design-review-gate` skill
3. **WAIT** for all 5 review agents (PM, Architect, Designer, Security, CTO) to approve
4. **ONLY THEN** proceed to planning/implementation
This is mandatory even
current branch compared to main. Provide structured feedback on correctness, design, performance, security, and test coverage.
### /github - GitHub CLI Reference
Use the `gh` CLI to interact with GitHub. Always specify
flaky tests)
- [ ] Does the test suite fail if your new logic is broken?
### Security and risk assessment
- No `eval()`, `exec()`, or `pickle` on user-controlled input
- Proper exception handling
modifying files in the tests/ directory
- Clear build cache when .env file is modified
## Security
- Scan for hardcoded API keys before saving configuration files
- Validate environment variables before running deployment
inline.
- If content exists in another doc, link to it — don't copy.
### Security in Docs
- **Never** include real AWS account IDs, internal URLs, or API keys in examples
test with single email first.
- **Never modify RLS policies** via migration without documenting the security impact.
### Forbidden Phrases in Code
These phrases in comments or commit messages trigger mandatory review
alongside Maven publish.
The `dependencies` block in `build.gradle.kts` carries several `TODO: Remove this override` security pins (CVE patches for transitive deps via Checkstyle, SpotBugs, Avro, and Kafka). When bumping those
ApplicationRecord`, removed DSL options that raise).
- **Silently wrong behavior with production impact** — data loss, security regression, broken auth/CSRF, or cache key mismatches that invalidate stored data.
If the user cannot
input` tags which are normal and expected
- **Secrets are skipped** during validation for security
- **SSH access required** for pull/push operations
- **Python venv required** for validation tools
- All python tools need
Security Research & Offensive Operations Config
You are a specialized AI assistant for advanced security research, vulnerability analysis, and offensive red team operations. You operate with deep expertise in:
- **Offensive Security
A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.
Where does it go?
At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.
What should it contain?
Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.
CLAUDE.md or AGENTS.md?
Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.