge/Sponsor-EA4AAA?style=for-the-badge\u0026logo=githubsponsors\u0026logoColor=white)](https://github.com/sponsors/Houseofmvps)\n\n---\n\n[![Follow @kaileskkhumar](https://img.shields.io/badge/Follow%20%40kaileskkhumar-000000?style=for-the-badge\u0026logo=x\u0026logoColor=white)](https://x.com/kaileskkhumar)\n[![LinkedIn](https://img.shields.io/badge/LinkedIn-Connect-0A66C2?style=for-the-badge\u0026logo=linkedin)](https://www.linkedin.com/in/kailesk-khumar-soundararajan)\n[![houseofmvps.com](https://img.shields.io/badge/houseofmvps.com-Website-green?style=for-the-badge\u0026logo=google-chrome\u0026logoColor=white)](https://houseofmvps.com)\n[![kailxlabs.co](https://img.shields.io/badge/kailxlabs.co-Website-6366F1?style=for-the-badge\u0026logo=google-chrome\u0026logoColor=white)](https://www.kailxlabs.co)\n\n**Built by [Kaileskkhumar](https://www.linkedin.com/in/kailesk-khumar-soundararajan), founder of [HouseofMVPs](https://houseofmvps.com) and [Kailxlabs](https://www.kailxlabs.co)**\n\n\u003c/div\u003e\n\n---\n\n```\n0 dependencies · 274 tests · Node.js ESM · MIT\n```\n\n## Install\n\n```bash\n# Claude Code plugin\nclaude plugin marketplace add Houseofmvps/ultraship\nclaude plugin install ultraship\n\n# Or standalone via npx\nnpx ultraship ship .\nnpx ultraship seo .\nnpx ultraship security .\n```\n\n## How It Works\n\n```mermaid\nflowchart LR\n    U[\"You type a\u003cbr/\u003eslash command\"] --\u003e S[\"Skill\u003cbr/\u003e(markdown instructions)\"]\n    S --\u003e A[\"Agent\u003cbr/\u003e(dispatched worker)\"]\n    S --\u003e T[\"Tools\u003cbr/\u003e(Node.js scripts)\"]\n    A --\u003e T\n    T --\u003e O[\"JSON Results\"]\n    O --\u003e R[\"Scorecard / Report /\u003cbr/\u003eActionable Fixes\"]\n\n    style U fill:#f59e0b,stroke:#d97706,color:#000\n    style S fill:#8b5cf6,stroke:#7c3aed,color:#fff\n    style A fill:#3b82f6,stroke:#2563eb,color:#fff\n    style T fill:#10b981,stroke:#059669,color:#000\n    style R fill:#ef4444,stroke:#dc2626,color:#fff\n```\n\n```mermaid\nflowchart TD\n    subgraph Lifecycle[\"Full Lifecycle Coverage\"]\n        direction LR\n        I[\"Idea\u003cbr/\u003e/brainstorm\"] --\u003e B[\"Build\u003cbr/\u003e/sprint\"]\n        B --\u003e AU[\"Audit\u003cbr/\u003e/ship /seo /secure\"]\n        AU --\u003e D[\"Ship\u003cbr/\u003e/deploy\"]\n        D --\u003e L[\"Launch\u003cbr/\u003e/launch /compete\"]\n        L --\u003e G[\"Grow\u003cbr/\u003e/grow /cost\"]\n        G --\u003e RE[\"Rescue\u003cbr/\u003e/rescue /canary\"]\n    end\n\n    style I fill:#8b5cf6,stroke:#7c3aed,color:#fff\n    style B fill:#3b82f6,stroke:#2563eb,color:#fff\n    style AU fill:#f59e0b,stroke:#d97706,color:#000\n    style D fill:#10b981,stroke:#059669,color:#000\n    style L fill:#06b6d4,stroke:#0891b2,color:#000\n    style G fill:#84cc16,stroke:#65a30d,color:#000\n    style RE fill:#ef4444,stroke:#dc2626,color:#fff\n```\n\n## What `/ship` Does\n\n`/ship` runs 6 tools in parallel and outputs a scorecard:\n\n```mermaid\nflowchart LR\n    SHIP[\"/ship\"] --\u003e SEO[\"seo-scanner\u003cbr/\u003e63 rules\"]\n    SHIP --\u003e A11Y[\"a11y-scanner\u003cbr/\u003eWCAG 2.2\"]\n    SHIP --\u003e SEC[\"secret-scanner\u003cbr/\u003e+ npm audit\"]\n    SHIP --\u003e CODE[\"code-profiler\u003cbr/\u003eN+1, leaks, ReDoS\"]\n    SHIP --\u003e BUNDLE[\"bundle-tracker\u003cbr/\u003eJS/CSS/images\"]\n    SHIP --\u003e ENV[\"env-validator\u003cbr/\u003e+ migration-checker\"]\n\n    SEO --\u003e SC[\"Scorecard\u003cbr/\u003eREADY TO SHIP\"]\n    A11Y --\u003e SC\n    SEC --\u003e SC\n    CODE --\u003e SC\n    BUNDLE --\u003e SC\n    ENV --\u003e SC\n\n    style SHIP fill:#f59e0b,stroke:#d97706,color:#000\n    style SC fill:#10b981,stroke:#059669,color:#000\n    style SEO fill:#3b82f6,stroke:#2563eb,color:#fff\n    style SEC fill:#3b82f6,stroke:#2563eb,color:#fff\n    style CODE fill:#3b82f6,stroke:#2563eb,color:#fff\n    style BUNDLE fill:#3b82f6,stroke:#2563eb,color:#fff\n    style ENV fill:#3b82f6,stroke:#2563eb,color:#fff\n```\n\n```\n+===========================================+\n|      U L T R A S H I P   S C O R E       |\n+===========================================+\n|  SEO + AI Vis.  92/100  ############-    |\n|  Security        95/100  ############-    |\n|  Code Quality    88/100  ###########--    |\n|  Bundle Size     97/100  ############-    |\n+===========================================+\n|   OVERALL         90/100                  |\n|   STATUS          READY TO SHIP           |\n+===========================================+\n```\n\n\u003cdetails\u003e\n\u003csummary\u003eDemo\u003c/summary\u003e\n\n\u003cimg src=\"assets/demo.gif\" alt=\"Ultraship — SEO audit, secret scanning, scorecard\" width=\"100%\"/\u003e\n\n\u003c/details\u003e\n\n## Tools (40)\n\nEach tool is a standalone Node.js script (`node tools/\u003cname\u003e.mjs`). JSON output. Exit 0 always. No build step.\n\n### Auditing\n\n| Tool | What it checks |\n|---|---|\n| `seo-scanner` | 63 rules: 39 SEO (meta tags, canonicals, headings, OG tags, structured data, sitemap, cross-page duplicate/orphan detection), 20 GEO (AI bot access in robots.txt, snippet restrictions, llms.txt, structured data for AI extraction), 4 AEO (FAQPage/HowTo/speakable schema) |\n| `a11y-scanner` | WCAG 2.2 A/AA static checks: missing alt text, unlabeled form controls, icon-only buttons, missing `lang`/`title`/`main`, heading order, positive tabindex, zoom disabled, duplicate ids, broken aria references. Zero false positives. |\n| `ship-gate` | Blocking quality gate — scores all auditors (shared math with `/ship`), compares to `.ultraship/ship-gate.json` thresholds, hard-fails on leaked secrets / critical findings, **exits 1 on fail**. Generates a pre-push hook + GitHub Actions workflow. |\n| `secret-scanner` | AWS keys, Stripe keys, JWT secrets, database URLs, private keys. Redacts values in output. |\n| `vibe-security-scanner` | Vibe-Coding Security Sentinel — context secret-scanner misses: server-only secrets behind a `NEXT_PUBLIC_`/`VITE_` prefix, a decoded Supabase `service_role` key exposed to the client, service_role in a `\"use client\"` file, Supabase tables with no RLS. Zero false positives. |\n| `eval-scanner` | Locates every LLM call site (Anthropic, OpenAI, Gemini, Mistral, Cohere, Ollama, Vercel AI SDK, LangChain) by provider + model id, detects the test runner and whether an eval suite exists. Flags AI features shipping with no evals. Seeds `/evals`. Zero false positives. |\n| `code-profiler` | N+1 queries, sync I/O in handlers, unbounded queries, missing indexes, memory leaks, sequential awaits, ReDoS risk |\n| `bundle-tracker` | JS/CSS/image sizes in build output. Detects heavy deps (`moment`→`dayjs`, `lodash`→native). History for before/after. Monorepo-aware. |\n| `dep-doctor` | Unused dependencies via import graph analysis (not just grep). Dead wrapper files. Outdated packages. |\n| `content-scorer` | Flesch-Kincaid readability, keyword density, thin content detection, GEO heading analysis |\n| `lighthouse-runner` | Lighthouse via headless Chrome. Core Web Vitals, render-blocking resources, diagnostics. |\n\n### Validation\n\n| Tool | What it checks |\n|---|---|\n| `health-check` | HTTP status, response time, SSL certificate (issuer, expiry), 6 security headers |\n| `env-validator` | Compares `.env.example` against actual `.env`. Catches missing/empty/placeholder vars. |\n| `migration-checker` | Pending DB migrations for Drizzle, Prisma, Knex |\n| `og-validator` | Open Graph tags, image reachability, size validation |\n| `redirect-checker` | Redirect chains, loops, mixed HTTP/HTTPS. Sitemap-based bulk check. |\n| `api-smoke-test` | Hit API endpoints, check status codes, response times, CORS headers |\n\n### Generators\n\n| Tool | What it creates |\n|---|---|\n| `sitemap-generator` | `sitemap.xml` from HTML files and routes |\n| `robots-generator` | AI-friendly `robots.txt` (allows GPTBot, PerplexityBot, ClaudeBot) |\n| `llms-txt-generator` | `llms.txt` for AI assistant discoverability |\n| `structured-data-generator` | JSON-LD schema markup |\n\n### Competitive \u0026 Launch\n\n| Tool | What it does |\n|---|---|\n| `compete-analyzer` | Compares two URLs: tech stack, SEO score, security headers, response time. ASCII comparison card. |\n| `launch-prep` | Reads project, generates PH/Twitter/LinkedIn/HN copy, 14-item checklist, press kit |\n| `demo-prep` | Finds console.logs, TODOs, placeholder text, missing favicons. Scores demo readiness. |\n\n### Operations\n\n| Tool | What it does |\n|---|---|\n| `incident-commander` | Health check + git culprit analysis + error patterns + rollback commands + post-mortem template |\n| `growth-tracker` | Uptime, git velocity, SEO trajectory, dep health. Stores snapshots for week-over-week comparison. |\n| `cost-tracker` | Log AI token usage per feature/model. Built-in pricing for Claude, GPT-4o, Gemini. Daily trends. |\n| `pentest-scanner` | Automated penetration testing: XSS, SQLi, SSTI, command injection, path traversal, CORS, JWT, GraphQL introspection, prototype pollution, race conditions, request smuggling. Zero false positives, every finding has proof-of-concept. |\n| `canary-monitor` | Post-deploy canary monitoring: HTTP status, response time, error patterns, baseline regression detection. Auto-saves baselines for future comparison. |\n| `retro-analyzer` | Sprint retrospective: git velocity, commit patterns (features vs fixes), test health, hot files, shipping cadence. Generates insights and recommendations. |\n| `learnings-manager` | Project learnings CRUD: save, search, list, prune, export. Structured knowledge that compounds across sessions. |\n\n### Project Analysis\n\n| Tool | What it does |\n|---|---|\n| `onboard-generator` | Auto-generates developer guide: stack, directory tree, routes, schema, env vars, Mermaid diagram |\n| `architecture-mapper` | 4 Mermaid diagrams: system overview, route tree, DB ER, data flow. Circular dependency + orphan detection. |\n| `pattern-analyzer` | Analyzes testing, error handling, TypeScript usage, CI/CD, git practices. Cross-repo comparison. |\n| `audit-history` | Saves/compares audit scores over time |\n\n### Integrations (optional)\n\n| Tool | What it does |\n|---|---|\n| `gsc-client` | Google Search Console: submit sitemaps, inspect URLs, query rankings (requires `ULTRASHIP_GSC_CREDENTIALS`) |\n| `bing-webmaster` | Bing Webmaster: submit sitemaps/URLs, IndexNow instant push, keyword research, backlinks, site-scan, URL inspection (requires `ULTRASHIP_BING_KEY`). Powers ChatGPT Search + Microsoft Copilot. |\n| `ga4-client` | Google Analytics 4: overview, top-pages, landing-pages, traffic-sources, conversions, user-journey, devices, realtime, **ai-traffic** (ChatGPT/Perplexity/Copilot tracking), **organic** (search-only). `--organic` flag. |\n| `keyword-intelligence` | 12-command keyword engine: analyze, quick-wins, cannibalization, content-gaps, intent-map, trending, high-intent, page-keywords, content-decay, difficulty, **anomalies** (CTR anomalies), **cross-reference** (GSC↔GA4). `--brand` flag for non-brand filtering. |\n| `index-doctor` | Index diagnosis: inspect URLs via GSC URL Inspection API, diagnose 15+ coverage states, auto-fix and submit to Bing. |\n\n## Commands (16)\n\n\u003e **Every skill is also a slash command.** Claude Code merged commands into skills, so `/a11y`, `/sprint`, `/pentest`, `/compete`, `/canary`, `/launch`, `/rescue`, `/grow`, `/deploy`, `/learn`, `/guard`, `/retro`, `/investigate`, `/cost`, `/onboard`, `/architecture`, `/clone-patterns`, `/demo`, `/visual-diff`, `/release`, `/seo-strategy` and `/index-fix` all work too — they live in [Skills](#skills-41) above. The commands below are the remaining dedicated command files.\n\n| Command | Description |\n|---|---|\n| `/ship` | Pre-deploy scorecard. Runs 6 auditors, scores 5 categories |\n| `/seo` | SEO audit (63 rules) + AI visibility checks (bot access, snippet restrictions, schema) |\n| `/secure` | Secret scanning + OWASP patterns + `npm audit` |\n| `/perf` | Lighthouse + bundle size |\n| `/review` | Code review with confidence-scored findings |\n| `/health` | Production health check |\n| `/codex` | Generate a compact codebase index (routes, schema, components, lib) to save AI tokens |\n| `/content` | Readability + keyword density analysis |\n| `/bundle` | Bundle size tracking |\n| `/profile` | Static analysis for backend anti-patterns |\n| `/deps` | Unused/outdated dependency detection |\n| `/redirects` | Redirect chain/loop detection |\n| `/revise-claude-md` | Update CLAUDE.md with session learnings |\n| `/brainstorm` | Deprecated alias → use the `brainstorming` skill |\n| `/write-plan` | Deprecated alias → use the `writing-plans` skill |\n| `/execute-plan` | Deprecated alias → use the `executing-plans` skill |\n\n## Skills (43)\n\nSkills are markdown instruction files that shape Claude's behavior during your session. They activate based on context. When you're debugging, Claude uses the debugging skill. When you're building UI, it uses the frontend design skill.\n\n**Workflow (19):** brainstorming, planning, TDD, implementation, code review, debugging, refactoring, frontend design, API design, data modeling, git workflow, deploy pipeline, release, CLAUDE.md management, verification, browser testing, **sprint pipeline**, **investigation**, **learnings management**\n\n**Specialist (12):** SEO + AI visibility audit, **accessibility audit + auto-fix**, **deterministic ship-gate**, **AI eval harness**, security audit, **penetration testing**, performance audit, content quality, code profiling, parallel agent dispatching, **safety guardrails**, **staying current**\n\n**Growth \u0026 Intelligence (12):** competitive analysis, launch prep, incident response, growth tracking, cost tracking, onboarding, architecture mapping, pattern analysis, demo readiness, visual regression, **canary monitoring**, **sprint retrospective**\n\n## Agents (13)\n\nAgents are dispatched by skills to run audits in parallel:\n\n`code-reviewer` · `seo-auditor` · `seo-strategist` · `security-auditor` · `pentest-auditor` · `perf-auditor` · `a11y-auditor` · `browser-verifier` · `compete-analyzer` · `launch-auditor` · `incident-responder` · `growth-tracker` · `canary-monitor`\n\n## MCP Servers (2)\n\n| Server | Purpose |\n|---|---|\n| [Context7](https://github.com/upstash/context7) | Live library documentation. Fetches current docs for any framework/library. |\n| [Playwright](https://github.com/anthropics/anthropic-quickstarts/tree/main/mcp-server-playwright) | Browser automation. Navigate, screenshot, fill forms, test deployed pages. |\n\nBoth lazy-start on first use. No background processes.\n\n### Optional MCP integrations (detect-if-present)\n\nUltraship doesn't bundle these (they need your credentials and would slow every install), but several skills use them automatically *if you've connected them*:\n\n| Connect | Sharpens |\n|---|---|\n| **Sentry** | `/rescue` pulls live production errors and maps stack traces to code instead of guessing the culprit. `/canary` confirms a post-deploy error spike before recommending rollback. |\n| **Vercel** | `/deploy` reads real deployment status, build logs, and which commit is live (not just a single HTTP probe). |\n| **Supabase** | `/deploy` verifies migration state against the actual database to catch dashboard-vs-repo drift. |\n\nAdd them with `claude mcp add` (or the `/plugin` browser). When connected, the skills detect the tools and use them; when not, they fall back to the built-in static checks.\n\n## Sprint Workflow\n\nUltraship skills chain into a structured sprint pipeline. Each phase produces artifacts that feed the next.\n\n```mermaid\nflowchart LR\n    P[\"/write-plan\u003cbr/\u003ePlan\"] --\u003e B[\"/execute-plan\u003cbr/\u003eBuild\"]\n    B --\u003e T[\"TDD\u003cbr/\u003eTest\"]\n    T --\u003e R[\"/review + /secure\u003cbr/\u003eReview\"]\n    R --\u003e S[\"/ship + /deploy\u003cbr/\u003eShip\"]\n    S --\u003e V[\"/canary\u003cbr/\u003eVerify\"]\n    V --\u003e RE[\"/retro + /learn\u003cbr/\u003eReflect\"]\n\n    style P fill:#8b5cf6,stroke:#7c3aed,color:#fff\n    style B fill:#3b82f6,stroke:#2563eb,color:#fff\n    style T fill:#06b6d4,stroke:#0891b2,color:#000\n    style R fill:#f59e0b,stroke:#d97706,color:#000\n    style S fill:#10b981,stroke:#059669,color:#000\n    style V fill:#84cc16,stroke:#65a30d,color:#000\n    style RE fill:#ec4899,stroke:#db2777,color:#fff\n```\n\n| Phase | Skill | Output |\n|---|---|---|\n| Plan | `/write-plan` | Implementation plan with file map and test strategy |\n| Build | `/execute-plan` | Working code on a feature branch |\n| Test | TDD skill | Passing test suite |\n| Review | `/review` + `/secure` | Review report, security scan |\n| Ship | `/ship` + `/deploy` | Scorecard + production deploy |\n| Verify | `/canary` | Post-deploy health verification |\n| Reflect | `/retro` + `/learn` | Retrospective + saved learnings |\n\nRun `/sprint` to follow the full pipeline, or run individual phases as needed.\n\n## Safety Guardrails\n\n`/guard` activates PreToolUse hooks that block destructive commands before they execute:\n\n```mermaid\nflowchart LR\n    CMD[\"Claude runs\u003cbr/\u003ea command\"] --\u003e HOOK[\"PreToolUse\u003cbr/\u003eHook\"]\n    HOOK --\u003e CHECK{\"Destructive?\"}\n    CHECK --\u003e|\"rm -rf, DROP TABLE,\u003cbr/\u003egit push --force,\u003cbr/\u003ekubectl delete...\"| BLOCK[\"BLOCKED\"]\n    CHECK --\u003e|Safe| ALLOW[\"Allowed\"]\n\n    style HOOK fill:#f59e0b,stroke:#d97706,color:#000\n    style BLOCK fill:#ef4444,stroke:#dc2626,color:#fff\n    style ALLOW fill:#10b981,stroke:#059669,color:#000\n```\n\n- `rm -rf`, `DROP TABLE`, `TRUNCATE` (data destruction)\n- `git push --force`, `git reset --hard` (git history destruction)\n- `git clean -f`, `git checkout .` (working directory destruction)\n- `kubectl delete`, `docker system prune` (infrastructure destruction)\n\nOptional directory freeze restricts all file edits to a specific path. Explicitly confirmed actions always proceed.\n\n## Persistent Memory\n\nUltraship enforces a **memory-first rule** at session start. The SessionStart hook detects if you have a `MEMORY.md` file and instructs Claude to read it before performing any task. Context persists across sessions. No more repeating yourself about project state, deploy status, or decisions already made.\n\n- If `MEMORY.md` is found: Claude reads memory files before doing anything\n- If not found: Claude suggests setting up auto-memory for persistent context\n\nNo configuration needed. Just install the plugin.\n\n## SEO + AI Visibility\n\n```mermaid\nflowchart TD\n    subgraph Data[\"Data Sources (optional API keys)\"]\n        GSC[\"Google Search Console\u003cbr/\u003eIndex status, rankings\"]\n        GA4[\"Google Analytics 4\u003cbr/\u003eTraffic, AI referrals\"]\n        BING[\"Bing Webmaster\u003cbr/\u003eCrawl, IndexNow, backlinks\"]\n    end\n\n    subgraph Analysis[\"Intelligence Layer\"]\n        KW[\"keyword-intelligence\u003cbr/\u003e12 commands\"]\n        IDX[\"index-doctor\u003cbr/\u003eDiagnose + fix\"]\n        SCAN[\"seo-scanner\u003cbr/\u003e63 rules\"]\n    end\n\n    subgraph Output[\"Outputs\"]\n        STR[\"/seo-strategy\u003cbr/\u003e90-day ranking plan\"]\n        FIX[\"/index-fix\u003cbr/\u003eAuto-submit fixes\"]\n        SCORE[\"/seo\u003cbr/\u003eSEO + GEO + AEO score\"]\n    end\n\n    GSC --\u003e KW\n    GSC --\u003e IDX\n    GA4 --\u003e KW\n    BING --\u003e IDX\n    SCAN --\u003e SCORE\n    KW --\u003e STR\n    IDX --\u003e FIX\n\n    style GSC fill:#4285f4,stroke:#3367d6,color:#fff\n    style GA4 fill:#e37400,stroke:#c56200,color:#fff\n    style BING fill:#00809d,stroke:#006680,color:#fff\n    style KW fill:#8b5cf6,stroke:#7c3aed,color:#fff\n    style IDX fill:#8b5cf6,stroke:#7c3aed,color:#fff\n    style SCAN fill:#8b5cf6,stroke:#7c3aed,color:#fff\n    style STR fill:#10b981,stroke:#059669,color:#000\n    style FIX fill:#10b981,stroke:#059669,color:#000\n    style SCORE fill:#10b981,stroke:#059669,color:#000\n```\n\nThe SEO scanner checks 63 rules across three layers:\n\n- **SEO (39 rules)**: meta tags, canonicals, heading hierarchy, alt text, OG tags, sitemap, robots.txt, structured data, analytics detection, cross-page duplicate titles/descriptions, orphan page detection, canonical conflicts, thin content, internal linking\n- **GEO (20 rules)**: AI search visibility signals. Does `robots.txt` block GPTBot/PerplexityBot/ClaudeBot? Do `nosnippet`/`max-snippet` directives restrict AI citation eligibility? Is there `llms.txt` for AI discovery? Does structured data exist for AI extraction? These are verifiable technical signals, not ranking factor guesses.\n- **AEO (4 rules)**: answer engine schema checks. FAQPage, HowTo, speakable, Article/BlogPosting. These are the structured data types that enable featured snippets and voice results. We check presence, not SERP performance.\n\nBeyond the scanner, Ultraship connects to real APIs: GSC URL Inspection (actual index status), GA4 (actual AI referral traffic from ChatGPT/Perplexity/Copilot), Bing Webmaster (crawl status, IndexNow). Data-driven analysis, not estimates.\n\n## Dogfooding\n\n`/ship` results on [SaveMRR](https://savemrr.co) (Hono + React + Drizzle pnpm monorepo, 5 packages, 41 routes):\n\n| | Backend + Dashboard | Landing (29 pages) |\n|---|---|---|\n| SEO + AI Visibility | 63 | 52 |\n| Security | 100 | 100 |\n| Code Quality | 70 | 67 |\n| Bundle Size | 100 | 92 |\n| **Overall** | **83** | **78** |\n\n227 findings: 1 N+1 query, 33 unused deps (dead shadcn/ui wrappers via import graph), 153 SEO issues, 1 memory leak, 1 heavy dep.\n\n## Security\n\nAll tools use `execFileSync` with array args (no shell interpolation). HTTP tools import `tools/lib/security.mjs` for SSRF protection (blocks private IPs, cloud metadata, non-HTTP schemes). 10MB file read cap. 5MB response cap. Secret values redacted in output. Zero telemetry.\n\nSee [SECURITY.md](SECURITY.md).\n\n## Architecture\n\n```mermaid\nflowchart TD\n    subgraph Plugin[\"ultraship plugin\"]\n        MANIFEST[\".claude-plugin/\u003cbr/\u003eplugin.json\"]\n        HOOKS[\"hooks/\u003cbr/\u003eSessionStart + Currency Guard + Guard\"]\n\n        subgraph Core[\"Core Loop\"]\n            SKILLS[\"skills/\u003cbr/\u003e45 markdown files\"]\n            AGENTS[\"agents/\u003cbr/\u003e13 agent definitions\"]\n            COMMANDS[\"commands/\u003cbr/\u003e16 command files\"]\n        end\n\n        subgraph Runtime[\"Runtime\"]\n            TOOLS[\"tools/\u003cbr/\u003e41 Node.js ESM scripts\"]\n            LIB[\"tools/lib/\u003cbr/\u003esecurity.mjs, monorepo.mjs\"]\n        end\n    end\n\n    subgraph External[\"External (optional)\"]\n        MCP1[\"Context7 MCP\u003cbr/\u003eLive docs\"]\n        MCP2[\"Playwright MCP\u003cbr/\u003eBrowser automation\"]\n        GSC2[\"GSC / GA4 / Bing\u003cbr/\u003eAPIs\"]\n    end\n\n    COMMANDS --\u003e SKILLS\n    SKILLS --\u003e AGENTS\n    SKILLS --\u003e TOOLS\n    AGENTS --\u003e TOOLS\n    TOOLS --\u003e LIB\n    TOOLS --\u003e GSC2\n    SKILLS --\u003e MCP1\n    SKILLS --\u003e MCP2\n\n    style MANIFEST fill:#6b7280,stroke:#4b5563,color:#fff\n    style HOOKS fill:#f59e0b,stroke:#d97706,color:#000\n    style SKILLS fill:#8b5cf6,stroke:#7c3aed,color:#fff\n    style AGENTS fill:#3b82f6,stroke:#2563eb,color:#fff\n    style COMMANDS fill:#06b6d4,stroke:#0891b2,color:#000\n    style TOOLS fill:#10b981,stroke:#059669,color:#000\n    style LIB fill:#059669,stroke:#047857,color:#fff\n    style MCP1 fill:#6b7280,stroke:#4b5563,color:#fff\n    style MCP2 fill:#6b7280,stroke:#4b5563,color:#fff\n    style GSC2 fill:#6b7280,stroke:#4b5563,color:#fff\n```\n\n- Node.js ESM (`type: module`)\n- 1 dependency: `htmlparser2` (SAX HTML parser, ~30KB)\n- Tools output JSON to stdout, exit 0 on success and failure (errors in JSON)\n- Skills reference tools via `${CLAUDE_PLUGIN_ROOT}/tools/\u003cname\u003e.mjs`\n- No build step. No native bindings. No `node-gyp`.\n\n## Contributing\n\n```bash\ngit clone https://github.com/Houseofmvps/ultraship.git\ncd ultraship\nnpm test              # 180 tests, node:test\nnode tools/\u003ctool\u003e.mjs # Run any tool directly\n```\n\n[Open an issue](https://github.com/Houseofmvps/ultraship/issues) or submit a PR.\n\n## License\n\nMIT\n\n---\n\nBuilt by [Kailesk Khumar](https://www.linkedin.com/in/kailesk-khumar), founder of [HouseofMVPs](https://houseofmvps.com) · [Book a 30-min strategy call](https://cal.com/houseofmvps/30-min-strategy-call-with-our-founder)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FHouseofmvps%2Fultraship","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FHouseofmvps%2Fultraship","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FHouseofmvps%2Fultraship/lists"}