breaking user-facing auth change and must not
be done as generic security hardening. Keep
`scripts/check-oauth-release-contract.sh` in CI/release verification.
- See `docs/RELEASE.md` for the full release handbook.
## Commit & Pull Request Guidelines
this repository.
## Repository Overview
SecOpsAgentKit is a collection of Claude Code skills for security operations, DevSecOps, and secure SDLC practices. The repository follows a skill-based architecture where each security
OAuth client ID by default
- Implements PKCE (Proof Key for Code Exchange) for security
- Opens browser for user authorization
- Runs local HTTP server to capture OAuth callback
- Exchanges authorization code
unbuilt features
- Marketing language or unverified capability claims
- Pricing information (lives on idun-group.com)
- Security vulnerabilities or exploit details
- API keys, secrets, or credentials (even example ones that look real)
- Content
code
- Run `golangci-lint run ./...` to check lint error
- Run `gosec -quiet ./...` to check security issue
- Run tests to ensure no impact on other code
- All comment and character literal
Repository Purpose
This repository helps users self-host STDIO MCP servers remotely using a secure, containerized approach. It provides infrastructure and tooling to deploy MCP servers accessible over HTTPS with
undoes it. `https` anywhere, `http` to **loopback** — the web platform's own set (W3C secure-contexts), so the exemption is a definition rather than a guess about what looks local
A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.
Where does it go?
At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.
What should it contain?
Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.
CLAUDE.md or AGENTS.md?
Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.