drop, so a "reset pending" flag cleared by a drop would never clear again
## Security & Transparency
- All URLs and API endpoints as top-level constants - no dynamic URL construction
Affiliate signup if you don't have a lemlist account yet: <https://get.lemlist.com/skrtwnkxw60i>
## Security
- **NEVER display API keys, tokens, or secrets from `.env.local` in chat output.** Mask all credentials
changelog.d/ . .md`, where the section is one of `added`, `changed`, `deprecated`, `removed`, `fixed`, or `security` (see `changelog.d/README.md`). Any slug works in place of the number while the PR does
Split large changes into stacked PRs.
- Request review from at least one team member.
## Security
- Never commit secrets, tokens, or credentials. Use environment variables.
- Validate all external input at system
CLAUDIT-SEC — Claude Security Audit Tool
## Project Overview
CLAUDIT-SEC is a read-only, single-file security audit tool for macOS that inspects Claude Desktop and Claude Code configuration, scheduled
Overview
**OrchestKit** — Claude Code plugin for AI-assisted development with built-in best practices, security patterns, and quality gates.
For live component counts (skills / agents / hooks / per-session token cost
team or swarm, orchestrate bounded subagent work with the runtime's team
tools.
## Security
- NEVER ask user to write secrets in chat
- Instead: provide instructions where to store them securely
Plamen — Security Auditor
You are **Plamen**, an autonomous Web3 security auditing agent (v2.2.4).
Methodology files live under `~/.claude/rules/` and `~/.claude/prompts/` (or
`~/.codex/plamen/...` on Codex) — both are install-created symlinks into
every slice)
**Step 1 — Read the slice.** Read its objective, files, changes, security considerations, edge cases, expected output,
suggested tests, and suggested commit message (from your local development plan, with
keys
- View current configuration (with masked API keys)
- Reset configuration
- API keys are stored securely in your system's config directory
### doctor - Health Check
Check installation and configuration health:
```bash
A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.
Where does it go?
At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.
What should it contain?
Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.
CLAUDE.md or AGENTS.md?
Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.