- Modified task status update instructions in AGENTS.md files to refer to corresponding sprint files as `/docs/implplan/SPRINT_*.md` instead of `docs/implplan/SPRINTS.md`. - Added a comprehensive document for Secret Leak Detection operations detailing scope, prerequisites, rule bundle lifecycle, enabling the analyzer, policy patterns, observability, troubleshooting, and references.
36 lines
1.7 KiB
Markdown
36 lines
1.7 KiB
Markdown
# Vulnerability Explorer agent guide
|
|
|
|
## Mission
|
|
Vulnerability Explorer delivers policy-aware triage, investigation, and reporting surfaces for effective findings.
|
|
|
|
## Key docs
|
|
- [Module README](./README.md)
|
|
- [Architecture](./architecture.md)
|
|
- [Implementation plan](./implementation_plan.md)
|
|
- [Task board](./TASKS.md)
|
|
|
|
## How to get started
|
|
1. Review ./architecture.md for ledger schema, workflow states, and export requirements.
|
|
2. Open sprint file `/docs/implplan/SPRINT_*.md` and locate stories for this component.
|
|
3. Check ./TASKS.md and update status before/after work.
|
|
4. Read README/architecture for design context and update as the implementation evolves.
|
|
|
|
## Guardrails
|
|
- Uphold Aggregation-Only Contract boundaries when consuming ingestion data.
|
|
- Preserve determinism and provenance in all derived outputs.
|
|
- Document offline/air-gap pathways for any new feature.
|
|
- Update telemetry/observability assets alongside feature work.
|
|
|
|
## Required Reading
|
|
- `docs/modules/vuln-explorer/README.md`
|
|
- `docs/modules/vuln-explorer/architecture.md`
|
|
- `docs/modules/vuln-explorer/implementation_plan.md`
|
|
- `docs/modules/platform/architecture-overview.md`
|
|
|
|
## Working Agreement
|
|
- 1. Update task status to `DOING`/`DONE` in both correspoding sprint file `/docs/implplan/SPRINT_*.md` and the local `TASKS.md` when you start or finish work.
|
|
- 2. Review this charter and the Required Reading documents before coding; confirm prerequisites are met.
|
|
- 3. Keep changes deterministic (stable ordering, timestamps, hashes) and align with offline/air-gap expectations.
|
|
- 4. Coordinate doc updates, tests, and cross-guild communication whenever contracts or workflows change.
|
|
- 5. Revert to `TODO` if you pause the task without shipping changes; leave notes in commit/PR descriptions for context.
|