# ICDEV™ Project Rules

Project: ICDEV™ Project (IL4, CUI)
Type: python webapp

## Architecture

FORGE framework — deterministic Python tools in `tools/` with `--json` output.
Goals: `goals/manifest.md` | Tools: `tools/manifest.md` | Config: `args/`

## Rules

- All Python files: `# CUI // SP-CTI` header required
- snake_case naming, 100-char lines
- Tests: pytest + behave, >= 80% coverage
- Security: 0 CAT1 STIG, 0 critical vulns, 0 secrets

## Commands

- Context: `python tools/project/session_context_builder.py --format markdown`
- Tests: `pytest tests/ -v`
- SAST: `python tools/security/sast_runner.py --project-dir . --json`
- STIG: `python tools/compliance/stig_checker.py --project-id "" --json`

## MCP Categories

@security: sast_runner, dependency_auditor, secret_detector
@compliance: ssp_generator, stig_checker, sbom_generator, control_mapper
@build: test_writer, code_generator, scaffolder, formatter, linter
@project: project_status, project_create, session_context_builder

## Karpathy Principles — Pre-Design Engineering Gate

Before writing code, apply these 5 heuristics from `hardprompts/karpathy_principles.md`:

1. **State assumptions** — Name the constraints, inputs, invariants you're relying on. Unstated assumptions are where bugs hide.
2. **Enumerate interpretations** — For any ambiguous requirement, list the 2–4 ways it could be read before picking one. Surface them to the user if the choice is load-bearing.
3. **Prefer simpler** — Three similar lines beats one clever abstraction. Don't design for hypothetical future requirements. YAGNI.
4. **Bound your edit scope** — Only touch what the task requires. No drive-by refactors, no surrounding cleanup, no speculative error handling.
5. **Success criteria** — State how you'll know the change is done before writing it. If you can't write the test / acceptance check, the spec is incomplete.

Applies to: build, bug fix, refactor, TDD, and code review workflows.
