MCAF: Source Control
Trigger On
- bootstrapping source-control policy
- tightening branch, merge, or PR rules
- documenting commit or release hygiene
- dealing with secrets-in-git or repository structure issues
Value
- produce a concrete project delta: code, docs, config, tests, CI, or review artifact
- reduce ambiguity through explicit planning, verification, and final validation skills
- leave reusable project context so future tasks are faster and safer
Do Not Use For
- CI/CD workflow design with no source-control policy change
- one-off git commands that do not alter repo policy
Inputs
- current branching and merge flow
- release strategy and versioning expectations
- secret-handling and repository-structure constraints
Quick Start
- Read the nearest
AGENTS.md and confirm scope and constraints.
- Run this skill's
Workflow through the Ralph Loop until outcomes are acceptable.
- Return the
Required Result Format with concrete artifacts and verification evidence.
Workflow
- Agree on merge and release strategy before scaling implementation.
- Enforce
MCAF-ARCH-001: the complete solution-owned backend, frontend, contracts, tests, infrastructure, and docs are versioned in one repository.
- Enforce
MCAF-REQ-001 at PR boundaries: changed behaviour traces through REQ-*, AC-*, ADR implementation tasks, tests, and evidence; document statuses match reality.
- Keep branch and PR rules explicit in-repo.
- Treat secrets in git history as a critical incident, not cleanup noise.
- Use concrete policy language, not hand-waving.
Deliver
- clear branch and merge strategy
- updated contribution or governance docs
- safer repository hygiene around commits, PRs, and secrets
Validate
- naming and merge rules are explicit
- release/versioning implications are documented where needed
- secret hygiene is treated as policy, not tribal knowledge
- repository policy does not permit solution-owned surfaces to drift into separate repositories
- PR policy rejects missing requirements/ADR implementation traceability or premature
Verified/Implemented status
Ralph Loop
Use the Ralph Loop for every task, including docs, architecture, testing, and tooling work.
- Brainstorm first (mandatory):
- analyze current state
- define the problem, target outcome, constraints, and risks
- generate options and think through trade-offs before committing
- capture the recommended direction and open questions
- Plan second (mandatory):
- write a detailed execution plan from the chosen direction
- list final validation skills to run at the end, with order and reason
- Execute one planned step and produce a concrete delta.
- Review the result and capture findings with actionable next fixes.
- Apply fixes in small batches and rerun the relevant checks or review steps.
- Update the plan after each iteration.
- Repeat until outcomes are acceptable or only explicit exceptions remain.
- If a dependency is missing, bootstrap it or return
status: not_applicable with explicit reason and fallback path.
Required Result Format
status: complete | clean | improved | configured | not_applicable | blocked
plan: concise plan and current iteration step
actions_taken: concrete changes made
validation_skills: final skills run, or skipped with reasons
verification: commands, checks, or review evidence summary
remaining: top unresolved items or none
For setup-only requests with no execution, return status: configured and exact next commands.
Load References
- read
references/source-control.md first
- open
references/naming-branches.md only when the task is specifically about branch naming
Example Requests
- "Define branch naming and merge rules for this repo."
- "Document how releases and component versions should work."
- "Tighten our source-control policy after a secrets leak."
1---2name: mcaf-source-control-33description: Set or refine source-control policy for repository structure, branch naming, merge strategy, commit hygiene, and secrets-in-git discipline. Use when bootstrapping a repo, tightening PR flow, or documenting branch and release policy.4---56# MCAF: Source Control78## Trigger On910- bootstrapping source-control policy11- tightening branch, merge, or PR rules12- documenting commit or release hygiene13- dealing with secrets-in-git or repository structure issues1415## Value1617- produce a concrete project delta: code, docs, config, tests, CI, or review artifact18- reduce ambiguity through explicit planning, verification, and final validation skills19- leave reusable project context so future tasks are faster and safer2021## Do Not Use For2223- CI/CD workflow design with no source-control policy change24- one-off git commands that do not alter repo policy2526## Inputs2728- current branching and merge flow29- release strategy and versioning expectations30- secret-handling and repository-structure constraints3132## Quick Start33341. Read the nearest `AGENTS.md` and confirm scope and constraints.352. Run this skill's `Workflow` through the `Ralph Loop` until outcomes are acceptable.363. Return the `Required Result Format` with concrete artifacts and verification evidence.3738## Workflow39401. Agree on merge and release strategy before scaling implementation.412. Enforce `MCAF-ARCH-001`: the complete solution-owned backend, frontend, contracts, tests, infrastructure, and docs are versioned in one repository.423. Enforce `MCAF-REQ-001` at PR boundaries: changed behaviour traces through `REQ-*`, `AC-*`, ADR implementation tasks, tests, and evidence; document statuses match reality.434. Keep branch and PR rules explicit in-repo.445. Treat secrets in git history as a critical incident, not cleanup noise.456. Use concrete policy language, not hand-waving.4647## Deliver4849- clear branch and merge strategy50- updated contribution or governance docs51- safer repository hygiene around commits, PRs, and secrets5253## Validate5455- naming and merge rules are explicit56- release/versioning implications are documented where needed57- secret hygiene is treated as policy, not tribal knowledge58- repository policy does not permit solution-owned surfaces to drift into separate repositories59- PR policy rejects missing requirements/ADR implementation traceability or premature `Verified`/`Implemented` status6061## Ralph Loop6263Use the Ralph Loop for every task, including docs, architecture, testing, and tooling work.64651. Brainstorm first (mandatory):66 - analyze current state67 - define the problem, target outcome, constraints, and risks68 - generate options and think through trade-offs before committing69 - capture the recommended direction and open questions702. Plan second (mandatory):71 - write a detailed execution plan from the chosen direction72 - list final validation skills to run at the end, with order and reason733. Execute one planned step and produce a concrete delta.744. Review the result and capture findings with actionable next fixes.755. Apply fixes in small batches and rerun the relevant checks or review steps.766. Update the plan after each iteration.777. Repeat until outcomes are acceptable or only explicit exceptions remain.788. If a dependency is missing, bootstrap it or return `status: not_applicable` with explicit reason and fallback path.7980### Required Result Format8182- `status`: `complete` | `clean` | `improved` | `configured` | `not_applicable` | `blocked`83- `plan`: concise plan and current iteration step84- `actions_taken`: concrete changes made85- `validation_skills`: final skills run, or skipped with reasons86- `verification`: commands, checks, or review evidence summary87- `remaining`: top unresolved items or `none`8889For setup-only requests with no execution, return `status: configured` and exact next commands.9091## Load References9293- read `references/source-control.md` first94- open `references/naming-branches.md` only when the task is specifically about branch naming9596## Example Requests9798- "Define branch naming and merge rules for this repo."99- "Document how releases and component versions should work."100- "Tighten our source-control policy after a secrets leak."