feat(rules): user permanent rules — writing style, web building, web security (BDR-085)
...
Three rules/ files from the user's permanent-rules text:
- writing-style.md (always-on): em-dash ban, no it's-not-X-it's-Y, no
emoji, no decorative bold, no reflex triads, no hedging chains, slop
vocabulary ban, sentence-length variety, deliverable self-check.
Scope carve-outs keep caveman registries, code comments, skill
templates intact.
- web-building.md (path-scoped): design anti-default list + public-site
done checklist (report missing items, never invent them).
- web-security.md (path-scoped): browser-exposed keys, service-key/client
split, RLS, server-side auth, IDOR, cookie flags, field minimization,
rate limiting — extends §Security, no dup of the core.
Project CLAUDE.md rules/ doctrine: 320-budget exception for standalone
always-on user rule sets.