Prismor Security — CLAUDE.md
This project is the Prismor security package for AI coding agents.
## Prismor Runtime Protection
This repo has Prismor hooks enabled. The hook dispatcher at `prismor/runtime/cli.py` monitors tool
infra/hf-proxy` (`hf.meridiona.com`) was an unauthenticated reverse proxy to huggingface.co. Its header carried a thoughtful `SECURITY:` block about cache-key poisoning and auth headers leaking into a shared cache; it never
Skills should refuse destructive or malicious use cases
- Focus on educational value and professional security workflows
- Keep descriptions "pushy" — include all relevant trigger phrases so the skill activates when needed
developer`, `code-reviewer`, `test-reviewer` → **sonnet** (cost-efficient for mechanical tasks)
- `security-reviewer` → **opus** (reasoning-heavy; the one role where Opus pays for itself)
On dispatch paths (`/ai-sdlc execute`, `/ai-sdlc
always exempt, so the default local experience is unchanged. CORS is **not** the security boundary (it only restrains browsers); the token is. Frontend carries it via `Authorization: Bearer` (and `?token
criteria, margin, or demand (a HIPAA buyer; a 200-engineer org that triggers a security review) — and even then, never the first cut.
- **Same expected outcome + different success criteria
subissues for tasks >500 lines
- End with handoff notes before context compresses
---
*Language rules, security requirements, and testing guidelines are in `.chainlink/rules/` and auto-injected based on detected project languages
flaky tests)
- [ ] Does the test suite fail if your new logic is broken?
### Security and risk assessment
- No `eval()`, `exec()`, or `pickle` on user-controlled input
- Proper exception handling
build artifacts (`_build/`, `.mooncakes/`) or `node_modules/` — `.gitignore` covers them.
- If a skill gains security-sensitive detail, move it to chezmoi-local and remove from this repo
Falls back to `~/.claude/ide/` (legacy location)
- **Path Handling**: All paths normalized via `normalizePath()` utility
- **Security**: File operations restricted to vault boundaries
- **Multi-Vault Support**: Each vault needs unique HTTP port
GLOBALLY`: Emergency kill switch
- `CSP_ALLOWED_DOMAINS`: Comma-separated list of domains for Content-Security-Policy (default: `https://*.online.tableau.com,https://*.tableau.com`)
## Testing Strategy
### Unit Tests (`vitest.config.ts`)
- Located in `src/` alongside
Larger teaching-library skills used during Lab 6 (api-documentation-skill, spring-boot-skill, security-review-skill, plus a plugin example).
- Skills cover Java modernization, Spring scaffolding, security reviews, documentation
password prompt returns hours after granting, same app version | Claude Code's ~8h `security add-generic-password -U` rewrite resets the item's partition list to `apple-tool:`, silently wiping
A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.
Where does it go?
At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.
What should it contain?
Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.
CLAUDE.md or AGENTS.md?
Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.