docs: add Code Review Rules section for Codex review - #656
Conversation
Give the Codex PR reviewer this repository's review rules through a pointer-only "## Code Review Rules" section in the root AGENTS.md, per the melodic-software/standards code-review-rules convention (standards#656). Each line names a rule CI does not enforce and links the file that owns it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Drop the security-model parenthetical, which named a rule the SECURITY MODEL headers do not state, and the paraphrased qualifiers on the other lines. Each per-repository line now uses the convention's slot form and ends at its link. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 49s —— View job Security review: no issues found
Scope: This PR touches a single file, Instruction-surface lens: Since nothing is being removed, the instruction-exception-register check (for deleted/weakened guardrails) doesn't apply here — there's no prior rule being taken away for a hostile context to exploit. For completeness: Content reviewed: All six repo-specific lines are pointer-only (rule name + link), none restate executable policy inline, and none introduce secrets, credentials, executable code, or trust-boundary changes. Conclusion: No security-relevant surface in this diff (skip-gate condition 2) — docs-only, additive, no code/logic/auth/injection path. No CRITICAL / IMPORTANT / SUGGESTION findings. |
|
Claude finished @kyle-sexton's task in 1m 42s —— View job Code review —
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
claude-security-review has reviewed this pull request through f62a7a7; a later push is reviewed from there. |
|
claude-review has reviewed this pull request through f62a7a7; a later push is reviewed from there. |
No related issue: main has been red since c11c7ec (#650); this restores it. ## Summary #650 deleted `docs/topics/` while #656 added two AGENTS.md links into it, and two tests still read files there. `lychee-offline` and `selector-contract` fail on `main` and on every open PR. ## Fix - AGENTS.md: the two Code Review Rules lines that linked into `docs/topics/` now state their rule inline. - `.github/scripts/ci-fanout-consolidation.test.cjs`: drop the ADR read and the test that asserted the ADR's text. - `.github/scripts/claude-review-plugin-path.test.cjs`: drop the test that asserted the V2 architecture doc's text. ## Verification - `node --test .github/scripts/*.test.cjs`: 192 pass, 0 fail. - `git grep docs/topics` finds only the standards-managed `.github/actionlint.yaml` comment that #650 already noted. ## Related - Unblocks #659. - Cause: #650 and #656 merged in parallel. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
No related issue: rollout item for melodic-software/standards#656 (closed centrally)
Summary
Adds a pointer-only
## Code Review Rulessection to the rootAGENTS.md, so the Codex PR reviewer gets this repository's review rules. Shape followscomponents/code-review-rules/README.mdinmelodic-software/standards: the inherited block (managedREVIEW.mdpointer, since this repository receives the syncedREVIEW.md), then six repository-specific pointer lines.Fix
AGENTS.mdwas empty (blanked by the unhobble bare-baseline reset in #403). It now holds only this section.CLAUDE.mdstays empty and does not importAGENTS.md, so Claude Code sessions load nothing new; the section reaches Codex.Per-repository lines, each a short rule name followed by a
[rule](...)link to the file that owns it, none restating it:SECURITY MODELheaders ofclaude-review.ymlandclaude-security-review.yml.fixtures/configs only exercise contracts: README, Policy ownership.docs/topics/local-lane-guards.md.ci-status: CI fan-out ADR, Decisions locked.Left out because CI already checks them: SHA pinning (zizmor), PR title and body contract (
ci-status), markdown and link lint.Verification
code-review-rules.sh file --root <worktree>(standardsorigin/main):OK.markdownlint-cli2with the repository's.markdownlint-cli2.jsonc: 0 issues.lychee --offline --include-fragmentsonAGENTS.md: 8 of 8 links OK, anchors included.Related
🤖 Generated with Claude Code