Zones

A
Frontends (not neuroflash app), CLIs, MCP, Experiments
vibe coding OK, auth via Zitadel required
B
neuroflash frontend app + all backend
supervised, review
C
Infrastructure, secrets
suggest only, no autonomous

Before Every PR

  • /simplify
  • /code-review
  • /security-review BC
  • No secrets
  • Dependencies audited
  • Tests pass

Context Management

  • /context → check fill %
  • 60% → act
  • 70%+ → already bad
  • /compact [instructions] → preserve continuity
  • /clear → fresh start (default between tasks)

Prompting Habits

  1. “Tell me your plan before writing code”
  2. Narrow scope — specific files, specific lines
  3. State what’s out of scope explicitly
  4. Plan → approve → execute

CLAUDE.md Minimum

Project Stack Commands Security Constraints Structure Conventions Boundaries

Plugins

User scope (everyone) superpowers context7 claude-md-management skill-creator
Project scope (Zone B repos) code-review security-guidance pr-review-kit