must load successfully; never silently execute against local configuration when its snapshot fails.
### 🔴 Shell Security: Defense-in-Depth
> Full spec: `docs/design/security.md`; output sanitization: `docs/design/sanitization.md`
Primary defense: **OS-level user isolation
that no longer exist
- Broken features (e.g., `spawn delete` references non-existent shell scripts)
- Security concerns that need separate review
- Architectural debt that would be too large
steer users to System Administrator. Only escalate for genuinely admin-scoped operations (security roles, org settings).
Run `python .github/evals/static_checks.py` after every change; it must stay green.
---
## Testing a Skill Change
back to you..." and summarize the key user stories.
---
## PHASE 4: Technical Architecture & Security
Say:
> "Now let's figure out the technical approach. Based on what we're building, here
Enforces client coding conventions. Use when writing, reviewing, or modifying React/TypeScript code in the client/ directory. Ensures proper use of Tailwind/shadcn UI components, path aliases, TypeScript interfaces, icon usage, platform-safe storage/git logic, and consistent design system rules.
demos in Segments 3 and 4 point Claude at these files to show security review, refactoring, PR review, and MCP memory in action. The files are staged to be found
helps the community and maintainer understand and evaluate the request.
### 4. Code quality and security are top priority
- Code quality and security MUST be treated as the highest priority
feeds the changelog automatically.
- **Everything else users would notice** (feature, improvement, fix, SDK release, security work): append an entry to `data/changelog.json` with date, community-readable title + summary (plain language
experiments/`, and the invariant or doc that rests on them links back as `evidence:`.
## Security — agents run autonomously, so the system must fail safe
- **Trust nothing by default.** Treat external
domain expertise that enriches any relevant conversation without being explicitly asked — code style, security patterns, brand voice, commit conventions. Use `true` (user-invocable) for multi-step workflows the user explicitly
A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.
Where does it go?
At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.
What should it contain?
Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.
CLAUDE.md or AGENTS.md?
Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.