form of the `/publish` command |
| `remove-deadcode/` | NEW | Skill form of the `/remove-deadcode` command |
| `security-research/` | NEW | Team Mode security research audit: 3 vulnerability hunters + 2 PoC engineers |
| `codex
Remove unused code with LSP-verified safety + atomic commits. |
| `/security-research` | Run the Team Mode security-research audit with 3 vulnerability hunters and 2 PoC engineers. |
## OTHER CONTENTS
- `background-tasks.json` — Runtime state
equality between real artifacts, and observable runtime behavior such as parsing, routing, dispatch, state, security, and dynamic input propagation.
- Treat `tests/hashline/` as its own Bun package. Preserve its lockfile
versions stay lockstep:
1. **Feature/fix PRs:** add `changelog.d/ . .md` (`added` / `changed` / `fixed` / `removed` / `deprecated` / `security`) when the change belongs in the next release notes. See `changelog.d/README.md` and `CONTRIBUTING.md`. Fill
invoked directly.
Next.js documentation explicitly states: "Treat Server Actions with the same security considerations as public-facing API endpoints, and verify if the user is allowed to perform a mutation
Feature). `gh issue create` does not apply templates automatically.
Maintainer-directed work, urgent security fixes, release automation, and local or exploratory changes do not require a Ready issue.
## MCP Server
invoked directly.
Next.js documentation explicitly states: "Treat Server Actions with the same security considerations as public-facing API endpoints, and verify if the user is allowed to perform a mutation
issue, do not submit a competing one without maintainer agreement.
## Code Review Rules
For security reviews of Ruff and ty runtime changes, use the
[threat models](agents/references/threat-models.md) to assess trust
domain concept rather than a mechanical step extracted only to shorten the caller.
### Authentication Security (OWASP Mandatory)
- Any implementation, modification, or review involving authentication-related flows MUST comply with
src/utils/http/axios/` wraps Axios with:
- Token injection through interceptors.
- MD5 request signing for API security.
- Multi-tenant header support.
- Standard response unwrapping through the `result` field.
API functions usually follow this
validation.
- `npm run validate`: validate skill frontmatter, required sections, and schema rules.
- `npm run security:docs`: run safety checks for command, install, credential, and network guidance.
- `npm run test
critical commands, see the "Command Execution Guide" section in `/AGENTS.md` in the repository root.
## Security Guidelines
### Preventing Indirect Object References (IDOR)
Multi-tenant queries MUST be scoped — never trust user
tools` a
space-separated string, `metadata` scalars quoted, and a warning past 500 lines.
Security-scan new or substantially changed skills. Scanning uses
[Cisco AI Defense Skill Scanner](https://github.com
This repository is a monorepo. Each library lives in a subdirectory under `libs/`.
## Corridor security analysis
When Corridor's `analyzePlan` tool is available, create a plan and use the tool
relevant, test evidence, affected platforms/runtimes, and update `CHANGELOG.md` or docs for user-facing changes.
## Security & Configuration Tips
Do not commit secrets, local config, or generated worktree artifacts. Before release-facing