Security guidance and vulnerability review for codebases, APIs, services, CLI tools, libraries, and daemons. Use for security questions, focused reviews, vulnerability research, security audits, or pen tests. Run the complete workflow only for explicit codebase audit or pen-test requests, full/comprehensive/end-to-end reviews, or requested report artifacts.
Cloudflare's command-line tool and networking daemon written in Go. Production-grade tunneling and network connectivity services used by millions of developers and organizations worldwide. Notes on linting: - .golangci.yaml is configured with new-from-rev and whole-files: true. Touching a file triggers linting of the ENTIRE file, not just the changed hunks. Expect to fix pre-existing issues in files you modify, or add targeted // nolint: <linter> comments with a short justification. - Prefer defer func() { _ = resource.Close() }() over defer…
quiche draft GitHub release automation from a release commit hash or existing tag. Use when creating draft releases for the quiche crate from a quiche/Cargo.toml version bump.
UDP socket abstraction layer shared across the quiche workspace. Two main concerns: DgramBuffer (a headroom-aware zero-copy byte buffer for datagrams) and DatagramSocket* traits (uniform async send/recv over UdpSocket/UnixDatagram with Linux recvmmsg/sendmmsg batching). Wraps a Vec<u8> with a pos cursor dividing it into [headroom: 0..pos][payload: pos..]. as_slice() / len() expose only the payload. BufMut writes append to the tail, independent of pos. Fast path: allocate with withcapacityandheadroom, fill payload via BufMut, call tryadd_prefix to slide pos left and write the prefix…
Low-level HTTP/3 testing client. Sends arbitrary/malformed H3 frames to probe server RFC compliance. Both library (lib.rs) and CLI binary (main.rs). Used programmatically as test driver in tokio-quiche integration tests.
qlog data model for QUIC and HTTP/3 per IETF drafts (draft-ietf-quic-qlog-main-schema, draft-ietf-quic-qlog-quic-events, draft-ietf-quic-qlog-h3-events). Pure data types + serde serialization; no IO (deferred to consumers).
Low-level QUIC transport and HTTP/3 in Rust. App provides IO/timers; this crate handles protocol state. Also exposes C FFI via staticlib/cdylib. BoringSSL itself is built by boring-sys (no in-tree submodule).
HTTP/3 wire protocol over QUIC. Connection manages H3 state (streams, QPACK, SETTINGS, GOAWAY) on top of quiche::Connection<F>. Event-driven: caller loops poll() → Event. Own Error/Result types, separate from quiche::Error.
QUIC loss detection and congestion control per RFC 9002. Two parallel CC implementations coexist: congestion/ (legacy Reno/CUBIC) and gcongestion/ (next-gen BBR2 ported from google/quiche). Recovery enum dispatches between LegacyRecovery and GRecovery via enum_dispatch over the RecoveryOps trait (40+ methods). - Two Acked structs at congestion/recovery.rs:1079 and gcongestion/mod.rs:49. NOT unified. Do NOT create a third. - FIXME stubs: Some RecoveryOps methods only apply to one impl. Both sides have // FIXME only used by {congestion,gcongestion} stubs that return defaults. Do not…
Async tokio wrapper for quiche. Spawns per-connection IO worker tasks driven by an ApplicationOverQuic trait. Ships a ready-made H3Driver for HTTP/3. Uses foundations for structured logging (slog), telemetry, and settings.
Async HTTP/3 driver bridging quiche::h3::Connection to Tokio tasks via channels. H3Driver<H: DriverHooks> is generic over sealed client/server hooks; users interact through H3Controller + typed event/command channels.
Async QUIC connection management. Splits socket into recv-half (one InboundPacketRouter task) and send-half (shared by many IoWorker tasks). Entrypoints: connect()/connectwithconfig() for clients, start_listener() for servers. raw submodule bypasses the router for manual packet injection.
This project is building a platform for "vibe coded" personal applications and AI agents that run inside a strong sandbox. The following files are commonly important to reference: The project structure is:
Use for creating, modifying, moving, or reviewing React frontend code anywhere in packages/*, including Workshop pages, gatekeeper management apps, shared UI, components, hooks, forms, interactions, styling, accessibility, and frontend tests.
Guides implementation of Gatekeeper Workers that bridge Gadgets to external services. Covers auth, capability-based API design, approval queue integration, caching, and action simulation. Load when creating, modifying, or reviewing the implementation of a gatekeeper.
@gadgets/gatekeeper-kit is a library, not a deployable Worker. Do not add wrangler.jsonc; its presence makes release tooling treat this package as a gatekeeper deployment. - Only Layer 1 leaf modules are shipped. Layer 2 remains a proposal in ../../plans/gatekeeper-kit.md. - Keep leaf modules independently usable. Do not make one depend on a future assembly layer. - Accept the narrowest structural KV surface a module needs. Pass stable ctx.storage.kv objects to modules that coordinate work by storage identity. - Treat shipped…
@gadgets/ui is the shared runtime React UI layer for the Workshop and gatekeeper management apps. Kumo owns low-level controls and semantic tokens; this package owns reusable Gadgets interaction patterns and composed components. - Add a component here when at least two independent frontends need the same feature-independent behavior or when consistency across those frontends is an explicit product requirement. - Keep product data fetching, routing, RPC, permissions, and domain workflows in the consuming app. - Check Kumo before adding a…
This package is the Workshop single-page application. It uses React, TanStack Router, Tailwind, and Kumo. Follow the repository-wide guidance in ../../AGENTS.md in addition to this file. Organize new code by product ownership first and implementation type second. The existing tree predates this convention. Apply it to new code and to code being substantially reworked; do not migrate unrelated files opportunistically. Feature directories own product behavior. A feature may contain components, hooks, tests, and utilities that belong to that behavior. Start…
Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.
CLAUDE.md or AGENTS.md?
CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.
What is a skill?
A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.
Can I search my own team's files too?
Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.