report of issues and pain points
7. **Run `devcheck`** — lint, format, typecheck, and security audit
8. **Run the `security-pass` skill** — audit handlers for MCP-specific security gaps: output injection
creates an entry — **grant the host terminal (e.g. Ghostty) → Finder under System Settings → Privacy & Security → Automation and re-run**; v1.1.1's branded DMG was built from Claude Code this
summary report. The comparison basis is always "real `~/.claude` vs sim dir result".
## Security Hardening
`config/permissions.json` keeps high-risk tools out of `permissions.allow` so code execution, network fetches, environment reads
users need to set up login, sign-in, sign-up, credential authentication, or password security with Better Auth.
- `.claude/skills/email-and-password-best-practices/SKILL.md`
## Design Thinking
Create distinctive, production-grade frontend interfaces with high design
what we are doing, (2) only relevant state, (3) constraints
- Example: "Do a security review. Context: files X, Y, Z. Check: OWASP top 10. Format: JSON with severity."
## Structured Reasoning
report of issues and pain points
7. **Run `devcheck`** — lint, format, typecheck, and security audit
8. **Run the `security-pass` skill** — audit handlers for MCP-specific security gaps: output injection
Sonnet vanilla (7/10) by 2+ points.
- **Claim prism is domain-sensitive.** 9.5 on AuthMiddleware (security-adjacent code has clearer assumptions to invert; found genuine multi-org permission escalation vulnerability
This repo contains instruction files for using and conducting security reviews, do not confuse this `CLAUDE.md` from other copilot-instructions files existing in this workspace.
For every change
README.
Main areas:
- `openclaw-infra/`, `openclaw-im/`, `openclaw-models/`: deployment, IM integration, model/provider, security, and troubleshooting guides for OpenClaw.
- `openclaw-soul/`, `openclaw-heartbeat/`, `openclaw-skills/`: templates and examples for SOUL/AGENTS
guidance to Claude Code (claude.ai/code) when working with code in this repository.
> 本文件只管 `security-guardian/` 子项目。仓库根 `agentic-ai/CLAUDE.md` 是课程总览,与本文件并存。
## 这个项目是什么
第 20 节《企业级数字员工的安全审计与生产治理》配套项目:一个面向
A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.
Where does it go?
At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.
What should it contain?
Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.
CLAUDE.md or AGENTS.md?
Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.