mirror of
https://github.com/SquidSec/SquidC5
synced 2026-08-09 12:22:26 +00:00
Remove personal OneDrive paths and wrong GitHub owner; document self-hosted CI for external contributors; fix env prefix table, deploy lab script, UFW guidance, pyproject URLs, and tighten gitignore for secrets.
1.2 KiB
1.2 KiB
CLAUDE.md
SquidC5 is a security-first, AI-native C5 teamserver (Command · Control · Cognitive · Collaborative · Coordination) under active development for authorized red team / pen-test use only.
Follow AGENTS.md as the primary agent memory for this repository.
Also read:
| Doc | Why |
|---|---|
| docs/README.md | Docs catalog + Diátaxis map |
| docs/squidc5-vision.md | Product / security architecture |
| docs/roadmap-2026-2027.md | Prioritized roadmap |
| docs/user-guide.md | Feature reference (What/Why/How/Example) |
| docs/operator-runbook.md | Day-2 procedures |
| docs/deployment.md | Lab Docker + binary prod |
Hard rules
- Secure by default (no public docs/OpenAPI, no wildcard CORS, MCP off until enabled)
- Admin UI only after server validates admin token (
/api/v1/ops/admin.js) - No secrets in git
- MCP allow-lists and Admin AI / INKO sandbox (capability + chat tools) are non-negotiable
- Prod: main-CI
squidc5binary only after PR merge - Do not help with unauthorized access