Add a CLAUDE.md pointer to AGENTS.md - #8
Conversation
|
Reviewed against this repo's security checklist (corpus-text escaping, derived judgment/ranking, PoC token leakage, unbounded output, host-validation/transport-security, scope creep into writes/downloads). This PR only adds |
|
Reviewed against the MCP server's security checklist (corpus-text escaping, derived judgment, PoC token leakage, unbounded output, host/transport-security defaults, scope creep). None apply here — this PR only adds a static Checked that its references resolve in this repo: |
Claude Code loads CLAUDE.md, not AGENTS.md, so a session opened in this repository picked up no instructions at all. This is a pointer and nothing more: AGENTS.md stays the single authority, so there is no second copy of any rule to drift.
Review caught the wording: it sits in this repository's parent directory, not beside it. The previous phrasing also contradicted README.md where that file names the same location.
346787b to
637fcc0
Compare
|
Reviewed against the eip-mcp security checklist (corpus escaping, derived judgment/ranking, stored-analysis fidelity, PoC token leakage, output bounding, host-validation/transport security, scope creep). This PR only adds a 10-line No issues found. |
The pointer I added in #8 claimed workspace-wide rules live in the AGENTS.md in this repository's parent directory, alongside the sibling repositories. Nothing here supports that. Neither AGENTS.md nor README.md mentions a workspace file, a parent directory, or sibling repositories as a rule source, so the sentence asserted both a location and the existence of an authority on the repository's behalf, and pointed at a directory a session scoped to this checkout cannot list. It also described a private workspace layout in a repository that is distributed on PyPI, where the sibling repositories it named mean nothing to a reader. AGENTS.md is the authority here and says so in its first line.
Claude Code loads
CLAUDE.md, notAGENTS.md, so a session opened here picked up no instructions. 19 of 20 repositories in the workspace had this gap.Deliberately a pointer and nothing else.
AGENTS.mdstays the single authority, so no rule is duplicated anywhere it could drift out of step.