Appearance
Catalog-Driven Reference
Rule Reference
This is the primary browsing surface for shipped lintai rules. The goal is fast scanning first, then deep rule context once you open a page.
Lane-first browsingThe directory is grouped by public lane first so the product model is visible immediately.
Human-authored proseExamples, caveats, and remediation live in checked-in Markdown.
Provider stays secondaryProvider identity is still visible, but no longer drives the main browsing experience.
Start With These
These are the current highest-signal community-facing rules based on the latest external validation work. SEC340 and SEC329 are the clearest quiet-default story; SEC324 and SEC352 remain strong sidecar controls:
- SEC340: Claude hook commands launching external packages dynamically at runtime
- SEC329: committed
mcp.jsonentries launching external packages dynamically at runtime - SEC352: unscoped
Bashgrants in AI-native frontmatter as a governance least-privilege control - SEC324: unpinned third-party GitHub Actions
Reading The Catalog
recommendedmeans quiet practical default coveragepreviewmeans broader contextual review outside the defaultthreat-reviewmeans explicit malicious, secret-bearing, or spyware-like reviewsupply-chainmeans reproducibility, provenance, and dependency hardening reviewcompatmeans config, schema, and policy contract reviewgovernancemeans shared authority and workflow policy reviewguidancemeans advice-oriented guidance and maintainability reviewadvisorymeans installed-package advisory reviewsecurityis a strong exploit, secret, or unsafe-execution signalhardeningis a least-privilege, provenance, or hygiene signalqualityis a contract or config correctness signalauditis a heuristic or triage-oriented signal
Public Lane
Recommended
Quiet practical default findings most teams should start with.
Public Lane
Preview
Broader contextual review outside the quiet default.
Public Lane
Threat Review
Explicit malicious, secret-bearing, or spyware-like review.
Public Lane
Supply Chain
Reproducibility, provenance, and dependency hardening review.
Public Lane
Compat
Config, schema, and policy contract review.
Public Lane
Governance
Shared authority and workflow policy review.
Public Lane
Guidance
Advice-oriented guidance and maintainability review.
Public Lane
Advisory
Installed-package advisory review.