Install
$ agentstack add skill-ethanaubuchon-dossier-tradecraft-repo-setup ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Repo Setup
First step of /implement's repo path. Takes the repo from whatever state it's in to a fresh feature branch + worktree cut off an up-to-date main, clearing the debris of previously-merged work on the way. Assumes a git repo — the recipe's repo-vs-vault context branch runs before this.
Input
- branch — the feature branch to create, as
/(feat/,fix/,chore/,story/S--). The recipe derives it from the ticket. A bare description is acceptable — default the type tofeat/. - (implicit) the current repo and its
originremote.
Steps
- Guard a dirty tree. If
git status --porcelainis non-empty, stop and surface the changes — don't fetch/prune over dirty state. (A project override may stash-and-restore instead.) - Fetch.
git fetch --prune origin— updates remote-tracking refs and drops refs for branches deleted on the remote. - Fast-forward
main. Bring localmaintoorigin/main, never a merge commit:
- on
main→git merge --ff-only origin/main - not on
main→git fetch origin main:main(fast-forward-only update of the local ref; refuses if it would diverge).
- Prune merged work. Enumerate merged branches with
git branch --merged origin/main, add the squash-merged ones (see caveat), and for each — excludingmainand the current branch:
- Remove its worktree if present:
git worktree remove .worktrees/(--forceonly if an override opts in). - Delete its plan file:
rm -f .claude/plans/.mdusing the/→-flattened branch name (feat/foo→.claude/plans/feat-foo.md, matchingplan-file); gitignored, per-branch, safe. - Delete the branch:
git branch -dfor merge-commit / fast-forward merges;git branch -Dfor squash-merged branches (-drefuses them —-Dis safe because the caveat's check already confirmed the content landed).
Then git worktree prune to clear stale administrative entries.
Squash-merge caveat. git branch --merged origin/main catches merge-commit and fast-forward merges but not squash-merges — and /implement squashes by default, so a just-merged branch won't show as merged (and git branch -d would refuse to delete it). Detect those separately, in order of reliability:
gh pr list --state merged --headreports it merged — robust, but needs network + auth.git diff origin/main..(two-dot — compares the tip trees) is empty when the branch's change already landed andmainhasn't moved since. Network-free fallback; amainthat has advanced since the squash defeats it.
Delete the matches with git branch -D. Without gh auth and with an advanced main, a squash-merged branch may survive the prune — acceptable; the next clean run catches it.
- Create the feature branch + worktree off fresh main.
git worktree add .worktrees/ -b origin/main— one step: branch cut from up-to-datemain, checked out in an isolated worktree. - Ensure ignores. From the main checkout, make sure
.worktrees/and.claude/plans/are in the repo's.gitignore— append each if missing, no-op if present — so the.worktrees/dir never shows as untracked here:
`` [ -s .gitignore ] && [ -n "$(tail -c1 .gitignore)" ] && printf '\n' >> .gitignore for p in '.worktrees/' '.claude/plans/'; do grep -qxF "$p" .gitignore 2>/dev/null || printf '%s\n' "$p" >> .gitignore; done ` The leading guard appends a newline first if the file doesn't end in one, so an entry isn't glued onto the last line. Idempotent — a one-time addition per repo, committed via a normal branch/PR. (.claude/plans/ is also ensured independently by plan-file in the worktree where plans are actually written — step 6 covers the root checkout; plan-file` is the real plan-leak backstop.)
Output / contract
- In: repo state + a branch name.
- Out: the created branch name and its worktree path (
.worktrees/), surfaced soplan-fileand the later primitives operate inside the worktree. - Side effects: local
mainfast-forwarded; previously-merged branches + their worktrees + their plan files removed; new branch + worktree created;.worktrees/and.claude/plans/ensured in.gitignore. No pushes or other network writes; the optional squash-mergegh pr listcheck is a network read and needs auth.
Project overrides
This primitive stops at "branch + worktree exist." Deep, stack-specific provisioning is project-override territory, layered after the generic steps:
- Port / secret / compose setup — e.g. domainator's
setup-feature.sh(slot-based ports,.envsecret-gen,compose up). - Worktree policy — a repo that doesn't want worktrees overrides step 5 with a plain
git switch -c origin/main. - Dirty-tree handling — stash-and-restore instead of stop.
- Containerized verification seam — when tests run via
podman/docker compose, a bare worktree breaks two ways: the gitignored.env(and other secrets) won't exist in.worktrees/, so compose'senv_filefails — symlink or copy them in; and compose must be run from inside the worktree dir, because bind-mounts are relative and running from the repo root silently exercisesmain, not your branch. Overriderepo-setup(and see/implement's execute step) to set this up.
Overrides must honor the contract (same name, same "fresh branch + worktree off updated main" outcome) so the rest of /implement keeps working. (Step 6 already ensures .worktrees/ and .claude/plans/ are gitignored.)
Future scope
- Vault / non-repo path (deferred out of v1 —
/implementis repo-shaped for now). - Branch-name derivation from the ticket (currently the recipe's job, passed in).
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: ethanaubuchon
- Source: ethanaubuchon/dossier-tradecraft
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.