git-workflow

A set of rules for using Git, a tool for tracking code changes, when creating branches, commits, and pull requests for review.

In plain words
What is it for?
Use it when starting work from a branch, writing commits, pushing changes, opening a pull request, tracking discovered issues, or following project delivery checks.
Why use it?
It prevents unsafe delivery practices such as pushing directly to the main branch, omitting issue references, exposing secrets, or creating unclear pull requests.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/monkilabs/opencastle/git-workflow
Any agent
npx skills add monkilabs/opencastle --skill git-workflow
Clone the repo
git clone --depth 1 https://github.com/monkilabs/opencastle

Made for: Claude Code, Codex.

Per session 38 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 584 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00038 $0.00584
Opus 5 $0.00019 $0.00292
Sonnet 5 $0.00008 $0.00117
Haiku 4.5 $0.00004 $0.00058

Measured 2d ago against content hash 26023ec52915, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

git-workflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

src/orchestrator/skills/git-workflow/SKILL.md · 53 lines

How it starts

The opening of the file, as written. The whole thing — 53 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Git Workflow & Delivery

NEVER push directly to main. All changes go through feature/fix branch → PR.

Branch & Commit Rules

Rule Detail
Branch from main git checkout -b <type>/<ticket-id>-<slug>
Types fix, feat, chore, refactor, perf, docs
Commit messages Must reference issue ID — TAS-42: Fix token refresh
No force-push Never --force or --amend on shared branches; --force-with-lease on personal only
No secrets No tokens/keys in commits, PR descriptions, or output (rotate immediately if leaked)

Delivery Checklist (Every Task)

  1. Branch <type>/<ticket-id>-<slug> from main
  2. Atomic commits referencing issue ID
  3. Push branch to origin
  4. Open PR (do NOT merge) — write body to temp file first; use --body-file:
    # Write PR body to a temp file to avoid shell escaping issues
    cat > /tmp/pr-body.md << 'EOF'
    Resolves TAS-XX
    
    ## Changes
    - ...
    EOF
    GH_PAGER=cat gh pr create --base main --title "TAS-XX: Short description" --body-file /tmp/pr-body.md
    
    Never use inline --body with markdown/backticks/special chars — breaks in zsh heredocs, quoted strings.
  5. Update issue with PR URL

Discovered Issues Policy

No issue gets ignored. An untracked bug found during work is a quality-gate failure. Search .opencastle/KNOWN-ISSUES.md and the tracker first; if it is not tracked, either add it to KNOWN-ISSUES.md with all six fields (Issue ID, Status, Severity, Evidence, Root Cause, Solution Options) when it is an upstream limitation, or open a bug ticket with symptoms, repro steps, and affected files when it is fixable.

Task Tracking

Tracked in the task tracker (tracker-config.md). Team Lead creates/updates issues via MCP. Load task-management skill for conventions.

If MCP tools unavailable: Document planned issues (title + AC) in output; use "N/A" (no tracker) or "TAS-PENDING" (tracker configured); proceed with work; update IDs when available.

Read the full file on GitHub · 53 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 53 lines · 38 tokens per session scan A 26023ec52915

Subscribe to this mod's changes

git-workflow is a skill published in the GitHub repository monkilabs/opencastle (61 stars, last pushed 4d ago), licensed MIT. It adds 38 tokens to every session and 584 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

product-architect

Complete product development system with 64 agents and 35 frameworks. Use when the user wants to build a product, write a PRD, plan an MVP or roadmap, design an app, research a market or check whether a feature already exists or is novel, do competitive analysis, run a security audit, build a financial model, plan…

ankitjha67/product-architect · 211 tokens

codex-delegation

Use when a coding task would benefit from delegating work to Codex in the background — a deep independent second opinion, security or architecture analysis, or a parallel implementation running while the session continues. Lets Claude drive the codex companion itself (task, review, status --wait, result) without the…

zebbern/agent-collab · 74 tokens

cursor-delegation

Use when a coding task would benefit from delegating work to Cursor in the background — fast parallel implementation, scaffolding, or an everyday review running while the session continues. Lets Claude drive the cursor companion itself (task, review, status --wait, result) without the user typing /cursor: commands.

zebbern/agent-collab · 66 tokens

cursor-cli-runtime

Internal helper contract for calling the cursor-companion runtime from Claude Code.

zebbern/agent-collab · 17 tokens

cursor-prompting

Internal guidance for composing cursor-agent prompts and picking models for coding, review, diagnosis, and research tasks inside the Cursor Claude Code plugin.

zebbern/agent-collab · 31 tokens

cursor-result-handling

Internal guidance for presenting Cursor helper output back to the user.

zebbern/agent-collab · 16 tokens