finding whose severity was mis-assigned to something that is really a security or data-integrity defect) — anything else is a `[DEVIATION]`, not a judgment call.
Skill discovery: no command
outcomes.
### Frontends
- Use Typescript and shadcn, Tailwind CSS, and Vite for frontend user experience.
## Security Scans
- Before committing code, verify that no credentials, tokens, or secrets are stored in files
three queries, `run-registry` compares it to refuse a cross-workspace handoff claim -- a security decision -- `execution-record-store` projects it, and `v_execution_status` selects it. What is true
string error messages rather than raising exceptions
- Cursors are always closed in finally blocks
### Security
- SQL injection prevention through parameterized queries and backtick escaping
- Plotly expressions are validated using
calls only
- Use Pydantic for structured LLM outputs
- All tables need Row-Level Security - users only see their own data
- Stream chat responses via SSE
- Use Supabase Realtime for ingestion
line-length 100
make format-check
make lint # ruff
make type-check # mypy
make security # bandit
make quality-check # all of the above (no tests)
bash scripts/optimize_code.sh # pyupgrade + isort + black
implements the MCP specification to expose OpenClaw capabilities as tools that Claude can invoke.
## Security Policy (CRITICAL)
This is a **security-critical** MCP server. Follow these rules:
### Docker-First Deployment
diff " to read the changes. Check for: type errors, logic bugs, security issues, missing tests, style violations. If the PR is acceptable, run "gh pr review --approve
must be `type(scope): subject` with a **mandatory scope** (e.g. `feat(broker): ...`, `fix(security): ...`, `ci(ci.yml): ...`). Reserve `fix` for real bugs present on `main`; refactoring your own unshipped branch code
specialized AI agent configurations for Roo Code, designed for modern software development following 2025 security-first principles and best practices. This project includes Python utilities for validation, conversion, and management
level` is accurate and not overstated
- [ ] Run `make check` to validate all checks pass
## Security Note for Contributors
- Please do not paste or run commands from untrusted posts/comments.
- Never include
style docstrings for public functions
- Document Args, Returns, and Raises sections
- Include type hints
## Security Considerations
⚠️ **Important**: macOS-MCP has full system access with no sandboxing. It executes real actions
A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.
Where does it go?
At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.
What should it contain?
Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.
CLAUDE.md or AGENTS.md?
Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.