Rules
Registry 2026.10.1. False-positive rates are measured on 210 public repositories and shown with their sample size; below 30 reviewed findings a rate is “not yet established”. A rule over 5% reports at info and stays beta.
| ID | Check | Severity | Status | Measured |
|---|---|---|---|---|
CTX-S001 | No agent context file in repository | info | ga | 0/26 · not yet established |
CTX-S002 | Two or more tool-specific context files with no shared source | warning | ga | 0.0% FP (n=43, ≤8.2%) |
CTX-S003 | Broken import or reference to a missing context file | blocker | ga | 0/11 · not yet established |
CTX-S004 | Rule glob or path scope matches no files | warning | ga | 0/11 · not yet established |
CTX-S005 | Invalid frontmatter in a rule or instruction file | warning | beta | 0/1 · not yet established |
CTX-S006 | Deprecated context format in use | info | ga | 0/28 · not yet established |
CTX-D001 | Referenced path does not exist | info | beta | 12% FP (n=60, ≤22%) |
CTX-D002 | Referenced command or script is not defined | warning | ga | 0/14 · not yet established |
CTX-D003 | Stated package manager contradicts the lockfile | warning | beta | not yet established |
CTX-D004 | Referenced dependency absent from manifests | info | beta | 6/17 · not yet established |
CTX-D005 | Stated major version contradicts installed version | warning | ga | 0/6 · not yet established |
CTX-D006 | Context unchanged while the paths it cites changed heavily | info | beta | not yet established |
CTX-D007 | Architecture claim contradicted by the code model | warning | beta deferred | not yet established |
CTX-C001 | Same fact stated with different values across files or tools | blocker | beta | not yet established |
CTX-C002 | AGENTS.md and CLAUDE.md shared sections have diverged | warning | beta | 0/3 · not yet established |
CTX-C003 | Nested file overrides a parent with a different value | warning | beta | not yet established |
CTX-C004 | Natural-language contradiction between directives | warning | beta deferred | not yet established |
CTX-C005 | Team memory entry contradicts an instruction file | warning | beta cloud | not yet established |
CTX-B001 | Always-loaded context exceeds the token budget for a tool | warning | ga | 0/29 · not yet established |
CTX-B002 | Section duplicates README or docs content | info | beta | 0/2 · not yet established |
CTX-B003 | Generic boilerplate with no repository-specific content | info | beta | 0/5 · not yet established |
CTX-B004 | Same directive repeated across files | info | ga | 0.0% FP (n=70, ≤5.2%) |
CTX-X001 | Invisible or bidirectional Unicode in a context file | blocker | beta | not yet established |
CTX-X002 | Long encoded payload in a context file | warning | beta | not yet established |
CTX-X003 | Instruction to download and execute remote code | blocker | beta | not yet established |
CTX-X004 | Instruction to skip tests, disable checks or hide changes | warning | beta | not yet established |
CTX-X005 | Secret or credential in context or MCP config | blocker | beta | not yet established |
CTX-X006 | MCP server not pinned to a version | warning | ga | 0/22 · not yet established |
CTX-X007 | Remote MCP server over plain HTTP or without auth | warning | beta | not yet established |
CTX-X008 | Instruction links to a domain outside the allowlist | info | beta | not yet established |
CTX-X009 | Third-party skill or rule pack imported without a pinned version or hash | warning | beta | not yet established |
CTX-G001 | Context files not covered by CODEOWNERS | warning | ga | 0/5 · not yet established |
CTX-G002 | Generated context file edited by hand | blocker | beta deferred | not yet established |
CTX-G003 | Org-required policy missing from repository | blocker | beta cloud | not yet established |
CTX-G004 | Team memory entry expired or never reviewed | warning | beta cloud | not yet established |