supply it via the `unlock` tool (see "Unlock tool" below)
- Executes shell commands with security hardening
- Returns plain text or JSON responses from CLI
**2. API Interface (Organization Administration)**
- Makes
word processing logic
- `utils/schema.ts` - Core data structure
- `utils/supabase/client.ts` - Database client setup
- `next.config.ts` - Headers, caching, security config
## Important Notes
- Always use Bun commands, not npm
- API route has 60s max duration
tool. Do not add it back to `_TOOL_REGISTRY` without an explicit security review.
## Security invariants
- Do-files may execute only from the configured working directory or the
Stata
every failure**: You are the ONLY developer. Every test failure, CI failure, and security scan failure is YOUR responsibility. NEVER use the words "unrelated", "pre-existing", or "not our changes
analysis agent that runs as a Claude Code plugin. It scans local projects for security vulnerabilities across OWASP 2025 Top 10 and CWE Top 25 categories, then generates prioritized reports
Zero-configuration discovery via mDNS/DNS-SD (`_lad-a2a._tcp.local`), well-known endpoints (`/.well-known/lad/agents`), and DHCP
- Security model assumes local networks are hostile by default
## Common Commands
### Reference Implementation
```bash
cd reference
surface is default-deny** (issue #145): the daemon binds `0.0.0.0` on purpose, so the security boundary is the pairing token enforced at one chokepoint per daemon (`bridge/src/http-auth-gate.ts` / `DaemonServer.httpAccessResponse`). An unauthenticated
patterns: pick one, name the discarded, flag cleanup.
Break convention only for correctness or security, named.
## R8 Evidence
Load-bearing claims on decision surfaces (report, PR, humanpending.md)
carry [executed]|[inspected
webToken` is already accepted, which is what makes the door URL session-independent; the security posture is unchanged (same-user local processes could already read this data, hostile web pages
repository, load the project skill from `skills/wireshark-traffic-analysis/SKILL.md`.
Use it for:
- `pcap` and `pcapng` analysis
- security hunting and incident response
- network troubleshooting
Prefer the skill playbooks, evidence rubric, and report template
resources during development
## Current Implementation Status
**✅ Completed:**
- GitHub App Manifest setup and OAuth flow
- Secure credential storage in Durable Objects with AES-256-GCM encryption
- Basic webhook processing infrastructure with
Nemesis Agent
## What This Is
**NEMESIS** is an iterative deep-logic security audit agent for [Claude Code](https://docs.anthropic.com/en/docs/claude-code). It orchestrates two sub-agents in an alternating feedback loop
compromised container can reach
every tenant's documents; db-per-tenant stays the security default. See
`docs/spec/runtime/storage.md`. Unset (the default) is a full no-op.
- The manager should also inject
installed persona's responses actually honor
kernel precedence (correctness > voice, no capitulation openers, security authorization
gates, etc. — `skills/_kernel/`) across 10 behavioral probes (`probes.json`). This is a
small honest smoke battery
A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.
Where does it go?
At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.
What should it contain?
Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.
CLAUDE.md or AGENTS.md?
Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.