Parent epic: #1
Source brief:
docs/ai-guardrails/issues/004-safe-agents-and-commands.mddocs/ai-guardrails/migration/claude-code-skills-inventory.md
Problem
Raw built-in agents are too permissive for an internal product. The repo needs a safer default operating model for implementation, review, and release workflows.
Deliverables
- hardened default primary agent
- review-oriented subagent
- slash commands for
/implement, /review, /ship, and /handoff - explicit permission policy for dangerous shell patterns and write operations
Acceptance
- default agent is not an unrestricted build clone
- review workflow can run without edit access
- release workflow cannot bypass explicit gates
Notes
Dependencies
Parent epic: #1
Source brief:
docs/ai-guardrails/issues/004-safe-agents-and-commands.mddocs/ai-guardrails/migration/claude-code-skills-inventory.mdProblem
Raw built-in agents are too permissive for an internal product. The repo needs a safer default operating model for implementation, review, and release workflows.
Deliverables
/implement,/review,/ship, and/handoffAcceptance
Notes
docs/ai-guardrails/adr/001-thin-distribution-over-deep-fork.mdclaude-code-skillsepic feat(guardrails): Wave 8 — review fixes + remaining hooks + multi-model delegation #130: mechanism-first guardrails, fast feedback, pointer-based instructions, and runtime verifiabilityDependencies
docs/ai-guardrails/migration/claude-code-skills-inventory.md