Engineering Foundation
The reproducible environment, static correctness, architecture boundaries, and pre-commit / CI gates that make any change reviewable.
The pillar names, descriptions, icons, and clause ranges below come from
AI-CONTRIBUTOR-RULE-CATALOG.json. This page owns the presentation only.
The reproducible environment, static correctness, architecture boundaries, and pre-commit / CI gates that make any change reviewable.
Secrets handling, dependency and CI/CD security, authorization boundaries, and threat modeling.
Runtime validation, testing strategy, accessibility, failure handling and observability, and performance and reliability.
Supply-chain transparency, branch protection, and release governance.
How AI agents, shared skills, MCP servers, and delegated agents are governed in the repository.
AI-specific risks (prompt injection, untrusted input, capability scoping, allowlists, cost ceilings) and data protection for AI workflows.
Human approval, guardrail evidence, policy ownership, AI licensing and attribution, AI credential lifecycle, model/provider changes, and AI incident response.
Each pillar is a contiguous clause range in the catalog. Follow the clause links to the full specification for the rule text and audit level.