tests must pass before any commit. No test should be skipped or marked `.only`.
## Security
- AES-256-GCM encryption at rest
- HMAC-SHA256 / Ed25519 signed tokens with TTL
- No hardcoded
SKILL.md` / `.zip` / Scout
`.json`.
- Anything that **breaks CI**, or is a **security / privacy** problem (secrets,
data exfiltration, harmful content).
**Not block-worthy — do NOT raise:**
- **Writing style in the skill
defect only in changed lines or code those lines directly break. Report correctness defects, security defects, data loss, and fail-open paths in gates, guards, or CI. Do not report
object or tool input when practical.
- Keep narrow utility logic in `src/utils/`:
- `validation.ts` for security-sensitive input validation and error sanitization
- `actions.ts` for URL-to-view-action extraction
- `markdown.ts
imported/vendored (git subtree). Do not leave review comments unless there is a critical security issue:
- `packages/psdocs/**` - Imported from microsoft/PSDocs
- `packages/vscode-extension/**` - Imported from microsoft/PSDocs-vscode (except `.github/workflows/` changes)
## Build System
This
will fail to load or run the file, or the issue presents a real security risk.
- **WARNING**: The file functions, but quality or maintainability is noticeably degraded.
- **INFO**: Gentle suggestions
check
cargo clippy -- -D warnings
cargo test
```
Always validate locally before submitting a PR.
## Security & ACL
Any change touching `src/server_auth/`, ACL logic, auth providers, or credential parsing **must** include tests
mandatory for non-obvious assertions** — any assertion on a URL structure, encoding format, security-sensitive behavior, or protocol requirement must include a `because:` clause explaining the invariant being enforced.
- **Dispose
lib.rs`
- Formatting: use rustfmt’s default settings (no project-specific rustfmt.toml)
## Security Review (Critical)
- Flag hardcoded secrets, API keys, tokens, or credentials
- Flag SQL injection risks in SQLite queries (must
kind --body " " --custom Issue=
```
Where:
- ` ` is one of: `breaking`, `changed`, `deprecated`, `removed`, `fixed`, `security`, `documentation`
- ` ` is a concise summary of what was changed or fixed. Follow the commit message style
Document any limitations or known issues
- Provide clear error messages for user-facing components
## Security Considerations
- Sanitize file paths to prevent directory traversal
- Be cautious with executing or evaluating batch
discord
uv run ruff check claude_discord/
uv run ruff format --check claude_discord/
```
## Security (Mandatory Pre-Commit)
This project spawns Claude Code CLI as a subprocess. All user input
Update `CHANGELOG.md` under `## [Unreleased]` using Keep a Changelog categories: `Added`, `Changed`, `Deprecated`, `Removed`, `Fixed`, `Security`.
- Choose the bump level as follows:
- `MAJOR` for breaking changes or required migration.
- `MINOR