toolset`); MCP and write tools belong to specific subagent leaves.
2. The README's security table and the `agent.yaml` comments must match what
the YAML actually grants. Don't claim
Linux backend at runtime.
**Sandbox env vars.** `CHProcess` and `VirtiofsdProcess` default to the upstream-secure spawn flags. Per-component opt-outs:
- `CONTAINERIZATION_NO_CH_SECCOMP=1` — launch cloud-hypervisor with
model-checks` and `cargo test -p monty-fs`
on Linux, macOS, and Windows
## Important Security Notice
It's ABSOLUTELY CRITICAL that there's no way for code
with code in this repository.
## Project Overview
DataHaven is an EVM-compatible Substrate blockchain secured by EigenLayer. It bridges Ethereum and Substrate ecosystems through:
- EigenLayer AVS integration for security
- Snowbridge
Claude for Securing Source Code
This repo has two halves:
- **Interactive skills** (`.claude/skills/`) — read and write files in the
repo (no target-code execution, except `/dnr-hunt` / `/dnr-respond`, which
this many times
max_loops=1,
)
result = moa.run("What are the best practices for securing a Kubernetes cluster?")
```
**When to use:** High-stakes tasks where you want multiple independent perspectives
procedure alias in it resolves to bare `t.procedure` (the cloud layer lives on `dev`)
#### Security Considerations
- Server-side keys come from env vars only; client-held keys are user-supplied
merges them with base + GPU overlay. Services bind to `127.0.0.1` by default for security.
### Dashboard API
FastAPI app in `extensions/services/dashboard-api/` with modular routers (`routers/agents.py`, `features.py`, `privacy.py`, `setup.py`, `updates.py`, `workflows.py`). Uses
Growth Pyramid, applied through practitioner field material
- ✅ **v0.79 Released (May 15, 2026):** Community contributions — security hardening, new meta-skill, bug fix
- Added `skills/pm-skill-creator/` — interactive skill for guided skill design
path (just `host.com/{endpoint}`)
- Use logger from `ctx` (API) or `sync_context` (during sync)
- Security: never use `random.*` for security values (ruff S311); use `secrets` module
### Frontend (TypeScript)
- TailwindCSS with
user first)
- Secret-free/domain-free templates in `assets/`; fresh secrets generated on the box; secure defaults; DNS/ports preflight; Day-2 update/backup/restore
- Python Code nodes need task runners in external mode
introduced by this PR?
5. If scope is split, does immediate user-data or security risk remain?
Use these decisions:
- Q1 + Q2: **Changes Requested**.
- Q3 + Q5: stop and revisit
A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.
Where does it go?
At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.
What should it contain?
Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.
CLAUDE.md or AGENTS.md?
Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.