Make /git-agent:ship-autonomous immune to claude-code#43809 — chain branch-agent, commit-agent, and pr-agent by Reading their SKILL.md files instead of gated Skill-tool calls, keeping disable-model-invocation: true (the guard against unsolicited git mutations) fully intact.
Read and implement all steps in the plan at docs/plans/fix-ship-autonomous-skill-chaining.md — Fix ship-autonomous skill chaining (claude-code#43809). Verify against the plan's Tests, Verification, and Acceptance Criteria before reporting done. If everything passed, mark completion in docs/plans/fix-ship-autonomous-skill-chaining.md — tick each step's [x] marker and each criterion's - [x], set status: completed — and re-render the HTML from the spec. If any check failed, leave status: in-progress and say which.
More ways to run this plan — goal & workflow prompts, file path
Achieve this goal: Fix ship-autonomous skill chaining (claude-code#43809). The plan at docs/plans/fix-ship-autonomous-skill-chaining.md describes one approach — use it as reference, but optimize for the outcome. Fan out across parallel subagents where that serves the outcome. Verify against the plan's Tests, Verification, and Acceptance Criteria before reporting done. If everything passed, mark completion in docs/plans/fix-ship-autonomous-skill-chaining.md — tick each step's [x] marker and each criterion's - [x], set status: completed — and re-render the HTML from the spec. If any check failed, leave status: in-progress and say which.
Run a workflow to implement the plan at docs/plans/fix-ship-autonomous-skill-chaining.md — Fix ship-autonomous skill chaining (claude-code#43809). Brief subagents with the plan file at docs/plans/fix-ship-autonomous-skill-chaining.md. Reserve a final verification phase for the lead agent, not a subagent. Verify against the plan's Tests, Verification, and Acceptance Criteria before reporting done. If everything passed, mark completion in docs/plans/fix-ship-autonomous-skill-chaining.md — tick each step's [x] marker and each criterion's - [x], set status: completed — and re-render the HTML from the spec. If any check failed, leave status: in-progress and say which.
fix-ship-autonomous-skill-chaining.html
docs/plans/fix-ship-autonomous-skill-chaining.html
docs/plans/fix-ship-autonomous-skill-chaining.md
Context
The story behind this plan — what prompted the work and why it matters now.
claude-code#43809 reports that disable-model-invocation: true blocks every model-driven Skill-tool invocation — not just unsolicited auto-triggering. Any nested call fails with Error: Skill <name> cannot be used with Skill tool due to disable-model-invocation , even when the user explicitly requested the parent workflow. The issue was filed against Claude Code 2.1.92 and auto-closed as inactive — the behavior was never fixed.
The flag is deliberate in git-agent: commit-agent , pr-agent , branch-agent , and ship stage all changes and mutate git state, so they are command-only — explicit /git-agent:<name> invocation, never fuzzy intent matching. Keeping that guard is a hard requirement of this plan.
The exposure: ship-autonomous chains its pipeline by instructing Skill-tool invocations of three flagged skills at five sites — Step 2 branch-agent (line 89), Step 3 commit-agent (line 99), Step 4 pr-agent (line 109), and the autofix loop's commit references (lines 229 and 238). The user typed /git-agent:ship-autonomous , not the child commands, so every nested call is model-driven and refusable. The plain ship skill and the agent-commit background agent are immune only because they inline duplicate copies of the same workflows — a maintenance tax this plan avoids.
The fix: Read-based chaining. The flag gates only the Skill tool — SKILL.md files are plain markdown on disk, and ${CLAUDE_PLUGIN_ROOT} expands inside skill content at load time (verified empirically this session). Reading keeps a single source of truth. One behavioral consequence: under Skill-tool chaining each child ran under its own allowed-tools ; under Read-chaining the parent's list governs — so ship-autonomous must absorb Bash(date *) for branch-agent's auto-naming. (Branch-agent's model: Haiku pin likewise no longer applies — inlined steps run on the session model.)
Files that change
Every file this plan touches, and what happens to each one.
kit/plugins/git-agent/skills/ship-autonomous/SKILL.mdmodified swap 5 Skill-tool calls to Read chaining; update allowed-toolskit/plugins/git-agent/CHANGELOG.mdmodified add v3.10.7 entry.claude-plugin/marketplace.jsonmodified bump git-agent 3.10.6 → 3.10.7tests/plugins/test-ship-autonomous-read-chaining.shnew chaining-contract smoke test
Steps
The step-by-step work, in order — each step says what to do, why it matters, and how to check it worked.
Tests
The tests that prove the change does what it promises.
Definition of done
The plan counts as done when every statement below is true — check each one off as you verify it.
Final check
One last pass to confirm the whole change works end to end.
Run the smoke test and the metadata checks, then (optionally) exercise the live pipeline:
bash tests/plugins/test-ship-autonomous-read-chaining.sh — every check prints PASS, exit code 0.
jq -r '.plugins[] | select(.name=="git-agent").version' .claude-plugin/marketplace.json prints 3.10.7 ; the same query against git show origin/main:.claude-plugin/marketplace.json prints 3.10.6 .
git diff --name-only origin/main lists exactly: the ship-autonomous SKILL.md, the git-agent CHANGELOG, .claude-plugin/marketplace.json , the new test script, this plan file, and the auto-rebuilt docs/plans/index.html .
Live smoke (required — the static test cannot catch runtime failure modes like a STOP-halt mid-pipeline or an unexpanded ${CLAUDE_PLUGIN_ROOT} ): run claude --plugin-dir ./kit/plugins/git-agent on a scratch branch with a trivial change, invoke /git-agent:ship-autonomous , and confirm Steps 2–4 Read the child SKILL.md files — no "cannot be used with Skill tool due to disable-model-invocation" error — and the pipeline reaches PR creation without halting at any inlined child STOP. Re-run once on a branch that already has an OPEN PR and confirm the pipeline continues to CI watch instead of halting.
Commit all changed files together — repo convention ships the plan file with the plugin change.
Wrapping up
Three gates that must all pass before this plan is marked completed.
Completion Report
No items to report — all requirements met.