The rules are mostly things I got tired of re-explaining to Claude: no speculative abstractions, validate only at system boundaries, never bypass branch protection, integration tests hit real DBs, etc. Skills and agents are bundled alongside.
Link has the full breakdown of what's inside and how the overlay keeps your conversation history safe.