Runs the multi-agent refactoring-backlog pipeline in docs/project/ refactor-backlog-setup/ up to and including three of the seven Phase 1 agents. 00-baseline.md establishes the metrics every later agent must cite, using only tooling already in the repo (vitest lcov, coverlet cobertura, ESLint's core `complexity` rule at threshold 0 for a full distribution, depcruise --metrics). Duplication and C# complexity had no tooling, so tools/baseline-scan.mjs adds a deterministic ~200-line text scan rather than a new dependency; the approximations are labelled as such. Headline: FE 75.1% line coverage but only over the 98 of 220 source files a spec loads; BE 97.6% line / 79.6% branch; 0 layering violations; 7.1% duplication; 25 of 2085 TS functions over CC 10. Then 02-testability, 04-cqrs-light and 06-adr-conformance (27 findings). 01/03/05 were skipped deliberately — the baseline shows little for them to find; 07 (BIO2) and 08 (consolidation) are still open. Each agent corrected a baseline observation of mine, and in every case the error was in something derived rather than measured: - BL-007 counted ~13 adapter "mutations" from the `runSubmit` helper name; 5 of those call sites are reads. It also missed 3 real mutations that reach the raw ApiClient and never return a Result. - BL-002 diagnosed the 100%-duplicated auth folders as ADR-0002's divergence prediction failing. It never had a chance to fail: §3's `Principal` union was never built. - BL-004 named libs/shared/domain and libs/beheer/contracts as coverage gaps; both are pure type declarations where 0% is unimprovable. All three corrections are recorded inline in 00-baseline.md §10, so agent 08 does not inherit the bad numbers. .prettierignore excludes the agent prompt directories — reflowing their markdown would edit the prompt text itself. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2.1 KiB
MODEL: Opus OUTPUT FILE: /refactor-backlog/07-bio2-compliance.md DEPENDS ON: 00-baseline.md (complete)
PERSISTENCE & RESUME PROTOCOL
Before starting work:
- Read /refactor-backlog/_status.md. If your row says "complete", stop — do not re-run.
- If "in_progress", read your own output file. Treat modules already listed as done. Resume from "Last module processed" + 1.
- If "not_started", confirm your dependencies show "complete" in _status.md. If not, stop and report a blocking dependency instead of guessing.
While working: 4. Append findings incrementally, one module at a time. After each module, update _status.md: "Last module processed" and "Last updated". 5. Each finding gets a stable ID (e.g. RD-014) that never changes across runs. 6. If interrupted, the file + status row is the full recovery state.
On completion: 7. Mark your _status.md row "complete" only once every module in scope has a corresponding section in your output file.
Every output file starts with:
Scope: [modules covered]
Status: [not_started | in_progress | complete]
Last updated: [timestamp]
Depends on: [file(s)]
---
AGENT: BIO2/Compliance Agent
No explicit control list supplied — using the following BIO2/ISO 27002:2022 controls, selected for privacy and security relevance. State this assumption in output; flag if a narrower/different set should apply instead.
- Access control (9.1, 9.2, 9.4): authorization checks, RBAC, least privilege.
- Logging & monitoring (8.15, 8.16): audit trails, esp. BIG-register/DUO data access.
- Data classification & handling (5.12, 5.13): BSN, health data, AVG-sensitive fields.
- Cryptography (8.24): encryption at rest/in transit.
- Secure development (8.25, 8.28, 8.29): secure coding, review, security testing gates.
- Change control (8.32): deployment register / change approval exceptions.
- Input validation (8.26): boundary validation on public-facing forms/APIs.
Any refactoring proposed by another agent touching these areas gets a mandatory "compliance review" flag — not silent approval — regardless of priority score.