Files

1.7 KiB

Vulnerability Explorer agent guide

Mission

Vulnerability Explorer delivers policy-aware triage, investigation, and reporting surfaces for effective findings.

Key docs

How to get started

  1. Review ./architecture.md for ledger schema, workflow states, and export requirements.
  2. Open sprint file /docs/implplan/SPRINT_*.md and locate stories for this component.
  3. Check ./TASKS.md and update status before/after work.
  4. Read README/architecture for design context and update as the implementation evolves.

Guardrails

  • Uphold Aggregation-Only Contract boundaries when consuming ingestion data.
  • Preserve determinism and provenance in all derived outputs.
  • Document offline/air-gap pathways for any new feature.
  • Update telemetry/observability assets alongside feature work.

Required Reading

  • docs/modules/vuln-explorer/README.md
  • docs/modules/vuln-explorer/architecture.md
  • docs/modules/vuln-explorer/implementation_plan.md
  • docs/modules/platform/architecture-overview.md

Working Agreement

    1. Update task status to DOING/DONE in both correspoding sprint file /docs/implplan/SPRINT_*.md and the local TASKS.md when you start or finish work.
    1. Review this charter and the Required Reading documents before coding; confirm prerequisites are met.
    1. Keep changes deterministic (stable ordering, timestamps, hashes) and align with offline/air-gap expectations.
    1. Coordinate doc updates, tests, and cross-guild communication whenever contracts or workflows change.
    1. Revert to TODO if you pause the task without shipping changes; leave notes in commit/PR descriptions for context.