Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Guru Merge Task Pr

ASecurity

Merge one Ready task PR through a semantic live gate, or request an independent read-only review of an exact completed archive.

8 stars
0 votes
0 copies
0 views
Added 9/20/2026
businessbashgit

Works with

terminal

Security Analysis

A100/100

Scanned 9/20/2026

Install to Claude Code

$npx -y skills add castbox/guru-trellis --skill guru-merge-task-pr --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Guru Merge Task Pr?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Guru Merge Task Pr
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/castbox-guru-merge-task-pr/badge)](https://www.skillsdirectory.com/skills/castbox-guru-merge-task-pr)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: guru-merge-task-pr
description: Merge one Ready task PR through a semantic live gate, or request an independent read-only review of an exact completed archive.
---

# Guru Merge Task PR

Use this Skill only for the remote post-publication merge boundary. In workflow
mode consume `guru-finalize-task:ready_for_merge`; in standalone mode accept one
repo-bound PR identity plus the expected base/head branches. Before invocation,
author and review the exact PR-native Chinese `chore(merge)` subject/body plus a concrete Chinese summary,
then rebuild the same live evidence.

For a genuinely missing current review result on a completed archive, use the
independent `archived_review_request` profile described in the contract. First
decide whether a fresh review is necessary: a normally retired Branch Review
checkpoint alone never triggers it. This profile accepts only archive task_ref,
repo_ref, pr_number and expected_head_sha plus schema_version/profile/mode.
It does not accept a Publication hash or merge message and cannot merge.
Preview the exact committed archive/Ready PR facts, review the six dimensions
as archived-entry prerequisites, and invoke the same public wrapper with
`route.typed_exit=review_refresh_required` or `merge_blocked`. No merge
confirmation is requested for this read-only operation. Successful output
contains only task_ref, the current archive HEAD as branch_review_commit, and
the exact title/body snapshot digest. Workflow runs its distinct Architecture
branch_review stage before Branch Review consumes that seed as archived_review.

Read [references/contract.md](references/contract.md), run the preview, and
perform the semantic gate. A current task-work content finding returns
`phase2_reentry_required` without merge confirmation or remote mutation. Only a
fully passed merge route asks once for the exact merge action. After that
confirmation, call the original and sole public Happy Path entry:

```bash
scripts/invoke.sh --input <public-input.json> \
  --review-input <semantic-review.json> --json
```

It records the already-completed review, reuses one pre-merge snapshot, performs
one expected-head merge, captures one post-merge snapshot, projects exactly one
of `merged`, `merge_blocked`, `phase2_reentry_required`, or
`closure_mismatch`, and retires the private gate/body state before returning.
On exact recovery, rerun the same `scripts/invoke.sh` call with the same input
and semantic review. It resolves the package-owned current gate, or reconstructs
an exact already-merged terminal result from live facts without repeating the
mutation.

`record-task-pr-merge`, `check-task-pr-merge`, `execute-task-pr-merge`, and
their wrappers remain package-private diagnostic and bounded recovery commands.
`scripts/invoke.sh` accepts only the current `--review-input` transaction shape.
An already persisted terminal output is recovered only after read-only live
revalidation of the exact merge SHA, two parents, reviewed subject/body, remote
base ref and closure facts; recovery never repeats the merge mutation.

`phase2_reentry_required` is reserved for an AI-reviewed current-scope finding
that requires changing the archived task's content. External CI, policy,
permission, provider, mergeability, or other non-task blockers remain
`merge_blocked`.

Fail closed on stale head, base/head branch drift,
Draft/Open/readiness drift, unknown policy, incomplete GitHub response, or
unmapped output. Never enter Phase
0, sync a base, update/rebase the PR branch, close Issues directly, synchronize
local `main`, or clean task resources.

For an explicit independent manual operation after an automatic stop, read
`.trellis/workflow.md#manual-gitgithub-operations` (Manual Git/GitHub Operations).
That global boundary does not relax this Skill's entry or completion contract.

Known preview and invocation errors retain a package-owned error code, field,
and credential-safe remediation. An input diagnostic is not a Skill exit or a
review result. When the current complete input and semantic review support a
blocked route, use the existing `merge_blocked` exit with its concrete reason;
never relabel a metadata-only problem as `phase2_reentry_required`.

Do not require a Branch Review checkpoint on the normal `ready_for_merge`
path: its owner retires it after a successful public projection. For a genuine
missing or stale required review result, follow the original-owner re-entry
conditions in [references/contract.md](references/contract.md#closeout-identity-and-review-re-entry).
Neither checkpoint absence nor an old diagnostic authorizes a new pass,
private-state lookup, unconditional review request, or merge mutation.

Workflow-mode `ready_for_merge` requires Finalizer's
`publication_body_sha256`. Merge compares it with the exact bytes from its first
live PR read before deriving closing keywords, reading their Issues, or
performing the merge mutation. A mismatch fails closed; the caller must re-enter
fresh Publication and Finalizer preparation. Merge does not expose a new
reprepare exit. Standalone merge neither accepts nor synthesizes this
Publication authority.

Merge derives the closure verification set only from closing keywords in the
live PR body. It performs no Issue read before merge. After merge, it reads only
those named Issues and verifies GitHub's automatic effect; a body without closing
keywords requires no Issue reads.

If required CI is still pending, run exactly one repo/PR/expected-head-bound
watcher:

```bash
scripts/watch-task-pr-checks.sh --repo <owner/repo> --pull-request <number> \
  --expected-head <sha> --json
```

It returns `checks_succeeded`, `checks_failed`, `checks_pending_timeout`, or
`head_changed`. These are deterministic CI facts only; the Merge AI still owns
readiness and route judgment. Do not combine it with `gh run watch`,
`gh pr checks --watch`, or an Agent polling loop.

Attribution

castboxcastbox
View sourceMore from castbox →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Solution Architect

Designs system architecture, component specifications, and technical integration strategy. Use when: designing solutions, system architecture, technology stack, or integration approaches.

192 votes

Akorchak:Venture Assessment

Generate a comprehensive VC investment assessment report for a company

72 votes

Stock Analysis

Analyze stocks and cryptocurrencies using Yahoo Finance data. Supports portfolio management (create, add, remove assets), crypto analysis (Top 20 by market cap), and periodic performance reports (daily/weekly/monthly/quarterly/yearly). 8 analysis dimensions for stocks, 3 for crypto. Use for stock analysis, portfolio tracking, earnings reactions, or crypto monitoring.

6511 votes

Just Fucking Cancel

Find and cancel unwanted subscriptions by analyzing bank transactions. Detects recurring charges, calculates annual waste, and helps you cancel with direct URLs and browser automation. Use when: 'cancel subscriptions', 'audit subscriptions', 'find recurring charges', 'what am I paying for', 'save money', 'subscription cleanup', 'stop wasting money'. Supports CSV import (Apple Card, Chase, Amex, Citi, Bank of America, Capital One, Mint, Copilot) OR Plaid API for automatic transaction pull. Out...

6511 votes

Telegram Compose

Compose rich, readable Telegram messages using HTML formatting via direct Telegram API. Use when: (1) Sending any Telegram message beyond a simple one-line reply, (2) Creating structured messages with sections, lists, or status updates, (3) Need formatting unavailable via Clawdbot's Markdown conversion (underline, spoilers, expandable blockquotes, user mentions by ID), (4) Sending alerts, reports, summaries, or notifications to Telegram, (5) Want professional, scannable message formatting wit...

6511 votes
View all in business →