framework_eng/rules/vanessa-security-warning/SKILL.md
Security Warning in the event log requires visual verification
npx skillsauth add steelmorgan/1c-agent-based-dev-framework vanessa-security-warningInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Trigger: a
Security Warningentry in the event log. When it fires, apply thegui-controlskill (framework/skills/tool-usage/browser-ui/gui-control/SKILL.md) andscreenshot(framework/skills/tool-usage/browser-ui/screenshot/SKILL.md).
| Requirement | Description |
|------------|----------|
| Event log as trigger | An entry for Security Warning in the event log → mandatory visual verification |
| Visual verification is mandatory | MUST use a VA MCP screenshot of the real test client window |
| Do not rely on X11 heuristics | Do not draw conclusions only from wmctrl/xwininfo/window titles; obtain the visual artifact via va-visual-check |
| Screenshot is validated | Check that the PNG is not empty/black; handle Linux/Xvfb and fallback cases via va-visual-check |
| Trust-flow only for the first run | The first run after changing the EPF does not count as a valid test run |
depends_on:
development
1C server maintenance webhooks: container restart and external component cache cleanup
development
Interactive DAP debugging of a single BSL procedure
tools
Rules for using RLM tools for project search and navigation in 1C/BSL
development
Creates web applications and routes on Winow (a web server on OneScript and Autumn). Use when working with a web server on OneScript, routing, or Winow controllers.