task-integrate

A PitWay command that applies a worker task's committed changes to the main code tree. A worktree is a separate working copy used to isolate that task's files.

In plain words
What is it for?
It helps an orchestrator integrate one dispatched task at a time, preserve the worker's commit as evidence, clean up the temporary worktree, and leave verification for the main tree.
Why use it?
It prevents unrelated files or protected project records from being copied into the main tree and checks the change before applying it.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/thixpin/pitway/task-integrate
Clone the repo
git clone --depth 1 https://github.com/thixpin/pitway
Per session 15 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 399 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00015 $0.00399
Opus 5 $0.00008 $0.00199
Sonnet 5 $0.00003 $0.00080
Haiku 4.5 $0.00002 $0.00040

Measured 2d ago against content hash b3bcbcc64679, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

task-integrate scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

src/integrations/claude/commands/task-integrate.md · 40 lines

What it actually says

task-integrate

Role: Orchestrator

pitway task-integrate <id> [--json]

Integrates one dispatched task's worktree commits back into the main tree, diff-apply-model, one task at a time: computes the combined range diff (--binary --no-renames, created-from revision to scaffolding-branch HEAD), refuses before writing anything if any changed path (deletions included) falls outside the task's write_scope or touches .pitway/ or the worktree marker, pre-checks the apply (git apply --check — a failed check leaves the main tree byte-identical, the worktree preserved, and the task in_progress; PitWay never invents a merge), then applies the diff uncommitted, appends a worktree_integrate journal record (worker SHA as evidence-only metadata), and removes the worktree + scaffolding branch. The branch never enters history.

Completion stays the existing path, after integration: authoritative task-verify <id> in the main tree (while still in_progress), then task-update <id> review, then completed for the one atomic commit.

Re-runs are idempotent across both crash windows: an already-recorded integration finishes cleanup only; an applied-but-unrecorded diff (reverse-apply detected) finishes the record + cleanup. In both windows the work is already in the main tree — never task-discard there.

Refusals name their cause: no live dispatch, vanished worktree (→ task-discard), worker committed nothing, empty diff, dirty main tree, scope violation (every offending path named).

See ../protocol-driver.md (Parallel dispatch).

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 40 lines · 0 tokens per session scan A b3bcbcc64679

Subscribe to this mod's changes

task-integrate is a command published in the GitHub repository thixpin/pitway (19 stars, last pushed 3d ago), licensed MIT. It adds 15 tokens to every session and 399 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.