Rules
## When to Use Subagents
- Use a subagent for tasks that require focused expertise (security audit, performance analysis, test generation).
- Use a subagent when the main task would exceed
failing tests
- Make breaking changes to GA'd APIs without explicit approval
- Turn off security checks or introduce security vulnerabilities
- Suggest third-party alternatives to Azure SDK packages in official
correction in these generated files.
- If the upstream source is inaccessible, prepare ordinary, non-security feedback through the README's feedback process with the endpoint/method or schema, expected behavior
already exists on `stable`
- Correctness, data-loss, crash, hang, deadlock, and resource-leak fixes
- Security fixes, including dependency bumps that address a known vulnerability
- Fixes for regressions introduced
link, a
script, a transcript — and this skill builds a complete, validated,
security-scanned agent skill with functional code, its own eval suite, and a
cross-platform installer.
## Activation
Invoke
Describe your changes" section with a clear summary of what changed and why.
## Security and environment notes
- Do not commit secrets, caches, or generated model artifacts.
- Some workflows require optional
Build multi-platform chat bots with Chat SDK (`chat` npm package). Use when developers want to scaffold a bot with create-chat-sdk, build a Slack, Teams, Google Chat, Discord, Telegram, GitHub, Linear, or WhatsApp bot, handle mentions, direct messages, subscribed threads, reactions, slash commands, cards, modals, files, or AI streaming, set up webhook routes or multi-adapter bots, send rich cards or streamed AI responses to chat platforms, or build a custom adapter or state adapter.
stop()` from
the React side aborts the handler's iterator.
## Authentication
`getUser` is the **security boundary**. Every request comes from a
browser with no Slack-style platform signature
documentation-site changes. Update `CHANGELOG.md` and target-specific docs when behaviour changes.
## Security & Configuration Tips
Do not commit secrets, local `.env` files, or generated session memory. Keep project-specific template
just type `/triage` in Claude Code. Hard safety rails (test-passing gates, no security-sensitive auto-merges, no scope-changing merges, Codex sign-off required on closures) live inside `triage.md
fast, do/don't version.
## What this is
open·kritt is an AI-driven security vulnerability scanner. It's a **polyglot
monorepo** of cooperating services:
| Path | What | Stack |
| ---------------- | --------------------------------------------- | ----------------------------- |
| `frontend
server runtime paths used by MCP `stdio`.
- Use `apply_patch` for manual file edits.
## Security
- Default transport is local `stdio`. HTTP is optional and requires auth token.
- Never expose unauthenticated
Proxy: Check your origin server logs
### Cookies not persisting
- Must be HTTPS (cookies have `Secure` flag)
- Check `SameSite=Strict` compatibility with your frontend
- Cookies are valid for 1 hour after