跳到主要内容
知仓学习社ZHICANG

git-worktree-manager

Run parallel feature work safely with Git worktrees. Standardizes branch isolation, port allocation, environment sync, and cleanup so each worktree …

读凭据执行命令写文件严重 11 · 高危 2alirezarezvani/claude-skills

它会碰到什么

扫了多少6 个文本文件,25 KB
它会碰到什么读凭据执行命令写文件
命中总数14 处
命中统计严重 11 · 高 2 · 中 1 · 低 0
逐条看命中(13 条严重或高危)
  • 严重 README.md:23cred-paths
    - `scripts/worktree_manager.py`: create/list-prep workflow, deterministic ports, `.env*` sync, optional dependency install
  • 严重 references/docker-compose-patterns.md:28cred-paths
    ## Pattern 2: `.env` Driven Ports
  • 严重 references/docker-compose-patterns.md:30cred-paths
    Use compose variable substitution and write worktree-specific values into `.env.local`.
  • 严重 references/docker-compose-patterns.md:42cred-paths
    Worktree `.env.local`:
  • 严重 scripts/worktree_manager.py:7cred-paths
    - .env file sync from main repo
  • 严重 scripts/worktree_manager.py:23cred-paths
    ENV_FILES = [".env", ".env.local", ".env.development", ".envrc"]
  • 严重 scripts/worktree_manager.py:23cred-paths
    ENV_FILES = [".env", ".env.local", ".env.development", ".envrc"]
  • 严重 scripts/worktree_manager.py:23cred-paths
    ENV_FILES = [".env", ".env.local", ".env.development", ".envrc"]
  • 严重 SKILL.md:22cred-paths
    - Copy local environment files (`.env*`) from main repo to new worktree
  • 严重 SKILL.md:105cred-paths
    - Copy `.env*` files
  • 严重 SKILL.md:140cred-paths
    3. `.env` files copied successfully (if present in source repo).
  • scripts/worktree_cleanup.py:38exec-spawn
    return subprocess.run(cmd, cwd=cwd, text=True, capture_output=True, check=check)
  • scripts/worktree_manager.py:49exec-spawn
    return subprocess.run(cmd, cwd=cwd, text=True, capture_output=True, check=check)

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Git Worktree Manager

Tier: POWERFUL

Category: Engineering

Domain: Parallel Development & Branch Isolation

Overview

Use this skill to run parallel feature work safely with Git worktrees. It standardizes branch isolation, port allocation, environment sync, and cleanup so each worktree behaves like an independent local app without stepping on another branch.

This skill is optimized for multi-agent workflows where each agent or terminal session owns one worktree.

Core Capabilities

  • Create worktrees from new or existing branches with deterministic naming
  • Auto-allocate non-conflicting ports per worktree and persist assignments
  • Copy local environment files (.env*) from main repo to new worktree
  • Optionally install dependencies based on lockfile detection
  • Detect stale worktrees and uncommitted changes before cleanup
  • Identify merged branches and safely remove outdated worktrees

When to Use

  • You need 2+ concurrent branches open locally
  • You want isolated dev servers for feature, hotfix, and PR validation
  • You are working with multiple agents that must not share a branch
  • Your current branch is blocked but you need to ship a quick fix now
  • You want repeatable cleanup instead of ad-hoc rm -rf operations

Key Workflows

1. Create a Fully-Prepared Worktree

  1. Pick a branch name and worktree name.
  2. Run the manager script (creates branch if missing).
  3. Review generated port map.
  4. Start app using allocated ports.
python scripts/worktree_manager.py \
  --repo . \
  --branch feature/new-auth \
  --name wt-auth \
  --base-branch main \
  --install-deps \
  --format text

If you use JSON automation input:

cat config.json | python scripts/worktree_manager.py --format json
# or
python scripts/worktree_manager.py --input config.json --format json

2. Run Parallel Sessions

Recommended convention:

  • Main repo: integration branch (main/develop) on default port
  • Worktree A: feature branch + offset ports
  • Worktree B: hotfix branch + next offset

Each worktree contains .worktree-ports.json with assigned ports.

3. Cleanup with Safety Checks

  1. Scan all worktrees and stale age.
  2. Inspect dirty trees and branch merge status.
  3. Remove only merged + clean worktrees, or force explicitly.
python scripts/worktree_cleanup.py --repo . --stale-days 14 --format text
python scripts/worktree_cleanup.py --repo . --remove-merged --format text

4. Docker Compose Pattern

Use per-worktree override files mapped from allocated ports. The script outputs a deterministic port map; apply it to docker-compose.worktree.yml.

See [docker-compose-patterns.md](references/docker-compose-patterns.md) for concrete templates.

5. Port Allocation Strategy

Default strategy is base + (index * stride) with collision checks:

  • App: 3000
  • Postgres: 5432
  • Redis: 6379
  • Stride: 10

See [port-allocation-strategy.md](references/port-allocation-strategy.md) for the full strategy and edge cases.

Script Interfaces

  • python scripts/worktree_manager.py --help
  • Create/list worktrees
  • Allocate/persist ports
  • Copy .env* files
  • Optional dependency installation
  • python scripts/worktree_cleanup.py --help
  • Stale detection by age
  • Dirty-state detection
  • Merged-branch detection
  • Optional safe removal

Both tools support stdin JSON and --input file mode for automation pipelines.

Common Pitfalls

  1. Creating worktrees inside the main repo directory
  2. Reusing localhost:3000 across all branches
  3. Sharing one database URL across isolated feature branches
  4. Removing a worktree with uncommitted changes
  5. Forgetting to prune old metadata after branch deletion
  6. Assuming merged status without checking against the target branch

Best Practices

  1. One branch per worktree, one agent per worktree.
  2. Keep worktrees short-lived; remove after merge.
  3. Use a deterministic naming pattern (wt-<topic>).
  4. Persist port mappings in file, not memory or terminal notes.
  5. Run cleanup scan weekly in active repos.
  6. Use --format json for machine flows and --format text for human review.
  7. Never force-remove dirty worktrees unless changes are intentionally discarded.

Validation Checklist

Before claiming setup complete:

  1. git worktree list shows expected path + branch.
  2. .worktree-ports.json exists and contains unique ports.
  3. .env files copied successfully (if present in source repo).
  4. Dependency install command exits with code 0 (if enabled).
  5. Cleanup scan reports no unintended stale dirty trees.

References

  • [port-allocation-strategy.md](references/port-allocation-strategy.md)
  • [docker-compose-patterns.md](references/docker-compose-patterns.md)
  • [README.md](README.md) for quick start and installation details

Decision Matrix

Use this quick selector before creating a new worktree:

  • Need isolated dependencies and server ports -> create a new worktree
  • Need only a quick local diff review -> stay on current tree
  • Need hotfix while feature branch is dirty -> create dedicated hotfix worktree
  • Need ephemeral reproduction branch for bug triage -> create temporary worktree and cleanup same day

Operational Checklist

Before Creation

  1. Confirm main repo has clean baseline or intentional WIP commits.
  2. Confirm target branch naming convention.
  3. Confirm required base branch exists (main/develop).
  4. Confirm no reserved local ports are already occupied by non-repo services.

After Creation

  1. Verify git status branch matches expected branch.
  2. Verify .worktree-ports.json exists.
  3. Verify app boots on allocated app port.
  4. Verify DB and cache endpoints target isolated ports.

Before Removal

  1. Verify branch has upstream and is merged when intended.
  2. Verify no uncommitted files remain.
  3. Verify no running containers/processes depend on this worktree path.

CI and Team Integration

  • Use worktree path naming that maps to task ID (wt-1234-auth).
  • Include the worktree path in terminal title to avoid wrong-window commits.
  • In automated setups, persist creation metadata in CI artifacts/logs.
  • Trigger cleanup report in scheduled jobs and post summary to team channel.

Failure Recovery

  • If git worktree add fails due to existing path: inspect path, do not overwrite.
  • If dependency install fails: keep worktree created, mark status and continue manual recovery.
  • If env copy fails: continue with warning and explicit missing file list.
  • If port allocation collides with external service: rerun with adjusted base ports.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 26,030
本站分层T1
该仓技能数846
原文件路径engineering/skills/git-worktree-manager/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 846 个技能

同名技能的其他版本

有 2 个不同仓库或目录里都有叫 git-worktree-manager 的技能。它们内容并不相同,别混用: