read/write access to the workspace's local `.vision-memory-mcp/` cache directory.
# Cryptographic Vault & Security (webcrypt-mcp)
This project provides native `webcrypt-mcp` tooling for zero-dependency
under `src/strategies/`.
## Working rules
- Confirm the goal, acceptance criteria, constraints, current behavior, and
affected security or compatibility boundaries.
- Reuse repository patterns and tools. Make small, complete changes without
unrelated refactoring
doesn't suffice.
- Every dependency must pass `cargo deny check` (license allowlist + security advisories).
- Prefer well-maintained crates under MIT or Apache-2.0.
### Safety
- No `unsafe` without a `// SAFETY:` comment
extension logs
- Webview dev server runs on localhost:3001 for standalone testing
## Security Considerations
- Credential storage in `%LOCALAPPDATA%/Microsoft/pqtest`
- Extension handles sensitive authentication data
- Test environments should use mock/test credentials
Prefer simple conditionals over nested ternary operators
- Group related code together and separate concerns
#### Security
- Add `rel="noopener"` when using `target="_blank"` on links
- Avoid `dangerouslySetInnerHTML` unless absolutely necessary
HIGH-SEVERITY issue exists -> RECOMMENDATION: DO NOT MERGE (regardless of score).
HIGH-SEVERITY includes: security flaw, correctness bug likely to break users, data loss risk, auth/secret exposure, unsafe concurrency/race.
- Else
STRICT)
- Prefer **one high-level summary comment**
- Inline comments are **allowed ONLY** for:
- Bugs
- Security issues
- Broken imports
- Public API breakage
- If the PR is acceptable, say **“Looks good
databases, frameworks) and link them to the milestones/tasks using `decided_in` edges.
# Cryptographic Vault & Security (webcrypt-mcp)
This project provides native `webcrypt-mcp` tooling for zero-dependency
This is a JavaScript security scanner for Claude Code Skills. It has 9 detection engines. Security is critical — never bypass checks, validate all input
Return meaningful error messages
- Never silently swallow exceptions
- Prefer explicit error returns over panics/exceptions
### Security
- Never suggest committing secrets, keys, or credentials
- Never suggest .env files in version control
- Validate