Pm Ai Shipping
AI Shipping Kit — for PMs and founders accountable for AI-built code. Document a vibe-coded app, review it for correctness, security and performance defects, and produce a reviewer-ready shipping packet.
- Type
- Plugin
- Repository
- phuryn/pm-skills
- GitHub stars
- 26.6k
- License
- MIT
- Repo last updated
- Sep 14, 2026
- Source file
- pm-ai-shipping/.claude-plugin/plugin.json
- Version
- 2.1.0
- Author
- Paweł Huryn
What Pm Ai Shipping is
Pm Ai Shipping is a plugin published in the phuryn/pm-skills repository on GitHub, which has about 26.6k stars. The repository describes itself as: “PM Skills Marketplace: 100+ agentic skills, commands, and plugins — from discovery to strategy, execution, launch, and growth.”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Pm Ai Shipping adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Pm Ai Shipping
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add phuryn/pm-skills
- Install the plugin: claude plugin install pm-ai-shipping@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter phuryn/pm-skills (the owner/repo shorthand works for GitHub).
- Find Pm Ai Shipping in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from pm-ai-shipping/.claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.
For PMs and founders accountable for AI-built code. Document a vibe-coded app, review it for correctness, security and performance defects, and produce a reviewer-ready shipping packet.
Overview
AI agents write code fast but leave no record of intent — what the system should do, who may do what, where the secrets live. Without that record, no human and no auditing agent can tell whether the code is safe to ship. This kit restores reviewability: it documents the system, then audits the gap between what the docs say and what the code does — the class of bug generic scanners miss because they have no model of intent.
Start with /ship-check for the full sequence, or run a single stage with the specialist commands.
Install
Install from the pm-skills marketplace and enable the pm-ai-shipping plugin. Each command can be triggered with /pm-ai-shipping: or its short / form; skills auto-load when the topic matches.
Skills (3)
- shipping-artifacts — The durable documentation set that makes an AI-built app reviewable: a core every app needs (architecture, user/permission flows, permissions, variables/secrets, test-coverage map) plus conditional docs added only when they apply (emails, cron, SEO, embedded agents/automation). Defines what each doc must capture and how a reviewer uses it.
- code-review — The top-level review skill. Correctness is its core; performance and security are optional sub-cases of the same engine. Anchors on agreements between participants across a boundary — the defects that are invisible file-by-file because each side looks reasonable alone — forces a violating execution, and refutes every candidate before reporting.
- intended-vs-implemented — The method for finding the gap between what a system is documented to do and what the code actually does, with cited evidence on both sides and without hand-wavy findings.
Commands (5)
- /pm-ai-shipping:ship-check — Turn a vibe-coded repo into a reviewer-ready shipping packet: document, wire agent context, run correctness, security and performance reviews, add an independent unsteered pass by a second model, map test coverage, and compile the results.
- /pm-ai-shipping:document-app — Reverse-engineer a codebase into the system documents reviewers and auditors need — a core set (architecture, flows, permissions, variables) plus conditional docs (emails, cron, SEO, automation) when they apply.
- /pm-ai-shipping:derive-tests — Turn documented intent into a test-coverage map: inventory the tests that exist today, separate them from proposed tests and unverified gaps, mark each unit / guarded-live / manual, and recommend a green-before-merge CI gate.
- /pm-ai-shipping:security-audit-static — Static security audit: map trust boundaries, cross-reference documented intent, self-refute every finding, and report only evidence-backed risks.
- /pm-ai-shipping:performance-audit-static — Static performance audit: find N+1 queries and request waterfalls, over-fetching, missing indexes, and caching opportunities, ranked by effort and impact.
Author
Paweł Huryn — The Product Compass Newsletter
License
MIT
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Pm Ai Shipping?
Pm Ai Shipping is a plugin for Claude Code and Claude Cowork from the phuryn/pm-skills repository on GitHub. AI Shipping Kit — for PMs and founders accountable for AI-built code. Document a vibe-coded app, review it for correctness, security and performance defects, and produce a reviewer-ready shipping packet.
How do I install Pm Ai Shipping in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add phuryn/pm-skills Install the plugin: claude plugin install pm-ai-shipping@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Pm Ai Shipping in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter phuryn/pm-skills (the owner/repo shorthand works for GitHub). Find Pm Ai Shipping in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Pm Ai Shipping safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Pm Go To Market Go-to-market skills for PMs: GTM strategy, growth loops, GTM motions, beachhead segments, and ideal customer profiles. Plugin · phuryn/pm-skills
- Pm Market Research Market research skills for PMs: user personas, market segmentation, sentiment analysis, and competitive analysis. Plugin · phuryn/pm-skills
- Pm Marketing Growth Product marketing and growth skills: marketing ideas, value proposition statements, North Star metrics, product naming, and positioning. Plugin · phuryn/pm-skills
- Pm Product Strategy Product strategy skills for PMs: vision, strategy canvas, value propositions, lean canvas, business model canvas, SWOT, PESTLE, Ansoff Matrix, Porter's Five Forces, and monetization. Plugin · phuryn/pm-skills
- Pm Data Analytics Data analytics skills for PMs: SQL query generation and cohort analysis. Analyze user data, generate queries, and identify retention patterns. Plugin · phuryn/pm-skills
- Planning With Files Persistent project planning files with lifecycle hooks that inject selected plan context. Automatic recovery uses project files only. Explicit catchup modes may read same-project local session records to emit aggregate counts or bounded nonce-framed excerpts. Optional gated mode can request continuation on capable hosts and never runs commands declared in Markdown. No network upload path. Works… Plugin · OthmanAdi/planning-with-files
- Pm Execution Execution and product management skills: PRDs, OKRs, roadmaps, sprints, pre-mortems, stakeholder maps, user stories, prioritization frameworks, and more. Plugin · phuryn/pm-skills
- Beads AI-supervised issue tracker for coding workflows. Manage tasks, discover work, and maintain context with simple CLI commands. Plugin · gastownhall/beads