# Guardrails category reference

From the documents and code graph analysis, extract concrete, actionable rules in these categories. Only include a category if you found real evidence for it.

- Architecture constraints: layer boundaries, module dependencies, forbidden imports, directory ownership rules (e.g. "src/api/ must not import from src/ui/"). Verify actual import boundaries with the project-selected analysis tools.
- File organization: avoid god-files and dumping-ground constants. Each file should have one clear responsibility. Split by domain or feature instead (e.g. `user-constants.ts`, `order-types.ts`, `auth-config.ts`). A file that imports from 5+ unrelated modules is a sign it should be split.
- Naming conventions: file naming, component naming, API route conventions, branch naming
- Code style: formatter config, lint rules, import ordering, max line length. Derive from actual config files.
- Testing rules: test file locations, naming, coverage gates, what must be tested before merge
- Build & deployment: build commands, env requirements, deployment targets, CI gates
- Data & state: migration rules, schema change process, state management patterns
- Security: auth boundaries, input validation requirements, secrets handling
- Dependencies: package manager, lockfile rules, upgrade policy, forbidden packages
- Git workflow: branch naming, commit message format, PR process (platform-specific from `opencode-onboard.json`)
- Domain-specific rules: anything in `openspec/config.yaml` context or `ARCHITECTURE.md` constraints/risks sections

Each rule must be:
- Concrete: "Use `pnpm` not `npm`" not "Use the right package manager"
- Evidence-based: derive from the files/code graph you analyzed, do not invent rules
- Actionable: an agent can check it before acting

## Skill template

Write (or update) `.agents/skills/ob-guardrails-project/SKILL.md`:

```markdown
---
name: ob-guardrails-project
description: Project-specific rules and constraints extracted from ARCHITECTURE.md. Load this skill before implementing any change to understand boundaries, conventions, and constraints for this codebase.
license: MIT
---

# Project Guardrails

> Auto-generated by `/make-guardrails`. Regenerate with the same command when architecture or conventions change.

## Architecture Constraints
- <rule>
- <rule>

## Naming Conventions
- <rule>

## Code Style
- <rule>

## Testing
- <rule>

## Build & Deployment
- <rule>

## Data & State
- <rule>

## Security
- <rule>

## Dependencies
- <rule>

## Git Workflow
- <rule>

<!-- Last updated: <current ISO timestamp> -->
```

Only include sections that have real rules. Omit empty sections.
