forwarding patterns and the opt-in Asymptote Managed path.
- Dependency vulnerability scanning or package security remediation.
## Common Commands
Run tests for the public CLI. Build the embedded hooks binary first
Overview
This is the **Docker MCP Gateway** - a CLI plugin that enables easy and secure running of Model Context Protocol (MCP) servers through Docker containers. The plugin acts
swaps when a different user sends a message. See `.context/proposal-task-owner-git-auth.md` for the full design.
- **Security: OAuth token scope.** The user's GitHub OAuth token has `repo` scope, granting full control
paths exactly (agtx seeds each worktree into `trustedWorkspaces` when the root is trusted). **`AgentDialog::security` splits the table** — trust/bypass prompts are the user's decision: with `auto_trust = false` (default
issue #820): operational exceptions are caught and returned as error strings to the LLM; security exceptions (`PermissionError`, `ToolConfirmationRequired`) propagate.
- Pre-execution checks run on every call (not cached): permission validation
DATA_DIR` relocates team/task/inbox state but NOT global config.
## Cross-cutting conventions
### Path discipline (security-critical)
Every user-supplied name (team, agent, user, plan ID, inbox recipient…) must flow through
work).
Treat [packaging_policy.py](daymade-skill/skill-creator/scripts/packaging_policy.py)
as the canonical inclusion policy for packaging, security attestation, source
audits, and version checks. Keep consumers on this shared implementation. Preserve the recorded policy
behavior primes it. Reserve explicit prohibitions for failure modes
actually observed in traces.
## Security — agents run autonomously, so the system must fail safe
- **Trust nothing by default.** Treat external input
fallback-heavy logic. TAKT is a local tool: no audit trails, tamper-resistance, or security theater.
- Filenames mostly `kebab-case`. Conventional Commit style with occasional `(#issue)` suffix.
- Don't commit
execution authority;
approve, reopen, or rebaseline a SpecSection; make a material
product/value/scope, public-promise, security, legal, privacy, finance,
irreversible-data, compatibility, or authority-allocation choice.
- If current Work would rely
store.ts`. CLI tool behavior is abstracted via the provider system (`src/main/providers/`).
- **Preload** (`src/preload/preload.ts`) — Secure bridge exposing `window.vibeyard` API via `contextBridge` with namespaces: `pty`, `session`, `store`, `profiles`, `fs`, `provider`, `menu`.
- **Renderer
SAST Security Assessment
Your goal is to identify security vulnerabilities in the codebase located in the current directory.
---
## Step 1: Codebase Analysis & Threat Modeling
Before running, check if `sast/architecture.md` already
A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.
Where does it go?
At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.
What should it contain?
Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.
CLAUDE.md or AGENTS.md?
Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.