Reusable git delivery workflows derived from local slash commands (commit, push, PR, release notes, GitHub Actions failure triage with worktree-based fixes, and isolating your own changes from a…

MITAuto-check passedDevelopment

Install Git Workflows

skills CLI
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill git-workflows -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit git-workflows --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/git-workflows .claude/skills/git-workflows && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
git-workflows
GitHub stars
1.1k
Token cost
~3k tokens
SKILL.md length
1,669 words
Files
3 (incl. references)
Skills in repo
49
Repo updated
First seen
Licence
MIT

At a glance

Reusable git delivery workflows derived from local slash commands (commit, push, PR, release notes, GitHub Actions failure triage with worktree-based fixes, and isolating your own changes from a…

  • Works in 4 steps: Read the requested command template from… → Follow it as workflow steps, not as a… → Keep actions safe by default → …
  • Tasks that involve Git workflow
  • SKILL.md covers When to use this skill, Source of truth, Execution rules and Repo-specific gotchas…, plus 4 more sections
  • Calls git, node and gh

What it does

Git Workflows is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit. Reusable git delivery workflows derived from local slash commands (commit, push, PR, release notes, GitHub Actions failure triage with worktree-based fixes, and isolating your own changes from a shared dirty workspace).

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/command-catalog.md` and `references/source-commands.md`).

It sits in Development, covering Git workflow, Changelog and release notes and Hooks and plugins. It works with Git and GitHub Actions. The repository describes itself as: Backend for AI coding agents on CloudBase — database, auth, functions via Plugin, Skills & MCP. The licence is MIT.

When your agent uses it

  • Tasks that involve Git workflow
  • Tasks that involve Changelog and release notes
  • Tasks that involve Hooks and plugins

Example prompts

  • “/git-workflows”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Read the requested command template from references/source-commands.md.
  2. Follow it as workflow steps, not as a loose summary.
  3. Keep actions safe by default
  4. If a workflow implies external side effects (push/PR/release), request explicit confirmation right before performing the side effect.

What it can do on your machine

Read from SKILL.md and the folder at commit ea2c202. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • node
    • gh
    • npm
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, gh, npm and pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Git Workflows loads about 3k tokens when it runs, and up to ~8.3k if it reads all its reference files. Until then it costs about 58 tokens; SKILL.md has 1,669 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from TencentCloudBase/CloudBase-AI-Toolkit at commit ea2c202, republished under its MIT licence (© TencentCloudBase). 1,669 words, ~3,007 tokens.

Download SKILL.mdSave it as .claude/skills/git-workflows/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
git-workflows
description
Reusable git delivery workflows derived from local slash commands (commit, push, PR, release notes, GitHub Actions failure triage with worktree-based fixes, and isolating your own changes from a shared dirty workspace).

Git Workflows (from local commands)

This skill turns the repo's former local command templates into reusable git delivery workflows.

When to use this skill

Use this skill when the user asks to:

  • run a commit workflow (conventional-changelog style)
  • push changes with safe branching and open a PR
  • generate release notes from git history / GitHub context
  • publish a version from main (including bilingual README Recent updates on minor bumps)
  • analyze the latest failed GitHub Actions workflow, attempt a fix in an isolated worktree, and submit a PR
  • move your own uncommitted changes onto a clean branch when the current workspace also holds someone else's edits
  • check IDE icon configuration consistency across document components and source files

Source of truth

All detailed steps and constraints live in:

  • references/source-commands.md

This skill describes how to apply them consistently across agents/editors without duplicating implementation details.

Execution rules

  1. Read the requested command template from references/source-commands.md.
  2. Follow it as workflow steps, not as a loose summary.
  3. Keep actions safe by default:
    • avoid destructive git operations unless explicitly requested
    • avoid committing secrets
    • keep changes minimal and localized
  4. If a workflow implies external side effects (push/PR/release), request explicit confirmation right before performing the side effect.

Repo-specific gotchas (CloudBase-MCP)

  • Sync dependencies before building on main. A stale node_modules shows up as a type error in code that is actually correct (seen: @cloudbase/manager-node 5.8.6 installed vs 5.8.8 locked → Property 'ExternalStorage' does not exist on type 'CreateEnvParams'). Verify with npm pack <pkg>@<locked-version> and read the .d.ts before touching code.
  • pnpm install fails inside the sandbox with ERR_PNPM_CODEBUDDY_BROKER_DENY (symlink ENOENT), and the failed run deletes the package directory that was previously there. Re-run the same command with sandbox disabled before concluding anything about the build.
  • npm run build succeeds even when the last step is blocked. The build's rm -rf dist/types is refused by the safe-delete hook (325 files > threshold), so the log ends with a SAFE_DELETE_BULK_CONFIRM_REQUIRED line and dist/types/ is left behind. Judge the build by whether webpack printed ERROR in, not by that trailing message.
  • Release-note scope is git log <previous-tag>..HEAD, including merge commits. A PR number lower than the current version does not mean it already shipped — PRs often merge after the tag that "should" have contained them.
  • CHANGELOG.md's ## Unreleased is not rotated on release in this repo; publish a GitHub Release and leave the changelog alone unless asked.
  • Version bump surface: mcp/package.json + config/source/** skill versions (node scripts/sync-skill-versions.mjs --version X.Y.Z) + config/.claude/skills mirror (npm run sync:claude-skills-mirror) + optional README bullets (patch: only for clearly user-visible capability, and both README.md and README.zh-CN.md, verified with npm run check:readme-sync).

Redacting internal references from a pushed PR

Public-repo PR metadata — the title, the body, each commit headline, each commit message — is as public as the diff, yet it never appears in the diff, so no file-layer guard covers it. npm run check:internal-refs enforces this in CI (see internal-docs-guard.yml). When a reference has already been pushed, fix it in place:

  1. Enumerate every source before editing anything. gh pr view <n> --json commits truncates headlines — read messages from git instead (git log --format='%s%n%b' origin/main..<branch>) and the body via gh api repos/<owner>/<repo>/pulls/<n> --jq .body. Body and commit messages are separate fixes; doing only one is the usual miss.
  2. Amend the message, then prove nothing else moved: git commit --amend -F -, followed by git diff --stat <old-sha> HEAD — it must be empty.
  3. Force-push with --force-with-lease. The repo rule says "no --force", but rewriting an already-pushed message has no alternative; the lease form still refuses to clobber a concurrent update.
  4. Rewrite the body with gh pr edit <n> --body-file -.
  5. Clear local-only commits carrying the same problem: back up first (git diff > /tmp/residual.patch), then git reset --hard origin/main. The content is normally already in the PR it was split out of, so nothing is lost — verify each file is covered by a branch before resetting.

A --force-with-lease push re-triggers CI, and this repo's Publish MCP Package to pkg.pr.new job runs live cloud integration tests that flake on timeouts (seen: cloud-function create/call at 60s). Read the failed test name before assuming the rewrite broke something — a message-only amend cannot.

Recovering a stacked PR whose base was squash-merged

When PR B is stacked on branch A (base = A's branch) and A is squash-merged into main, A's commits on main get new shas. A's branch is no longer an ancestor of main, but B's base pointer still points at it — so B turns CONFLICTING even though nothing in it changed. Any PR merged into A's branch in the meantime (a deeper stack) makes the collision certain.

  1. Pre-flight the conflict set before touching anything: git merge-tree --write-tree <A's-branch> <B's-branch> lists the conflicting paths directly. Cheap, and it tells you which files need a decision.
  2. Rebase onto main, dropping the already-merged commit: git rebase --onto origin/main <A's-original-commit>. Dropping it is the point — its content is on main, and replaying it would re-apply an already-merged change. Do not rebase onto A's stale branch.
  3. Resolve by file type (these three recur):
    • CHANGELOG.md — keep both sides; bullet order is irrelevant. Re-align blank-line spacing if the merge changed it.
    • package.json — take the union; the added scripts entries come from different PRs and almost never truly conflict.
    • config/source/editor-config/compat-baseline.json — take main's side (git checkout --ours during rebase), then recompute after the rebase finishes with node scripts/update-compat-baseline.mjs. Sanity check: the recomputed diff should match the original commit's line count (a version bump touching 3 skills produced 23±, i.e. the same 46 lines).
  4. Fold the recomputed baseline into the commit that caused it — git commit --fixup=<sha> then GIT_SEQUENCE_EDITOR=true git rebase -i --autosquash <main-sha>. It belongs to the version bump, not a standalone commit. git commit --fixup sometimes prints nothing to commit and still squashes correctly afterwards — judge by git log, not that message.
  5. Retarget the base and rewrite the description: gh pr edit <n> --base main; the PR now carries the whole stack, so its title and body must cover every commit in it, not just the top one.
  6. Verify on the rebased content, not just by "no conflict markers": run the version check, the compat diff, and the unit tests. If the PR adds a CI gate, running that gate against origin/main on this branch is the strongest available check — it exercises the gate against real input.
Show full SKILL.md (621 more words)Show less
Trap: a paths-filtered workflow can silently not run at all

After a force-push (synchronize) while the base was still the stale stacked branch, the workflows that carry a paths: filter (compat-check.yml, check-prompts-sync.yml) did not trigger at all — only the unfiltered internal-docs-guard.yml and the push-triggered Sync to CNB ran. gh pr checks does not list checks that never ran, so the PR looked clean while two checks had simply been skipped.

  • Judge with the API, not the UI: gh api "repos/<owner>/<repo>/actions/runs?branch=<branch>" --jq '.workflow_runs[] | "\(.name) \(.event) \(.conclusion)"'. A workflow missing from that list was skipped, not passed.
  • Fix: gh pr close <n> then gh pr reopen <n>. The reopened event recomputes against the new base and triggers the filtered workflows normally.
When the PR is not stacked and main simply moved

A plain PR turns CONFLICTING the same way — usually on config/source/editor-config/compat-baseline.json alone, since every branch that regenerates it rewrites the same lines. git merge origin/main is fine here: the squash on merge erases the extra merge commit, and there is no already-merged commit to drop. Watch the direction — during a merge main is --theirs (git checkout --theirs …); during a rebase it is --ours.

Then regenerate the whole chain on top of the merge rather than hand-resolving the generated side:

  1. node scripts/generate-prompts-data.mjs, then node scripts/generate-prompts.mjs
  2. node scripts/sync-claude-skills-mirror.mjs
  3. node scripts/build-compat-config.mjs
  4. node scripts/update-compat-baseline.mjs

Merging main typically brings changes under config/source/skills/** as well, and those propagate into every IDE mirror and every generated surface — recomputing only the baseline leaves compat-diff or prompts-sync red. Close with node scripts/diff-compat-config.mjs (Has blocking diff: NO), node scripts/check-prompts-sync.mjs, and node scripts/sync-claude-skills-mirror.mjs --check.

Isolating your own changes from a shared dirty workspace

A workspace can hold several people's uncommitted work at once, sometimes on a branch whose PR already merged. Committing there means either shipping their work or fighting the index. Move your files onto a clean branch instead.

  1. Split by ownership before anything else. git status --porcelain lists the whole workspace; git diff --stat -- <your paths> against git diff --stat -- . ':(exclude)<your paths>' separates yours from theirs. Trace each of your files back to the edit that produced it — a workspace is not yours just because you were the last one in it.
  2. Snapshot your files as a patch, not a stash. git diff -- <your paths> > /tmp/<name>.patch, then confirm the set with grep -E '^diff --git' /tmp/<name>.patch. A patch travels between worktrees; a stash is per-worktree and easy to strand.
  3. Base the new branch on the fetched origin/main. git fetch origin then git worktree add -b <new-branch> .worktrees/<dir> origin/main. Never base it on the current branch — if that branch's PR was squash-merged, its commits are already on main under new shas.
  4. Give the new worktree node_modules. A fresh worktree has none. Check scripts that import only node builtins still run, but sync-skill-versions.mjs and vitest die with MODULE_NOT_FOUND: ln -sfn <main-worktree>/node_modules node_modules.
  5. Apply, then check what is staged. git apply --check <patch> before git apply <patch>; git add only your paths; git status --porcelain | grep -v '^M ' must come back empty, because anything left unstaged or untracked silently misses the PR.
  6. Clean the original workspace with git restore <your paths> only. Not git checkout -- ., not git stash — either takes the other person's work with it. Their files must stay modified exactly as they were.
  7. Rule out a duplicate before starting. git worktree list can show a prunable entry whose branch overlaps yours; gh pr list --head <branch> --state all says whether it already merged. An overlapping branch is more often the precedent to extend than parallel work.

Run the repo's gates in the new worktree, not the original one — the new tree is the only one being pushed.

Command mapping

See references/command-catalog.md.

© TencentCloudBase, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/git-workflows of TencentCloudBase/CloudBase-AI-Toolkit.

  • SKILL.md
  • references/command-catalog.md
  • references/source-commands.md

Open the folder on GitHubat commit ea2c202

Compare with similar skills

Git Workflows next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Git Workflows compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Git Workflows this skillTencentCloudBase/CloudBase-AI-Toolkit1.1k—~3kAutomated safety check: PassMIT
Git WorkflowEliasOulkadi/shokunin114—~2.4kAutomated safety check: NotesMIT
Worktrunk Release Workflowmax-sixty/worktrunk8.9k—~6.9kAutomated safety check: PassCustom licence
ZCF Release AutomationUfoMiao/zcf6.1k—~3.4kAutomated safety check: PassMIT
Git Changes ReporterNo-Trade-No-Life/Yuan352—~1.2kAutomated safety check: PassMIT
Pypi ReleasealchemiststudiosDOTai/tunacode125—~2.2kAutomated safety check: PassMIT

Similar skills

  • Git Workflow

    EliasOulkadi/shokunin

    Automate the complete Git development workflow — create feature branches with conventional naming, atomic commits with conventional commit messages, interactive rebase, squash merges, PR body…

    114 GitHub stars~2.4k tokensUpdated 2 days ago
    DevelopmentAuto-check: notes
  • Worktrunk Release Workflow

    max-sixty/worktrunk

    Walks a maintainer through cutting a Worktrunk release: sync the release branch, pass two test gates, review the changes, then publish.

    8.9k GitHub stars~6.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.

    6.1k GitHub stars~3.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Git Changes Reporter

    No-Trade-No-Life/Yuan

    生成结构化 git 变更报告(JSON + Markdown)。使用此技能当用户提到"git 变更"、"commit 摘要"、"代码审查"、"release note"、"近期改动"、"每日摘要",或需要分析指定 commit 区间的代码变更。包含三元组结构(设计意图、核心代码、影响范围)的语义化报告,适用于代码审查、发布说明、团队同步、CI/CD 等场景。

    352 GitHub stars~1.2k tokensUpdated 5 mo ago
    DevelopmentAuto-check passed
  • Pypi Release

    alchemiststudiosDOTai/tunacode

    This skill should be used when releasing tunacode-cli to PyPI.

    125 GitHub stars~2.2k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • npm Package Publisher

    klaudworks/universal-skills

    Releases an npm package by committing changes, bumping the version with npm version, pushing the tag and checking the GitHub Actions publish.

    181 GitHub stars~923 tokensUpdated 8 mo ago
    DevelopmentAuto-check passed

More from TencentCloudBase/CloudBase-AI-Toolkit

All 49 skills in this repo
  • AI Model Nodejs

    TencentCloudBase/CloudBase-AI-Toolkit

    A skill your agent uses for Node.js backend AI via @cloudbase/node-sdk (=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration.

    1.1k GitHub starsUsed in 3 repos~5k tokens
    Auto-check passed
  • HTTP API Cloudbase

    TencentCloudBase/CloudBase-AI-Toolkit

    CloudBase official HTTP API client guide. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit.

    1.1k GitHub starsUsed in 3 repos~2.1k tokens
    Auto-check passed
  • Cloud API Recipe Authoring

    TencentCloudBase/CloudBase-AI-Toolkit

    Author or revise a cloud-api-operations recipe (config/source/skills/cloud-api-operations/references/recipes/).

    1.1k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Manage Local Skills

    TencentCloudBase/CloudBase-AI-Toolkit

    Analyze, standardize, validate, and sync locally maintained skills into agent skill directories with a skills CLI-aligned workflow.

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Cloudbase Agent Python

    TencentCloudBase/CloudBase-AI-Toolkit

    Build production-ready AI agent backends using the CloudBase Agent Python SDK — create agents with LangGraph/CrewAI/LlamaIndex, serve them via FastAPI with AG-UI protocol streaming +…

    1.1k GitHub starsUsed in 2 repos~2.9k tokens
    Auto-check: notes
  • Cloudbase

    TencentCloudBase/CloudBase-AI-Toolkit

    A skill your agent uses when you develop, design, build, deploy, debug, migrate, or troubleshoot CloudBase (腾讯云开发, 云开发, TCB, 微信云开发) projects — Web, 微信小程序, 小程序, uni-app, mobile (iOS, Android…

    1.1k GitHub starsUsed in 1 repo~4.7k tokens
    Auto-check passed

Categories

Questions about Git Workflows

What does Git Workflows do?

Reusable git delivery workflows derived from local slash commands (commit, push, PR, release notes, GitHub Actions failure triage with worktree-based fixes, and isolating your own changes from a…. Git Workflows is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit. Reusable git delivery workflows derived from local slash commands (commit, push, PR, release notes, GitHub Actions failure triage with worktree-based fixes, and isolating your own changes from a shared dirty workspace).

When should I use Git Workflows?

Git Workflows fits situations like: tasks that involve Git workflow; tasks that involve Changelog and release notes; tasks that involve Hooks and plugins.

How do I install Git Workflows in Claude Code?

Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill git-workflows -a claude-code`. Or copy the skill folder (skills/git-workflows in TencentCloudBase/CloudBase-AI-Toolkit) into .claude/skills/git-workflows in your project. Claude Code loads it when a task matches its description.

How do I install Git Workflows in Codex?

Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill git-workflows -a codex`. Or copy the skill folder (skills/git-workflows in TencentCloudBase/CloudBase-AI-Toolkit) into .agents/skills/git-workflows in your project. Codex loads it when a task matches its description.

Can I use Git Workflows in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill git-workflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/git-workflows, .gemini/skills/git-workflows, .github/skills/git-workflows and .opencode/skills/git-workflows in your project.

What does Git Workflows need to run?

Going by SKILL.md and its folder, Git Workflows needs the command-line tools its instructions call (git, node, gh, npm and pnpm).

Does Git Workflows access the network?

SKILL.md contains no URLs. Its commands use git, gh and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Git Workflows safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Git Workflows use?

Git Workflows is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Git Workflows use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.3k tokens, read only when the agent opens those files.

What are the alternatives to Git Workflows?

Skills that share tags, products or a category with Git Workflows: Git Workflow (EliasOulkadi/shokunin, 114 stars), Worktrunk Release Workflow (max-sixty/worktrunk, 8.9k stars), ZCF Release Automation (UfoMiao/zcf, 6.1k stars) and Git Changes Reporter (No-Trade-No-Life/Yuan, 352 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Git Workflows?

TencentCloudBase (a GitHub organization) maintains it in TencentCloudBase/CloudBase-AI-Toolkit, which has 1,132 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 6, 2026.

Source: TencentCloudBase/CloudBase-AI-Toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.