feat: add source-control plugin (commit, pull-request, worktree skills)#72
Conversation
Migrates the medley commit, pull-request, and worktree skills into one repo-agnostic delivery plugin. De-couplings: consumer conventions (commit-msg hook, branch naming, PR template, merge style, bot identity) read from the consuming project's CLAUDE.md/rules; push-channel monitoring generalized to any GitHub-events MCP channel with Monitor-tool and gh-poll fallbacks; bundled scripts write scratch to CLAUDE_PLUGIN_DATA and carry a self-contained test-helpers.sh; babysit self-identity resolved from gh api user (+ BABYSIT_SELF_LOGINS/--self override). Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
# Conflicts: # .claude-plugin/marketplace.json # README.md
…ontrol # Conflicts: # .claude-plugin/marketplace.json # README.md
…rface watch polling, clean-tree rebase ordering) Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
…eply verify surface, table-row classification counting) Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
…ontrol # Conflicts: # .claude-plugin/marketplace.json # README.md
…safe gh pr checkout, safe rebase-state fallback, inline follow-up verify surface, watermark on fetch success, phantom-finding exclusion, no-PR smart-default routing) Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
…ontrol # Conflicts: # .claude-plugin/marketplace.json # README.md
…hase, fork-safe babysit checklist checkout, untruncated log fetcher in readiness gate) Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
…-branch resolution in create + babysit rebases) Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
…ontrol # Conflicts: # .claude-plugin/marketplace.json # README.md
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_7b481b8f-6bbe-43bb-bb94-ca53d2814ce6) |
|
Claude finished @kyle-sexton's task in 4m 20s —— View job PR Review: feat/publish-source-control
|
There was a problem hiding this comment.
Stale comment
Risk: medium. Cursor Bugbot did not complete successfully (check skipped — usage limit reached), so I am not approving. Human review is needed before merge; no reviewers were assigned because the only human repository contributor is the PR author.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: bb26d82655
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…gression test, dirty-tree guard on own-branch babysit path) Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_b548953f-e3c6-431c-8b1f-012a13867ff8) |
|
Claude finished @kyle-sexton's task in 4m 9s —— View job PR Review: feat/publish-source-control
Round-8 fixes: both verified correctFix 1 — Plain
One edge-case worth knowing: if a reviewer who uses the Codex shields-badge format also happens to write Fix 2 — Dirty-tree guard on own-branch (
Outstanding findings from prior roundsThese five were called out in the previous review and remain unaddressed in round-8 (the commit message is explicit that round-8 targeted the two Codex findings only). 1. Resource leak — scratch dir never cleaned up in
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cf90cfb332
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
…ontrol # Conflicts: # .claude-plugin/marketplace.json # README.md
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_12b80ec7-8357-4f72-815c-49c30966865f) |
|
Claude finished @kyle-sexton's task in 2m 15s —— View job PR Review: feat/publish-source-control
Latest commit (b7fd0c7)The head commit is a merge from The preceding commit Round-9 fix: verified correctCodex P1 — Guard dirty worktrees before forcing removal (
Outstanding findings (5 prior, all still open)1. Resource leak — scratch dir never cleaned up in
|
There was a problem hiding this comment.
Risk: medium. Cursor Bugbot did not complete successfully (check skipped — usage limit reached), so I am not approving. Human review is needed before merge; no reviewers were assigned because the only human repository contributor is the PR author.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b7fd0c7115
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…ss lint (#203) ## Summary Closes decisions #38, #71, #72 (Decisions Log: https://claude.ai/code/artifact/232ecdce-8316-4880-8c0a-dc3c7dcf3a63). - **#38** `formatting-create-md-attribution-footer-drift`: `create.md`'s PR-body heredoc now emits the `🤖 Generated with Claude Code` attribution footer it documents elsewhere but previously didn't actually emit. - **#71** `naming-work-items-checklist-template-staleness`: `templates/checklist.md`'s `add` action reconciled to `add.md`'s actual current behavior — `--force` skip, `--type` native-Issue-Type resolution (org repos) vs. `type:` label (personal/non-org repos), `--agent-ready` body template, `--recurring` title prefix — none of which the checklist previously mentioned. - **#72** `tooling-gov-commit-skill-composition-lint`: new `guardrails` plugin hook `flag-commit-pr-skill-bypass.sh` — advisory `PreToolUse`/`Bash` guard that flags direct `git commit` (missing the canonical `-F -` + `--trailer` shape) or any `gh pr create`, nudging toward this marketplace's own `/commit` / `/pull-request create` skills. Gated on the consuming project actually having `source-control` enabled in its own `.claude/settings.json` (fails quiet on uncertain state, per the plugin's existing advisory-guard posture). Mirrors `block-hook-bypass.sh`'s literal-stripping detection and the shared telemetry envelope. ## Verification - New hook's own test suite: 19/19 passed. - `shellcheck` on both the hook and its test — clean. - `guardrails` version bumped 0.3.2 → 0.4.0 (new toggleable guard), README's guard table/kill-switch table/consumer-seams section updated to match. --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>



Refs melodic-software/medley#1283. Supersedes #63 (closed — GitHub Actions stopped creating workflow runs for that PR's pushes, so its required ci-status check could never re-run; all review findings there are fixed and all threads resolved).
Migrates the medley
commit,pull-request, andworktreeskills into one repo-agnosticsource-controlplugin (per the migration playbook per-plugin gate + acceptance security review). Worker: MELO-LAP-001-20260711T105548Z-20263.What ships
plugins/source-control/— 3 skills:/source-control:commit,/source-control:pull-request(prep/create/monitor/comments/merge/status/full/fetch-logs/babysit),/source-control:worktree(create/status/cleanup/audit); 6 bundled scripts + black-box tests + self-containedtest-helpers.shcategory: development, tags incl.delivery) + root README rowDe-coupling (medley → repo-agnostic)
CLAUDE.md/rules; Conventional Commits + squash merge remain defaults only; default branch resolved viagh repo view --json defaultBranchRef(never hardcodedmain)tools/github-eventschannel infra → generic "GitHub-events push channel (MCP)" tier with Monitor-tool and cloudgh-poll fallbacksgh-bot.sh/melodic-ai[bot]→ "your posting identities"; babysit readiness gate resolves self viagh api user+--self/BABYSIT_SELF_LOGINS.work/<slug>/artifacts → working-notes location /${CLAUDE_PLUGIN_DATA}; script paths via${CLAUDE_PLUGIN_ROOT}; test fixtures useexample-org/example-repo; integration tests require explicitINTEGRATION_REPO(+_RUN_ID)pitchaction dropped (bound to medley conventions with no portable seam)Review hardening on #63 (19 findings, 7 Codex/Claude rounds — all fixed + replied + thread-resolved)
Fork-safe checkout (
gh pr checkout <N>) and head-repo pushes; WIP-safe babysit checkout (never reset/clean foreign WIP; own-branch no-op); terminal-only rebase states with safe read-only fallback; all-3-surface comment watching with fetch-success watermark; realgh pr checksbucket vocabulary; inline-reply verification on the correct API surface; table-row-only classification counting in the readiness gate (+ phantom-finding exclusion, regression-tested); review-body reaction exemption; untruncated log fetcher in the readiness gate; no-PR smart-default routing to prep.Gate evidence (speed-adjusted per issue)
claude plugin validate --strict ./plugins/source-control→ PASS; catalogvalidate --strict .→ PASSclaude --plugin-dir ... plugin details source-control→ always-on ~453 tok (commit ~130, pull-request ~160, worktree ~160)--plugin-dirsmoke test in a clean non-medley repo:/source-control:worktree statusresolved assource-control:worktree, no permission errors, correct outputgit/gh; GitHub writes only inside documented/pull-requestphases; merge always behind a human gateNote: advisor tool was unavailable this session (harness-level); proceeded per non-interactive fallback.
Note
Medium Risk
Large instruction surface that can drive commits, pushes, PR creation, and merge via
gh; mitigated by documented human gates and no auto-merge, but agents following the skills still have real repo write capability.Overview
Introduces the
source-controlClaude Code plugin and registers it in.claude-plugin/marketplace.jsonand the root README./source-control:commitdocuments Conventional Commits (consumer overrides), subject pre-check,Co-Authored-Bytrailers, Bash heredocgit commit, surgical staging, and pathspec-limited commits for shared indexes./source-control:pull-requestis the bulk of the change: phased prep → create → monitor → merge, plus babysit, fetch-logs, and status/full flows. Reference docs enforce verified review findings, research-gated CI fixes, six-gate merge readiness, mandatory monitor checklists, and graceful degradation when optional review/research/MCP push channels are absent. Create adds validatedCloses #Nassembly, quoted-heredoc PR bodies, and composition with/commit.Bundled scripts (with black-box tests):
discover-prs.sh,fetch-all-pr-comments.sh,fetch-annotations.sh,babysit-readiness-gate.sh(mechanical finding vs classification-row coverage), plus related CI log helpers referenced in the skill./source-control:worktreeis described in the plugin manifest/README for create/status/cleanup/audit parallel-session workflows.Design is repo-agnostic:
${CLAUDE_PLUGIN_ROOT}paths,gh-resolved default branch, optional env vars (BABYSIT_SELF_LOGINS,WORKTREE_STALE_DAYS, fetch-log overrides), skills-only surface (no hooks/MCP), and GitHub writes scoped to documented PR phases with merge behind a human gate.Reviewed by Cursor Bugbot for commit b7fd0c7. Bugbot is set up for automated code reviews on this repo. Configure here.