Last article in this , , and to audit methodology and documentation for AI agents. The common thread: every security pattern is simple on the surface. The complexity is in the implicit couplings — between container and provider, between timing and params, between handshake and middleware. Making these couplings explicit is the job.
CLAUDE.md After an Audit: 296 to 142 Lines, and My Agent Codes Better Than Before
- ▸ The "document everything" reflex
- ▸ The deletion test
- ▸ The 5 categories that survive
- ↳ 1. Architectural invariants
- ↳ 2. Non-deducible gotchas
- ↳ 3. Security decisions
- ↳ 4. Regression anchors
- ↳ 5. Trust boundaries
- ▸ What we deleted
- ▸ Before / after: the difference in practice
- ▸ CLAUDE.md vs AGENTS.md vs README
- ▸ Conclusion
SOCIAL SHARE CARD GENERATOR