skills/worktrees/SKILL.md
Git worktree hygiene — when to create, how to clean up, and what fails silently. Captures three classes of bug that recur with worktree-based agent isolation: subagent dangling commits, orphan branches with unique work, and time-sensitive dangling-commit garbage collection. Includes detection commands, the salvage decision flow, and the trust-but-verify rule for subagent commit reports. Use when: a subagent reports a commit SHA, after a worktree-based agent finishes, cleaning up `.claude/worktrees/`, salvaging old crew worktrees, "is this branch in main?", verifying agent-claimed commits actually landed, planning multi-agent parallel work in worktrees.
npx skillsauth add mikeparcewski/wicked-garden wicked-garden-worktreesInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Git worktrees let multiple branches be checked out simultaneously and let
agent runtimes (Claude Code's Agent({isolation: 'worktree'}), crew runners,
etc.) make changes in isolation without disturbing the main checkout. Useful —
and a quiet source of three repeating bugs.
Subagent dispatched into an isolated worktree commits inside that worktree. Branch ref lives only in the worktree; when the worktree is removed, the commit is dangling — reachable only via git fsck --no-reflogs --lost-found until git gc collects it (14-day default via gc.pruneExpire). The subagent's "Commit SHA: abc1234" report becomes a lie. Code may also be sitting in the main worktree as unstaged changes.
Trust-but-verify rule — every time a subagent reports a commit, run the ancestry check from refs/recipes.md §1.
Worktree dir is gone (auto-cleaned, deleted weeks ago); branch (local or origin/crew/<name>) still points at commits NOT in main; git worktree list says nothing about it. Bulk-deleting branches because "no worktree = no work" silently loses everything between fork-point and tip.
Detection commands in refs/recipes.md §2. Each branch needs an explicit salvage decision (see Salvage flow below).
Commit object exists but no branch points at it. Time sensitive — once git gc runs (default grace 14 days), the object is unreachable forever. List + preserve commands in refs/recipes.md §3.
Decision must be prompt — there is no third state. Either preserve or accept the loss.
Branch + remote ref state, not on-disk worktree presence. Worktree-dir absence is the LEAST reliable indicator of merge state. Safe-delete recipe in refs/recipes.md §4.
For each candidate branch:
.claude/worktrees/agent-* and project-specific dirs (e.g. ~/.command_iq/worktrees/crew-*). Run git worktree list.refs/recipes.md §5.Manual file-by-file extraction often beats git cherry-pick on noisy branches — see refs/recipes.md §7.
Dangling commit SHA + unstaged changes in main worktree shows up when the subagent edited shared files (main worktree sees as unstaged) before its own commit (lands in worktree branch). Both halves need attention. Re-landing recipe in refs/recipes.md §6.
Whenever a subagent's summary says "commit SHA: XYZ":
git merge-base --is-ancestor XYZ origin/main — must return true (exit 0). Use origin/main (not HEAD); the latter false-positives if you're on a feature branch. git fetch origin main first if origin is stale.git status -s — should be empty if the commit is real and completegit show XYZ --stat | head — confirm the change set matches what the subagent describedSkipping this check has cost time before. The closing comment on a GitHub issue citing a dangling SHA is misleading future archaeology.
wicked-garden:engineering:review — that
reviews code changes; this reviews whether the changes actually
landed where they should.development
Pattern-conformance agent-half: evaluates a produced artifact or diff against a set of architectural/design pattern rules from the conformance-rule store (wicked_governance schema). Returns structured findings with rule ID, severity, and rationale — the deterministic half (mechanical rule recall) is done by the guard pipeline; this is the semantic evaluation step. Triggered by: the guard_pipeline `outgov_pattern` check (session-close), or explicitly by an engineering review when WICKED_OUTGOV_RULES_DIR is populated. NOT a replacement for the full `engineering` review skill — focuses only on conformance to stored Pattern rules; architecture and code-quality checks live in the `engineering` skill. Semantic evaluation reuses `wicked-garden-qe-semantic-reviewer` as the designated agent-half evaluator (per garden#983 spec). This skill is the orchestrating wrapper that loads applicable Pattern rules and delegates the per-rule semantic judgment to qe-semantic-reviewer.
tools
The FOUNDATIONAL domain-model capability: extract a codebase's domain — testable business rules (with confidence + provenance), entities, requirements — as a schema-conformant model on the estate graph. The workers annotate the store; wicked-core reads it and builds the requirements graph, coverage-gating fail-closed. Steers three fork workers. A shared substrate, not a modernization tool. The `modernize` archetype DERIVES from it; build / migrate / review / specify / explore consume the SAME domain model — none OWN it. Understanding a codebase's domain is upstream of almost everything else garden does. Use when: "extract the business rules / domain model from this codebase", "build a requirements graph from the code", "what does this system actually require", "reverse-engineer the domain before we build/port/migrate". Works on ANY codebase (modern or legacy) — the value is the domain model, not the porting. NOT the code transform itself (that is the archetype consuming this model). This skill produces the DOMAIN MODEL, not new code.
development
Domain-graph fork worker for the modernize archetype. Groups the estate's Louvain communities into business domains, attaches each requirement to its cluster (advisory cluster_id provenance), and invokes wicked-core's domain-graph build (which reads the annotated estate store, recomputes coverage fail-closed, and builds the requirements graph) — then validates core's output against the vendored schema. Use when: dispatched by wicked-garden-domain after rule extraction to turn a flat rule set into cluster-keyed domains; "group these into domains", "build the requirements graph", "translate clusters into a domain model". NOT for mining the rules themselves (that is domain-extractor) or threat-modeling (that is domain-coverage).
tools
Rule-extraction fork worker for the FOUNDATIONAL domain-model capability. Mines testable business rules from a codebase — each with a numeric confidence and a provenance{source, ref, source_kinds} — and annotates them into the estate store so wicked-core can build the domain-model requirements graph (coverage-gated). This is a substrate, not a modernization tool: the `modernize` archetype DERIVES from it, and build / migrate / review / specify / explore can consume the same domain model — none OWN it. Use when: dispatched by wicked-garden-domain to mine the business_rules of a codebase (or a module); "extract the domain rules", "what does this system require", building the requirements half of a domain model. NOT for grouping into domains (that is domain-modeler) or judging coverage (that is domain-coverage — a seat-distinct evaluator).