Files
MCP-Project-bus/evidence/CLAUDE_REVIEW_BRIEF.md
T
2026-07-30 02:14:43 +02:00

1.6 KiB

Independent Claude Review Brief

Role

Act as independent Lead Reviewer for WP-PA-001 — Epimonos Project Bus MVP. Do not modify the implementation during the first review pass. The implementer is Codex; reviewer identity and evidence must remain independent.

Review objectives

  1. Verify every requested capability against code, schema, tests, and docs.
  2. Challenge BASDM separations:
    • PA cannot make product/architecture/gate decisions;
    • implementer cannot review or accept own work;
    • only authorized PM/PO actors close gates and release baselines.
  3. Inspect transaction boundaries, idempotency replay, concurrent claims, cursor semantics, and projection/event atomicity.
  4. Assess authentication, cross-project isolation, origin handling, input validation, SQL usage, audit immutability, and operational failure modes.
  5. Check MCP 2025-03-26 request/response interoperability assumptions.
  6. Confirm the core contains no Sandbox/Epimonos product-specific logic.
  7. Confirm documentation accurately states all production gaps.

Required output

Return:

  • verdict: APPROVE, CHANGES_REQUESTED, or REJECT;
  • numbered findings with severity Critical/High/Medium/Low;
  • exact file and line reference;
  • exploit/failure scenario;
  • required correction and suggested verification;
  • scope-completeness matrix;
  • residual-risk statement.

Run at minimum:

PYTHONPATH=src python -m unittest discover -v
PYTHONPATH=src python -m compileall -q src tests

Also add adversarial tests where a claimed invariant is not adequately proven. Do not accept solely because the existing suite is green.