gh-pr-merge-squash-stdout-shows-sibling-files-as-created

gh-pr-merge-squash-stdout-shows-sibling-files-as-created is a skill for Claude Code from wan-huiyan/agent-traffic-control. It costs 243 tokens per session (1,252 once invoked), scanned A, original, MIT.

A GitHub command-line troubleshooting guide for misleading output from squash-merging a pull request. It explains why files from other recently merged pull requests can appear as newly created even when they are not in your commit.

In plain words
What is it for?
Use it when `gh pr merge --squash` shows more files or insertions than your branch changed, especially with `create mode 100644` entries for files added elsewhere.
Why use it?
It prevents you from assuming that unrelated files were accidentally added to your pull request. It shows how to distinguish a confusing diff summary from the contents of the actual squash commit.

Skill for Claude Code

Written for Claude Code: disable-model-invocation in frontmatter.

Part of the agent-traffic-control plugin — 107 skills shipped together

Good fit Use it when gh pr merge --squash shows more files or insertions than your branch changed, especially with create mode 100644 entries for files added elsewhere.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/wan-huiyan/agent-traffic-control/gh-pr-merge-squash-stdout-shows-sibling-files-as-created
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add wan-huiyan/agent-traffic-control --skill gh-pr-merge-squash-stdout-shows-sibling-files-as-created
Clone the repo
git clone --depth 1 https://github.com/wan-huiyan/agent-traffic-control

Made for: Claude Code.

Or install agent-traffic-control, the plugin that ships this one along with the rest of its 107 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for gh-pr-merge-squash-stdout-shows-sibling-files-as-created

README.md
[![agentmods](https://agentmods.dev/badge/skills/wan-huiyan/agent-traffic-control/gh-pr-merge-squash-stdout-shows-sibling-files-as-created/github.svg)](https://agentmods.dev/skills/wan-huiyan/agent-traffic-control/gh-pr-merge-squash-stdout-shows-sibling-files-as-created)
Your own site
<a href="https://agentmods.dev/skills/wan-huiyan/agent-traffic-control/gh-pr-merge-squash-stdout-shows-sibling-files-as-created"><img src="https://agentmods.dev/badge/skills/wan-huiyan/agent-traffic-control/gh-pr-merge-squash-stdout-shows-sibling-files-as-created/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for gh-pr-merge-squash-stdout-shows-sibling-files-as-created

Your own site · 80×15
<a href="https://agentmods.dev/skills/wan-huiyan/agent-traffic-control/gh-pr-merge-squash-stdout-shows-sibling-files-as-created"><img src="https://agentmods.dev/badge/skills/wan-huiyan/agent-traffic-control/gh-pr-merge-squash-stdout-shows-sibling-files-as-created.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 243 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,252 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00243 $0.01252
Opus 5 $0.00121 $0.00626
Sonnet 5 $0.00049 $0.00250
Haiku 4.5 $0.00024 $0.00125

Measured 12d ago against content hash 5c6c92b39c34, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

gh-pr-merge-squash-stdout-shows-sibling-files-as-created scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/agent-traffic-control/skills/gh-pr-merge-squash-stdout-shows-sibling-files-as-created/SKILL.md · 104 lines

How it starts

The opening of the file, as written. The whole thing — 104 lines — stays where its author put it; the contents beside it link to each section on GitHub.

gh pr merge --squash stdout shows sibling-PR files as "created" — don't panic, check the commit

Problem

You squash-merge a clean, well-scoped PR and gh pr merge --squash echoes a diffstat that's far bigger than your change, including create mode lines for files you never touched:

 19 files changed, 744 insertions(+), 7 deletions(-)
 create mode 100644 docs/handoffs/session_24_handoff.md
 create mode 100644 docs/handoffs/session_25_prompt.md
 ...

This reads exactly like the git-add-all-sweeps-untracked-artifacts-into-commit trap — as if your feature PR smuggled unrelated docs onto main. It is alarming mid-deploy. But the files shown as "created" were already on main (added by sibling PRs merged after your branch's start point), and your actual squash commit does not contain them.

Context / Trigger Conditions

  • gh pr merge --squash (or --squash --delete-branch) prints a diffstat with more files / higher insertions than your PR's real diff.
  • create mode 100644 <file> appears for files added by other PRs merged since you branched (common when each session branches off main and several sibling PRs have merged in between).
  • You're about to revert / force-push / re-open in response to the scary echo.

Solution

Do not trust the merge command's stdout as the record of what landed. The echoed diffstat can be computed against an older ancestor than the current main tip, so files already present on main appear as new. Verify the actual squash commit:

git fetch origin --quiet
git show --stat origin/main | head -40   # the real squash commit + its file list

If the squash commit lists only your PR's files (and the insertion count matches), the merge is clean — the stdout was just a misleading view. Optionally confirm a specific file you feared was smuggled is NOT in the commit:

git show --stat origin/main | grep -c "session_2"   # 0 = not in the commit ✓

Only react (revert) if git show --stat origin/main itself shows the foreign files — that's the authoritative source, not the merge echo.

Read the full file on GitHub · 104 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 104 lines · 243 tokens per session scan A 5c6c92b39c34

Subscribe to this mod's changes

gh-pr-merge-squash-stdout-shows-sibling-files-as-created is a skill published in the GitHub repository wan-huiyan/agent-traffic-control (3 stars, last pushed yesterday), licensed MIT. It adds 243 tokens to every session and 1,252 once invoked, about $0.0012 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

ql-housekeep

Detect repo-hygiene issues that accumulate during long-running autonomous development (merge-conflict markers, orphan worktrees, CPC-variant duplicates, stale branches, version-manifest drift). Detection-only by default — reports findings, never deletes or modifies without explicit user confirmation.

andyzengmath/quantum-loop · 57 tokens

nazgul:doctor

Run the Nazgul read-only preflight diagnostic — checks jq/gh presence and auth, git-hooks drift, cache-vs-repo plugin version, the bash-vs-zsh hazard, the NAZGULDIR footgun, config-schema staleness, either install mode's .gitignore Nazgul-block drift (stamp and flush-left region), cross-session messaging and Remote…

OrodruinLabs/nazgul · 151 tokens

hotfix

Emergency fix workflow that bypasses normal sprint processes with a full audit trail. Creates hotfix branch, tracks approvals, and ensures the fix is backported correctly.

IdoCohen560/claude-unity-game-studio · 35 tokens

cloudflare-workers-ci-cd

Complete CI/CD guide for Cloudflare Workers using GitHub Actions and GitLab CI. Use for automated testing, deployment pipelines, preview environments, secrets management, or encountering deployment failures, workflow errors, environment configuration issues.

secondsky/claude-skills · 50 tokens

cloudflare-workers-observability

Cloudflare Workers observability with logging, Analytics Engine, Tail Workers, metrics, and alerting. Use for monitoring, debugging, tracing, or encountering log parsing, metric aggregation, alert configuration errors.

secondsky/claude-skills · 47 tokens

cloudflare-workers-dev-experience

Cloudflare Workers local development with Wrangler, Miniflare, hot reload, debugging. Use for project setup, wrangler.jsonc configuration, or encountering local dev, HMR, binding simulation errors.

secondsky/claude-skills · 47 tokens