Vellum Boundary Guard
Package Import Boundaries
Enforce these boundaries:
assistant/must not import fromgateway/via relative paths.gateway/must not import fromassistant/via relative paths.assistant/andskills/must not import from each other directly.- Runtime code must not import from
meta/. - Shared cross-package logic belongs in
packages/.
For tests that need behavior from another package, mock the boundary instead of importing real handlers.
HTTP And IPC Boundaries
- Public inbound HTTP endpoints belong in
gateway/. - New CLI-to-assistant interactions should use Unix socket IPC through the existing IPC route pattern.
- Events from assistant runtime code should use the assistant event hub rather than new HTTP endpoints when possible.
Security Ownership Boundaries
- Gateway owns trust rules and gateway security files.
- CES owns credential files.
- The assistant must not read gateway-owned directories directly.
- Clients must not read from the user's
~/.vellumdirectory. - Secrets must not be stored in workspace files.
Skill Boundaries
First-party skills run as separate processes and should communicate through supported contracts. Do not bypass skill isolation with direct relative imports.
Review Workflow
- Search changed imports and new route registrations.
- Identify any package-crossing dependency.
- Decide whether the correct home is a package-local module, a shared
packages/module, IPC, HTTP through gateway, or a skill contract. - If a violation exists, recommend the smallest boundary-preserving move.
Verification
Prefer existing guard tests when available, then add focused tests for any new boundary rule or route pattern.