Skip to content

Add a CLAUDE.md pointer to AGENTS.md - #8

Merged
exploitintel merged 2 commits into
mainfrom
docs/claude-md-pointer
Sep 10, 2026
Merged

exploitintel merged 2 commits into
mainfrom
docs/claude-md-pointer

Conversation

@exploitintel

Copy link
Copy Markdown
Owner

Claude Code loads CLAUDE.md, not AGENTS.md, so a session opened here picked up no instructions. 19 of 20 repositories in the workspace had this gap.

Deliberately a pointer and nothing else. AGENTS.md stays the single authority, so no rule is duplicated anywhere it could drift out of step.

@claude

claude Bot commented Sep 10, 2026

Copy link
Copy Markdown

Reviewed against this repo's security checklist (corpus-text escaping, derived judgment/ranking, PoC token leakage, unbounded output, host-validation/transport-security, scope creep into writes/downloads).

This PR only adds CLAUDE.md, a 9-line pointer to AGENTS.md/README.md/docs/, with no code changes. It doesn't touch the HTTP client, rendering, transport, or any of the checklist's risk surfaces, and the linked files (AGENTS.md, README.md, docs/) all exist in the repo. No findings.

@claude

claude Bot commented Sep 10, 2026

Copy link
Copy Markdown

Reviewed against the MCP server's security checklist (corpus-text escaping, derived judgment, PoC token leakage, unbounded output, host/transport-security defaults, scope creep). None apply here — this PR only adds a static CLAUDE.md pointer file with no executable code and no interaction with the API client, tool results, or transport layer.

Checked that its references resolve in this repo: AGENTS.md and README.md exist at the root, and docs/ contains user-guide.md and self-hosting.md. LGTM.

Claude Code loads CLAUDE.md, not AGENTS.md, so a session opened in this
repository picked up no instructions at all. This is a pointer and nothing
more: AGENTS.md stays the single authority, so there is no second copy of any
rule to drift.
Review caught the wording: it sits in this repository's parent directory, not
beside it. The previous phrasing also contradicted README.md where that file
names the same location.
@claude

claude Bot commented Sep 10, 2026

Copy link
Copy Markdown

Reviewed against the eip-mcp security checklist (corpus escaping, derived judgment/ranking, stored-analysis fidelity, PoC token leakage, output bounding, host-validation/transport security, scope creep).

This PR only adds a 10-line CLAUDE.md pointer file directing Claude Code sessions to read AGENTS.md (authoritative) and README.md; it explicitly disclaims adding rules or repo details. No source code, HTTP client, rendering, or transport logic is touched, so none of the checklist items apply here.

No issues found.

@exploitintel
exploitintel merged commit 1110941 into main Sep 10, 2026
4 checks passed
@exploitintel
exploitintel deleted the docs/claude-md-pointer branch September 10, 2026 17:38
exploitintel added a commit that referenced this pull request Sep 11, 2026
The pointer I added in #8 claimed workspace-wide rules live in the AGENTS.md in
this repository's parent directory, alongside the sibling repositories.

Nothing here supports that. Neither AGENTS.md nor README.md mentions a
workspace file, a parent directory, or sibling repositories as a rule source,
so the sentence asserted both a location and the existence of an authority on
the repository's behalf, and pointed at a directory a session scoped to this
checkout cannot list.

It also described a private workspace layout in a repository that is
distributed on PyPI, where the sibling repositories it named mean nothing to a
reader.

AGENTS.md is the authority here and says so in its first line.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant