TL;DR
Auto-quarantine on main means broken code merges green and nobody finds out until production. Quarantine belongs on feature branches and triage jobs - main must fail loud.

```text
agent auto-quarantined tests on the main branch, so regressions merge green and nobody notices
```

## Steps
1. Confirm the damage. Check recent main-branch runs for quarantined-away failures, then check whether the corresponding code actually broke something downstream (bug reports, rollbacks, hotfixes).
   Expected: you find at least one real regression that merged green behind a quarantine.
2. Disable auto-quarantine on protected branches immediately. Quarantine automation should only run on feature branches and scheduled triage jobs, never on main.
   Expected: the next main failure blocks the merge instead of getting skipped.
3. Convert existing main-branch quarantines into tracked work. Every skipped test on main becomes a ticket or a fix PR, not a silent skip.
   Expected: a visible backlog where the hidden skips used to be.
4. Set up alerting for quarantine events on main. If anything ever quarantines on a protected branch again, the team hears about it within minutes.
   Expected: a notification rule, not just a policy doc.
5. Re-run main's suite whole and fix what surfaces.
   Expected: a red main that tells the truth, then a green main you can trust.

## Use this when
- the agent auto-quarantines on main or other protected branches
- regressions are merging green and discovered late
- quarantine was designed for triage but leaked into merge-blocking runs
- nobody can say what main's quarantine list currently hides

## Not for this skill when
- quarantine only runs on feature branches or nightly triage (already correct)
- the problem is branch protection config unrelated to quarantine
- main is red for genuine failures nobody quarantined (different problem)
- you are setting up quarantine for the first time

## Variant phrasings
- "auto quarantine on main branch hides regressions"
- "tests quarantined on master so broken code merges"
- "should quarantine run on protected branches"

## Why it happens
The same quarantine automation runs on every branch by default, and main looks like just another branch to the agent. On a feature branch, quarantining a flake unblocks the developer; on main, it unblocks a regression into production. The green check on main stops meaning "the code works" and starts meaning "nothing was allowed to fail".

## Edge cases
- Some teams legitimately quarantine on main during an incident to keep deploys moving; that needs an explicit, time-boxed exception with an owner, not the default.
- Release branches have the same problem as main; cover all protected branches, not just the default one.
- If main has been green-but-dirty for a while, the first honest run may be very red; plan the fix backlog before you flip the switch.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_UpXXY1rA4LTr2CKNCO2ysw
