configurations
✅ **Do**: Achieve 95%+ test coverage
✅ **Do**: Use strict TypeScript settings
✅ **Do**: Write comprehensive security documentation
✅ **Do**: Use `unknown` instead of `any` for generic type defaults
✅ **Do**: Validate hooks match
directories
- Agents invoked via Agent tool, never via Bash
- Python deps install into `~/.claude/skills/repurpose/.venv/`
## Security Rules
- No hardcoded credentials or secrets
- URL validation in all scripts (block private IPs, loopback
explicitly overridden).
---
## 🚨 **Critical Rules**
These rules apply project-wide. Violations will cause deployment failures, security issues, or runtime errors.
### **Rule 1: Never Use Pydantic v2 Syntax**
The backend uses Pydantic
subnets } : undefined,
environment: { /* handler-specific env vars only; resource names resolve via SSM */ },
});
```
### Required Security Calls (Every Lambda Builder)
After creating the function, every builder MUST call these five helpers
value shape** — `vams_…` keys, JWTs, `Bearer …`, and presigned-URL `X-Amz-Signature` /
`X-Amz-Security-Token` parameters are scrubbed even when the key name gives no hint, which covers
A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.
Where does it go?
At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.
What should it contain?
Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.
CLAUDE.md or AGENTS.md?
Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.