compression for a single command.
## Quality Bar
- Zero clippy warnings, all tests pass
- Security: PathJail, Shell Allowlist, bounded_lock, no hardcoded secrets
- No mock data, no placeholders, no stubs
## Quality
fails.
- Classpath detection must be gated on runtime evidence, not just `Class.forName()` success.
### 6. Security: Every mutating surface requires explicit authorization
- **Every mutating/admin endpoint requires explicit authentication and authorization.** Default
check transport type or access HttpContext
if (Environment.GetEnvironmentVariable("ASPNETCORE_URLS") != null) { }
var httpContext = _httpContextAccessor.HttpContext;
```
### Security Best Practices
1. Always use HTTPS in production
2. Implement least privilege RBAC
version or a transport type also
counts).
- Dependency bumps require a concrete reason (security, bug, needed feature) — see
[DEPENDENCY_POLICY.md](DEPENDENCY_POLICY.md). Don't bump a dependency just because a newer version
Core Principles
1. **TypeScript-First**: Always use TypeScript with proper types from Payload
2. **Security-Critical**: Follow all security patterns, especially access control
3. **Type Generation**: Run `generate:types` script
checker and effective budget come from main, not the PR. Keep default CODEOWNERS.
## Security requirements
- Never commit, print, or upload API keys, bearer tokens, cloud credentials,
private keys, webhook secrets
Repository instructions
## Corridor security analysis
When Corridor's `analyzePlan` tool is available, create a plan and use the tool to analyze it before generating or modifying code. Apply the resulting
whole diff and run on every invocation of the `/review-areas` skill.
| Concern | Reviewer |
|---|---|
| Security: secrets, TLS/crypto, redaction, deserialization safety | `security-reviewer` |
| Public API / SemVer | `api-stability-reviewer` |
| Async/threading hygiene | `async
first lookup. Without knowing about a concrete type, the deserializer can't materialize it. **Security:** when deserializing untrusted BSON into open polymorphic types, an attacker-controlled `_t` value can drive
into a surrounding engineering project.
This ordering does not waive higher-priority safety or security requirements. Keep validation that is necessary at real external boundaries, such as user input
Review Guidelines
When reviewing pull requests, prioritize findings that can cause correctness bugs, regressions, security or privacy issues, release failures, broken CI, broken packaging, or misleading evidence. Treat these
that should
influence LLVM's hot and cold decisions
* **Verification-only:** important correctness, recovery, security, or rare
behavior that the final candidate must pass without making it hot
* **Intentional exclusion
obvious invariant, or run the right proof. The native Node-API architecture and security model are documented in `sdk/NAPI.md`.
## Start from the correct owner
The SDK has two WebAssembly surfaces