projects. Research agent runs first to build domain context, then Architect, PM, and Security agents run in parallel. Synthesis agent combines all perspectives into a detailed GSD-style PLAN.md with
Security-Driven Hardening): Lagune
> This file orients any AI agent (and human) working in this repository. Read it fully before making changes. It describes **what Lagune
Claude Code (claude.ai/code) when working with code in this repository.
## Project Overview
**skill-security-scan** is a command-line security scanner for Claude Skills. It performs static analysis
used to prevent accidental data loss. Every PR is analyzed with CodeQL for security.
## Development Commands
### Build and Run
```bash
npm install # Install dependencies
npm run build # Compile TypeScript
part of a
routine dependency bump; revisit only if v2 stops getting security fixes.
- `github.com/jedib0t/go-pretty/v6` - Table formatting
- `github.com/aws/aws-sdk-go-v2` - AWS SDK for live pricing and placement scores
- `golang.org/x/net/html
specialized expert subagents. Seven domain experts: Architect, Plan Reviewer, Scope Analyst, Code Reviewer, Security Analyst, Researcher, and Debugger. Only Gemini can advise OR implement. (GPT, Grok, and OpenRouter are advisory
same word for both turns a cosmetic issue into what
sounds like a security incident, and spends the operator's attention on alarm rather than
judgement.
### Evidence freshness
Any measurement
Supporting Infrastructure**:
- `PerformanceOptimizer` - Async performance optimization
- `SystemMonitor` - Prometheus-based monitoring
- `SecurityManager` - Data encryption and security
- `ErrorHandler` - Advanced error handling with retry logic
## Development Commands
This is a documentation/learning project with
Guide users to correct tools (e.g., "use 'read_pdf_fields' to see available fields")
### Security
- Never log or expose passwords
- Validate file paths to prevent directory traversal
- Use secure defaults
Analytics Engine
binding `VNSH_ANALYTICS`. Secrets belong in Wrangler secrets, never source or
`wrangler.toml`.
## Security invariants
- Never send fragment keys to the server or place them in logs.
- Never infer
STYLE.md.
## Project Overview
ACS (Agent Control Standard) is the industry standard for building secure, observable AI agents. It delivers three core capabilities:
- **Inspectability**: Complete visibility into agent components and capabilities
dirty tree.
- Alpha flow is normal: ship `x.y.z-alpha.N` while iterating, then promote to stable.
## Security (project-specific, enforced by tests)
- **User-supplied file paths** (custom music, config) go through
basic auth is not currently enabled. It was causing connection failures. Tailscale network-level security is the primary access control.
- **Apple Silicon vs Intel:** tmux-attach.sh uses `which tmux` to auto
class instead
- Use Bootstrap alert classes for notifications, not `alert()` calls
## Route Decorators — Swagger Security
**Every Flask route MUST include the `@swagger_route(security=get_auth_security())` decorator.**
- Import `swagger
/marketplace.json`
- Test files use `WEIXIN_STATE_DIR` env var to isolate from real credentials
## Security Rules
- Never log or expose tokens, aes_keys, or account credentials
- Never commit `.env`, `account.json
A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.
Where does it go?
At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.
What should it contain?
Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.
CLAUDE.md or AGENTS.md?
Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.