Verified against code.claude.com/docs/en/permission-modes and fixed 6 points: 1. acceptEdits: add PowerShell tool auto-approvals (Set-Content/Add-Content/ Clear-Content/Remove-Item + aliases) and env-prefix/process-wrapper note. 2. Protected paths: .claude exception is ONLY .claude/worktrees (was wrongly widened to commands/agents/skills); add per-mode protected-write table. 3. defaultMode:"auto" ignored from project files since v2.1.142+. 4. dontAsk: read-only Bash commands also run without allow rules; explicit ask rules are denied (not prompted). 5. auto conversational boundary: stays in force until user lifts it; Claude's own judgment doesn't lift it; lost on context compaction; use deny rule for hard. 6. auto consecutive-failure fallback: 3-in-a-row / 20-total pauses & re-prompts; -p non-interactive aborts the session. Plus dropped broad allow-rules on entry. Co-authored-by: chenchen <chenchen@xinghanlab.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Heicode Docs
当前 docs/ 只保留五类主线文档:
| 文档 | 用途 |
|---|---|
heicode.md |
Heicode 当前产品定位、系统边界和架构共识 |
plan.md |
按当前共识拆出的实施计划 |
heicode-runtime-auth-newapi-secret-design.md |
用户输入、登录用户复用、NewAPI 扣费映射、Azure Key Vault 凭证托管与短期凭证注入边界 |
heicode-manager-sub-swarm-progress-checklist.md |
Heicode Manager sub 模式、瀑布/敏捷、蜂群模式的已完成/未完成/依赖/风险/下一步进度清单 |
heicode-manager-standalone-execution-plan.md |
Heicode Manager 端可独立完成任务的执行计划、顺序、验收标准和边界 |
integration/Heicode-登录接口对接文档.md |
已上线登录接口对接文档 |
integration/agent-platform-request-contract.md |
Manager 请求 Agent 平台时携带的部署、日志、监控、事件与审计接口参数 |
deployment/azure-production-deploy-guardrails.md |
Azure VM / PostgreSQL / Redis / Agent / NewAPI 生产部署前的安全守卫、环境变量注入和验证计划 |
旧 Agent API 草案、旧里程碑、旧架构说明和旧上手材料不再作为实施依据。后续文档和实现以 heicode.md 与 plan.md 为准;生产部署操作以安全守卫文档约束,且不得覆盖产品/架构主线。
代码中的过渡期命名、旧接口注释或旧 UI 文案只作为现状参考;若与 heicode.md / plan.md 冲突,应先更新实现或另行补充当前主线文档,不得恢复旧 Agent/M1-M5 草案作为依据。