chore: add agent guardrails (CLAUDE.md, stop hook, permissions, git hooks)
CLAUDE.md documents commands, the spec-first workflow, the functional-core rule and a do-not list. A Claude Code Stop hook blocks finishing while typecheck or unit tests fail. Permissions deny reading env files, hook bypass flags, hard resets and recursive deletes, and ask before CI edits or any push. Husky pre-commit now also typechecks and runs unit tests; pre-push runs coverage and the mutation gate when src/domain changed. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
Executable
+32
@@ -0,0 +1,32 @@
|
||||
#!/usr/bin/env bash
|
||||
# Stop hook: the agent may only finish when typecheck and unit tests pass on the current code.
|
||||
set -uo pipefail
|
||||
cd "${CLAUDE_PROJECT_DIR:-$(git rev-parse --show-toplevel)}"
|
||||
|
||||
payload="$(cat)"
|
||||
# Avoid a loop: if we already blocked once in this turn, let it stop and show the failure to the user.
|
||||
if printf '%s' "$payload" | grep -q '"stop_hook_active"[[:space:]]*:[[:space:]]*true'; then
|
||||
exit 0
|
||||
fi
|
||||
|
||||
# Nothing changed in the app, nothing to verify.
|
||||
if [ -z "$(git status --porcelain -- apps/web package.json pnpm-lock.yaml)" ]; then
|
||||
exit 0
|
||||
fi
|
||||
|
||||
run() {
|
||||
local label="$1"; shift
|
||||
local out
|
||||
if ! out="$("$@" 2>&1)"; then
|
||||
{
|
||||
echo "VERIFY FAILED: $label"
|
||||
echo "$out" | tail -n 40
|
||||
echo "Fix the cause (do not weaken tests), then finish again."
|
||||
} >&2
|
||||
exit 2
|
||||
fi
|
||||
}
|
||||
|
||||
run "typecheck" pnpm --filter @mintel/web typecheck
|
||||
run "unit tests" pnpm --filter @mintel/web test
|
||||
exit 0
|
||||
Reference in New Issue
Block a user