This document provides guidance for AI coding agents working on the SetupSentry codebase.
SetupSentry is a static security scanner for repository instructions. It scans markdown files and shell scripts for dangerous patterns without executing them.
- CLI (
src/cli.ts): Entry point, argument parsing - Scan (
src/scan.ts): Orchestration, file processing - Engine (
src/engine.ts): Rule execution - Rules (
src/rules/): Individual security rules (SS001-SS010) - Discovery (
src/discovery.ts): File finding and filtering - Markdown (
src/markdown.ts): Code block extraction - Reporters (
src/reporters/): Output formatting (pretty, JSON)
interface Rule {
id: string;
severity: Severity;
title: string;
description: string;
scan(context: ScanContext): Finding[];
}npm install # Install dependencies
npm run build # Compile TypeScript to dist/
npm run typecheck # Type checking without emit
npm run lint # Run ESLint
npm test # Run Vitest tests
npm pack # Package for npm publication (dry-run with --dry-run)- Every rule must have positive and negative tests
- Tests are in
tests/directory - Run
npm testto verify changes - Tests must never execute commands found in fixtures
- Each rule is in its own file:
src/rules/ssXXX.ts - Rules are registered in
src/rules/index.ts - Rules must be deterministic and offline
- Prefer false negatives over false positives
- Every finding must include: ruleId, severity, file, line, title, evidence, explanation, remediation
- NEVER execute discovered commands during tests or development
- Preserve deterministic/offline behavior
- Do not add runtime dependencies unless absolutely necessary
- Use strict TypeScript (no
anyunless genuinely needed) - All code is ESM (import/export, not require)
- Create
src/rules/ssXXX.tsimplementing the Rule interface - Add the rule to
src/rules/index.ts - Add tests to
tests/rules.test.ts - Update documentation in README.md
Files scanned:
README*.md,AGENTS.md,CLAUDE.md,CLAUDE.local.md.cursorrules,.cursor/rules/**/*.md,.cursor/rules/**/*.mdc.github/copilot-instructions.mdsetup.sh,install.sh,scripts/setup.sh,scripts/install.sh
Excluded directories:
node_modules,.git,dist,build,coverage,vendor