reviewing-project-guidance
Reviewing Project Guidance
Covers CLAUDE.md at any level: project root, .claude/CLAUDE.md, or scoped to a
subdirectory. All three are valid and serve different scopes; the review is the same.
CLAUDE.md loads into context on every session in its scope. That is what makes both its content and its length matter — an instruction here is paid for on every turn.
Scope, severity, and output format come from ../reviewing-claude-config/SKILL.md. Report only
what the changeset introduced or worsened — the fence is stated there.
Prefer being reached through that router rather than directly: it runs an always-on secret scan
before routing and a filter afterwards, and neither happens on a direct invocation. If you were
invoked directly, run the secret scan yourself using the patterns in
../reviewing-claude-config/reference/security-patterns.md, as Grep queries rather than the
shell commands a read-only grant cannot execute, and say in the findings that the filter did
not run. For permission-rule syntax, see ../reviewing-claude-config/reference/claude-code-requirements.md.