feat(rules): user permanent rules — writing style, web building, web security (BDR-085)
Three rules/ files from the user's permanent-rules text: - writing-style.md (always-on): em-dash ban, no it's-not-X-it's-Y, no emoji, no decorative bold, no reflex triads, no hedging chains, slop vocabulary ban, sentence-length variety, deliverable self-check. Scope carve-outs keep caveman registries, code comments, skill templates intact. - web-building.md (path-scoped): design anti-default list + public-site done checklist (report missing items, never invent them). - web-security.md (path-scoped): browser-exposed keys, service-key/client split, RLS, server-side auth, IDOR, cookie flags, field minimization, rate limiting — extends §Security, no dup of the core. Project CLAUDE.md rules/ doctrine: 320-budget exception for standalone always-on user rule sets.
This commit is contained in:
@@ -7,6 +7,13 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
|
||||
## [Unreleased]
|
||||
|
||||
### Added
|
||||
- **User permanent rules (BDR-085)** — three new rules/ files from the
|
||||
user's rule text: `writing-style.md` (always-on: em-dash ban, no slop
|
||||
vocabulary, no hedging chains, deliverable self-check),
|
||||
`web-building.md` (path-scoped: design anti-defaults + public-site done
|
||||
checklist), `web-security.md` (path-scoped: RLS, service-key/client
|
||||
split, IDOR, cookie flags, rate limiting — extends §Security, no dup).
|
||||
Project CLAUDE.md rules/ doctrine gains the 320-budget exception.
|
||||
- **/tour multi-project parallel fan-out (BDR-084)** — two or more
|
||||
project paths now dispatch one runner per repo in a single message
|
||||
(independent working trees, nothing collides) instead of processing
|
||||
|
||||
Reference in New Issue
Block a user