Provide usage examples for complex functions
- Keep docstrings up-to-date with code changes
## Security Guidelines
### Security invariants (always apply)
These are hard rules distilled from prior security-review findings
agents.
`mcpc` can connect to any MCP server over Streamable HTTP or stdio transports,
securely login via OAuth credentials and store credentials,
and keep long-term sessions to multiple servers
adapter IIFE source code and a review token → AI reviews the code with security guidance → user confirms → call `plugin_mark_reviewed` with the token to set the permission and mark
Level Warning
}
```
**Example output** for a 400 with `moreDetails[0] = { errorCode: "UniversalSecurityFeatureDisabledForWorkspace", message: "Universal security feature is disabled for the workspace" }`:
- **Debug**: `Failed to retrieve... Full error: API request failed
catch` block in the sentinel wrapper as `"error_type"` = PS exception class name)
---
## Security Constraints
- **Never use `shell=True`** in `subprocess.Popen` — use a list of arguments.
- **App secrets** passed
citation with the standard.
2. **Stay platform-agnostic.** Describe outcomes, not implementations. "Set `Content-Security-Policy`" is in scope. "Add this to your `next.config.mjs`" is not. Link out to platform
pnpm build:linux # Linux (AppImage + deb)
```
Built applications will be in `frontend/apps/web/release/`.
### Key Features
- **Secure token storage**: Uses `electron-store` for encrypted credential storage
- **Auto-updates**: Built-in update checker
HTML-escaped at the boundary. Treat any change that
emits unescaped input as a security regression.
## Common Patterns
```
markdown-html/ /
├── SKILL.md
├── references/
│ └── *.md (rulebooks, severity models, layout and density guidance
This guide covers the **27 production-ready compliance skills** spanning medical device regulations, information security, privacy, financial resilience, AI governance, and infrastructure security — plus the new `audit-prep/` subfolder with
A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.
Where does it go?
At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.
What should it contain?
Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.
CLAUDE.md or AGENTS.md?
Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.