# company-dossier - Doramagic AI Context Pack

> 定位：安装前体验与判断资产。它帮助宿主 AI 有一个好的开始，但不代表已经安装、执行或验证目标项目。

## 充分原则

- **充分原则，不是压缩原则**：AI Context Pack 应该充分到让宿主 AI 在开工前理解项目价值、能力边界、使用入口、风险和证据来源；它可以分层组织，但不以最短摘要为目标。
- **压缩策略**：只压缩噪声和重复内容，不压缩会影响判断和开工质量的上下文。

## 给宿主 AI 的使用方式

你正在读取 Doramagic 为 company-dossier 编译的 AI Context Pack。请把它当作开工前上下文：帮助用户理解适合谁、能做什么、如何开始、哪些必须安装后验证、风险在哪里。不要声称你已经安装、运行或执行了目标项目。

## Claim 消费规则

- **事实来源**：Repo Evidence + Claim/Evidence Graph；Human Wiki 只提供显著性、术语和叙事结构。
- **事实最低状态**：`supported`
- `supported`：可以作为项目事实使用，但回答中必须引用 claim_id 和证据路径。
- `weak`：只能作为低置信度线索，必须要求用户继续核实。
- `inferred`：只能用于风险提示或待确认问题，不能包装成项目事实。
- `unverified`：不得作为事实使用，应明确说证据不足。
- `contradicted`：必须展示冲突来源，不得替用户强行选择一个版本。

## 它最适合谁

- **正在使用 Claude/Codex/Cursor/Gemini 等宿主 AI 的开发者**：README 或插件配置提到多个宿主 AI。 证据：`README.md` Claim：`clm_0003` supported 0.86
- **希望把专业流程带进宿主 AI 的用户**：仓库包含 Skill 文档。 证据：`integrations/claude-skill/company-dossier/SKILL.md` Claim：`clm_0004` supported 0.86

## 它能做什么

- **AI Skill / Agent 指令资产库**（可做安装前预览）：项目包含可被宿主 AI 读取的 Skill 或 Agent 指令文件，可用于把专业流程带入 Claude、Codex、Cursor 等宿主。 证据：`integrations/claude-skill/company-dossier/SKILL.md` Claim：`clm_0001` supported 0.86
- **命令行启动或安装流程**（需要安装后验证）：项目文档中存在可执行命令，真实使用需要在本地或宿主环境中运行这些命令。 证据：`README.md`, `packages/company-dossier/README.md`, `packages/company-dossier/deploy/README.md` Claim：`clm_0002` supported 0.86

## 怎么开始

- `npx company-dossier acme.com          # writes a "<Company> DOSSIER/" folder + dossier.json` 证据：`README.md` Claim：`clm_0005` supported 0.86
- `npm i -g company-dossier              # or install globally` 证据：`README.md` Claim：`clm_0006` supported 0.86
- `npm i -g @render/cli   # or: brew install render` 证据：`packages/company-dossier/deploy/README.md` Claim：`clm_0007` supported 0.86
- `curl -s http://localhost:8787/health      # -> {"status":"ok"}` 证据：`packages/company-dossier/deploy/README.md` Claim：`clm_0008` supported 0.86
- `curl -s https://mcp.companydossier.lol/health   # -> {"status":"ok"}` 证据：`packages/company-dossier/deploy/README.md` Claim：`clm_0009` supported 0.86
- `npm install -g company-dossier` 证据：`packages/company-dossier/README.md` Claim：`clm_0010` supported 0.86
- `npx company-dossier acme.com` 证据：`packages/company-dossier/README.md` Claim：`clm_0005` supported 0.86, `clm_0011` supported 0.86
- `npx company-dossier-mcp-http` 证据：`packages/company-dossier/README.md` Claim：`clm_0012` supported 0.86

## 继续前判断卡

- **当前建议**：先做研究框架试用
- **为什么**：这个项目面向研究工作流，核心风险是资料可信度和输出质量；先用 Prompt Preview 验证研究框架，再在隔离环境试装。

### 30 秒判断

- **现在怎么做**：先做研究框架试用
- **最小安全下一步**：先用 Prompt Preview 验证研究框架；满意后再隔离试装
- **先别相信**：研究结论、引用和实验结果不能在安装前相信。
- **继续会触碰**：研究判断、命令执行、宿主 AI 配置

### 现在可以相信

- **适合人群线索：正在使用 Claude/Codex/Cursor/Gemini 等宿主 AI 的开发者**（supported）：有 supported claim 或项目证据支撑，但仍不等于真实安装效果。 证据：`README.md` Claim：`clm_0003` supported 0.86
- **适合人群线索：希望把专业流程带进宿主 AI 的用户**（supported）：有 supported claim 或项目证据支撑，但仍不等于真实安装效果。 证据：`integrations/claude-skill/company-dossier/SKILL.md` Claim：`clm_0004` supported 0.86
- **能力存在：AI Skill / Agent 指令资产库**（supported）：可以相信项目包含这类能力线索；是否适合你的具体任务仍要试用或安装后验证。 证据：`integrations/claude-skill/company-dossier/SKILL.md` Claim：`clm_0001` supported 0.86
- **能力存在：命令行启动或安装流程**（supported）：可以相信项目包含这类能力线索；是否适合你的具体任务仍要试用或安装后验证。 证据：`README.md`, `packages/company-dossier/README.md`, `packages/company-dossier/deploy/README.md` Claim：`clm_0002` supported 0.86
- **存在 Quick Start / 安装命令线索**（supported）：可以相信项目文档出现过启动或安装入口；不要因此直接在主力环境运行。 证据：`README.md` Claim：`clm_0005` supported 0.86

### 现在还不能相信

- **研究结论、引用和实验结果不能在安装前相信。**（unverified）：研究 Skill 可以组织问题和路径，但不能替代真实资料检索、论文核验和实验复现。
- **是否适合你的具体研究领域不能直接相信。**（unverified）：Skill 覆盖很多研究主题，不代表对你的领域、资料要求和可信度标准足够。
- **真实输出质量不能在安装前相信。**（unverified）：Prompt Preview 只能展示引导方式，不能证明真实项目中的结果质量。
- **宿主 AI 版本兼容性不能在安装前相信。**（unverified）：Claude、Cursor、Codex、Gemini 等宿主加载规则和版本差异必须在真实环境验证。
- **不会污染现有宿主 AI 行为，不能直接相信。**（inferred）：Skill、plugin、AGENTS/CLAUDE/GEMINI 指令可能改变宿主 AI 的默认行为。 证据：`AGENTS.md`, `integrations/claude-skill/company-dossier/SKILL.md`
- **可安全回滚不能默认相信。**（unverified）：除非项目明确提供卸载和恢复说明，否则必须先在隔离环境验证。
- **真实安装后是否与用户当前宿主 AI 版本兼容？**（unverified）：兼容性只能通过实际宿主环境验证。
- **项目输出质量是否满足用户具体任务？**（unverified）：安装前预览只能展示流程和边界，不能替代真实评测。

### 继续会触碰什么

- **研究判断**：问题拆解、资料路径、实验路径、结论结构和可信度判断。 原因：研究型 Skill 可能让输出看起来更专业，但不能替代真实证据核验。
- **命令执行**：包管理器、网络下载、本地插件目录、项目配置或用户主目录。 原因：运行第一条命令就可能产生环境改动；必须先判断是否值得跑。 证据：`README.md`, `packages/company-dossier/README.md`, `packages/company-dossier/deploy/README.md`
- **宿主 AI 配置**：Claude/Codex/Cursor/Gemini/OpenCode 等宿主的 plugin、Skill 或规则加载配置。 原因：宿主配置会改变 AI 后续工作方式，可能和用户已有规则冲突。 证据：`AGENTS.md`, `integrations/claude-skill/company-dossier/SKILL.md`
- **本地环境或项目文件**：安装结果、插件缓存、项目配置或本地依赖目录。 原因：安装前无法证明写入范围和回滚方式，需要隔离验证。 证据：`README.md`, `packages/company-dossier/README.md`, `packages/company-dossier/deploy/README.md`
- **宿主 AI 上下文**：AI Context Pack、Prompt Preview、Skill 路由、风险规则和项目事实。 原因：导入上下文会影响宿主 AI 后续判断，必须避免把未验证项包装成事实。

### 最小安全下一步

- **先跑 Prompt Preview**：先验证它能否正确界定研究问题和证据边界，不要先相信研究输出。（适用：任何项目都适用，尤其是输出质量未知时。）
- **只在隔离目录或测试账号试装**：避免安装命令污染主力宿主 AI、真实项目或用户主目录。（适用：存在命令执行、插件配置或本地写入线索时。）
- **先备份宿主 AI 配置**：Skill、plugin、规则文件可能改变 Claude/Cursor/Codex 的默认行为。（适用：存在插件 manifest、Skill 或宿主规则入口时。）
- **安装后只验证一个最小任务**：先验证加载、兼容、输出质量和回滚，再决定是否深用。（适用：准备从试用进入真实工作流时。）

### 退出方式

- **保留安装前状态**：记录原始宿主配置和项目状态，后续才能判断是否可恢复。
- **准备移除宿主 plugin / Skill / 规则入口**：如果试装后行为异常，可以把宿主 AI 恢复到试装前状态。
- **保留资料和结论核验清单**：如果后续发现引用或实验路径不可靠，可以回到证据边界阶段重新校验。
- **记录安装命令和写入路径**：没有明确卸载说明时，至少要知道哪些目录或配置需要手动清理。
- **如果没有回滚路径，不进入主力环境**：不可回滚是继续前阻断项，不应靠信任或运气继续。

## 哪些只能预览

- 解释项目适合谁和能做什么
- 基于项目文档演示典型对话流程
- 帮助用户判断是否值得安装或继续研究

## 哪些必须安装后验证

- 真实安装 Skill、插件或 CLI
- 执行脚本、修改本地文件或访问外部服务
- 验证真实输出质量、性能和兼容性

## 边界与风险判断卡

- **把安装前预览误认为真实运行**：用户可能高估项目已经完成的配置、权限和兼容性验证。 处理方式：明确区分 prompt_preview_can_do 与 runtime_required。 Claim：`clm_0013` inferred 0.45
- **命令执行会修改本地环境**：安装命令可能写入用户主目录、宿主插件目录或项目配置。 处理方式：先在隔离环境或测试账号中运行。 证据：`README.md`, `packages/company-dossier/README.md`, `packages/company-dossier/deploy/README.md` Claim：`clm_0014` supported 0.86
- **待确认**：真实安装后是否与用户当前宿主 AI 版本兼容？。原因：兼容性只能通过实际宿主环境验证。
- **待确认**：项目输出质量是否满足用户具体任务？。原因：安装前预览只能展示流程和边界，不能替代真实评测。
- **待确认**：安装命令是否需要网络、权限或全局写入？。原因：这影响企业环境和个人环境的安装风险。

## 开工前工作上下文

### 加载顺序

- 先读取 how_to_use.host_ai_instruction，建立安装前判断资产的边界。
- 读取 claim_graph_summary，确认事实来自 Claim/Evidence Graph，而不是 Human Wiki 叙事。
- 再读取 intended_users、capabilities 和 quick_start_candidates，判断用户是否匹配。
- 需要执行具体任务时，优先查 role_skill_index，再查 evidence_index。
- 遇到真实安装、文件修改、网络访问、性能或兼容性问题时，转入 risk_card 和 boundaries.runtime_required。

### 任务路由

- **AI Skill / Agent 指令资产库**：先基于 role_skill_index / evidence_index 帮用户挑选可用角色、Skill 或工作流。 边界：可做安装前 Prompt 体验。 证据：`integrations/claude-skill/company-dossier/SKILL.md` Claim：`clm_0001` supported 0.86
- **命令行启动或安装流程**：先说明这是安装后验证能力，再给出安装前检查清单。 边界：必须真实安装或运行后验证。 证据：`README.md`, `packages/company-dossier/README.md`, `packages/company-dossier/deploy/README.md` Claim：`clm_0002` supported 0.86

### 上下文规模

- 文件总数：110
- 重要文件覆盖：40/110
- 证据索引条目：64
- 角色 / Skill 条目：1

### 证据不足时的处理

- **missing_evidence**：说明证据不足，要求用户提供目标文件、README 段落或安装后验证记录；不要补全事实。
- **out_of_scope_request**：说明该任务超出当前 AI Context Pack 证据范围，并建议用户先查看 Human Manual 或真实安装后验证。
- **runtime_request**：给出安装前检查清单和命令来源，但不要替用户执行命令或声称已执行。
- **source_conflict**：同时展示冲突来源，标记为待核实，不要强行选择一个版本。

## Prompt Recipes

### 适配判断

- 目标：判断这个项目是否适合用户当前任务。
- 预期输出：适配结论、关键理由、证据引用、安装前可预览内容、必须安装后验证内容、下一步建议。

```text
请基于 company-dossier 的 AI Context Pack，先问我 3 个必要问题，然后判断它是否适合我的任务。回答必须包含：适合谁、能做什么、不能做什么、是否值得安装、证据来自哪里。所有项目事实必须引用 evidence_refs、source_paths 或 claim_id。
```

### 安装前体验

- 目标：让用户在安装前感受核心工作流，同时避免把预览包装成真实能力或营销承诺。
- 预期输出：一段带边界标签的体验剧本、安装后验证清单和谨慎建议；不含真实运行承诺或强营销表述。

```text
请把 company-dossier 当作安装前体验资产，而不是已安装工具或真实运行环境。

请严格输出四段：
1. 先问我 3 个必要问题。
2. 给出一段“体验剧本”：用 [安装前可预览]、[必须安装后验证]、[证据不足] 三种标签展示它可能如何引导工作流。
3. 给出安装后验证清单：列出哪些能力只有真实安装、真实宿主加载、真实项目运行后才能确认。
4. 给出谨慎建议：只能说“值得继续研究/试装”“先补充信息后再判断”或“不建议继续”，不得替项目背书。

硬性边界：
- 不要声称已经安装、运行、执行测试、修改文件或产生真实结果。
- 不要写“自动适配”“确保通过”“完美适配”“强烈建议安装”等承诺性表达。
- 如果描述安装后的工作方式，必须使用“如果安装成功且宿主正确加载 Skill，它可能会……”这种条件句。
- 体验剧本只能写成“示例台词/假设流程”：使用“可能会询问/可能会建议/可能会展示”，不要写“已写入、已生成、已通过、正在运行、正在生成”。
- Prompt Preview 不负责给安装命令；如用户准备试装，只能提示先阅读 Quick Start 和 Risk Card，并在隔离环境验证。
- 所有项目事实必须来自 supported claim、evidence_refs 或 source_paths；inferred/unverified 只能作风险或待确认项。

```

### 角色 / Skill 选择

- 目标：从项目里的角色或 Skill 中挑选最匹配的资产。
- 预期输出：候选角色或 Skill 列表，每项包含适用场景、证据路径、风险边界和是否需要安装后验证。

```text
请读取 role_skill_index，根据我的目标任务推荐 3-5 个最相关的角色或 Skill。每个推荐都要说明适用场景、可能输出、风险边界和 evidence_refs。
```

### 风险预检

- 目标：安装或引入前识别环境、权限、规则冲突和质量风险。
- 预期输出：环境、权限、依赖、许可、宿主冲突、质量风险和未知项的检查清单。

```text
请基于 risk_card、boundaries 和 quick_start_candidates，给我一份安装前风险预检清单。不要替我执行命令，只说明我应该检查什么、为什么检查、失败会有什么影响。
```

### 宿主 AI 开工指令

- 目标：把项目上下文转成一次对话开始前的宿主 AI 指令。
- 预期输出：一段边界明确、证据引用明确、适合复制给宿主 AI 的开工前指令。

```text
请基于 company-dossier 的 AI Context Pack，生成一段我可以粘贴给宿主 AI 的开工前指令。这段指令必须遵守 not_runtime=true，不能声称项目已经安装、运行或产生真实结果。
```

## 角色 / Skill 索引

- 共索引 1 个角色 / Skill / 项目文档条目。

- **company-dossier**（skill）：Use this when the user wants to research a company, build a company profile or dossier, run a due-diligence brief, vet a vendor, prep for a sales call, evaluate an employer, or otherwise compile a sourced intelligence report on an organization from PUBLIC data. Triggers on "research company ", "build a dossier/profile on", "due diligence on", "who is company ", "company background check", "competitive intel", "vet t… 激活提示：当用户任务与“company-dossier”描述的流程高度相关时，先用它做安装前体验，再决定是否安装。 证据：`integrations/claude-skill/company-dossier/SKILL.md`

## 证据索引

- 共索引 64 条证据。

- **Company Dossier**（documentation）：Know any company in minutes — a complete, sourced file built from the public record. 证据：`README.md`
- **Growth**（documentation）：Discoverability and distribution playbooks — how Company Dossier gets found by search engines and AI assistants, and the off-site work that compounds it. 证据：`growth/README.md`
- **Per-company subdomains — .companydossier.lol**（documentation）：Per-company subdomains — .companydossier.lol 证据：`infrastructure/README.md`
- **Company Dossier — AI assistant integrations**（documentation）：Company Dossier — AI assistant integrations 证据：`integrations/README.md`
- **Reports**（documentation）：Point-in-time audit artifacts for Company Dossier. Each report records the tools run, what was found, and what if anything was fixed. They are dated snapshots, not living docs — re-run the relevant checks before relying on a finding. 证据：`reports/README.md`
- **ChatGPT App Apps SDK / MCP — Company Dossier**（documentation）：ChatGPT App Apps SDK / MCP — Company Dossier 证据：`integrations/chatgpt/apps-sdk/README.md`
- **company-dossier**（documentation）：Build a complete, sourced intelligence dossier on any company from public data — CLI, library and MCP server. 证据：`packages/company-dossier/README.md`
- **Deploying the company-dossier remote MCP server**（documentation）：Deploying the company-dossier remote MCP server 证据：`packages/company-dossier/deploy/README.md`
- **Package**（package_manifest）：{ "name": "companydossier-infrastructure", "version": "1.0.0", "private": true, "type": "module", "description": "Deploy tooling for per-company dossier subdomains S3 + CloudFront . Not published.", "bin": { "deploy-dossier": "deploy-dossier.mjs" }, "dependencies": { "@aws-sdk/client-s3": "^3.600.0" } } 证据：`infrastructure/package.json`
- **Package**（package_manifest）：{ "name": "companydossier-site-build", "version": "0.0.0", "private": true, "type": "module", "description": "Build tooling for the companydossier.lol static site not published .", "scripts": { "build": "node build.mjs", "og": "node render-og.mjs" }, "devDependencies": { "@resvg/resvg-js": "^2.6.2" } } 证据：`site/package.json`
- **Package**（package_manifest）：{ "name": "company-dossier", "version": "0.3.0", "description": "Build a complete, sourced intelligence dossier on any company from public data — CLI, library and MCP server.", "license": "MIT", "author": "EVERJUST", "type": "module", "engines": { "node": " =18" }, "bin": { "company-dossier": "dist/cli.js", "company-dossier-mcp": "dist/mcp.js", "company-dossier-mcp-http": "dist/mcp-http.js" }, "main": "dist/index.js", "types": "dist/index.d.ts", "exports": { ".": { "types": "./dist/index.d.ts", "import": "./dist/index.js" } }, "files": "dist", "README.md" , "keywords": "osint", "company-research", "competitive-intelligence", "dossier", "due-diligence", "business-intelligence", "company-data… 证据：`packages/company-dossier/package.json`
- **AGENTS.md — Company Dossier**（documentation）：Guidance for AI agents working in this repository and for agents deciding whether to use Company Dossier as a tool . 证据：`AGENTS.md`
- **Company Dossier**（skill_instruction）：Build a complete, sourced intelligence dossier on any company from PUBLIC data. Output is a nine-section brief where every claim is attributed to a source and tagged with a confidence level . Public sources only. 证据：`integrations/claude-skill/company-dossier/SKILL.md`
- **License**（source_file）：Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files the "Software" , to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: 证据：`LICENSE`
- **Cli**（source_file）：import { buildDossier, type BuildOptions, type SectionId, SECTIONS } from './core.js'; import { writeDossier, generateSite } from './index.js'; ⋮---- type OutputFormat = 'folder' 'site'; type DeployTarget = 'none' 'gh-pages'; ⋮---- interface ParsedArgs { target?: string; out: string; json: boolean; quiet: boolean; sections?: SectionId ; maxPages?: number; skipSocialProbe: boolean; format: OutputFormat; deploy: DeployTarget; subdomain?: string; noindex: boolean; help: boolean; version: boolean; error?: string; } function parseArgs argv: string : ParsedArgs async function main : Promise async function deployGhPages siteDir: string, log: msg: string = void : Promise ⋮---- const run = cmd: stri… 证据：`packages/company-dossier/src/cli.ts`
- **Website**（source_file）：import { fetchText, sleep } from '../utils.js'; export interface PageData { url: string; title: string; description: string; headings: string ; textContent: string; } export interface WebsiteData { url: string; title: string; description: string; keywords: string ; socialLinks: string ; emails: string ; phones: string ; schemaOrg: unknown null; sitemapUrls: string ; robotsTxt: string; rawHtml: string; pages: PageData ; allEmails: string ; allPhones: string ; pageCount: number; error?: string; } export type ProgressCallback = message: string = void; export interface WebsiteOptions { maxPages?: number; progress?: ProgressCallback; } function stripHtml html: string : string function extractTit… 证据：`packages/company-dossier/src/collectors/website.ts`
- **Core**（source_file）：import { collectDns, type DnsData } from './collectors/dns.js'; import { collectWebsite, type WebsiteData } from './collectors/website.js'; import { collectWayback, type WaybackData } from './collectors/wayback.js'; import { extractTechStack, type TechStackData } from './collectors/techstack.js'; import { collectSearch, type SearchData } from './collectors/search.js'; import { looksLikeDomain, toDomain, todayISO, titleCase } from './utils.js'; export type ProgressCallback = message: string = void; ⋮---- export type SectionId = typeof SECTIONS number ; export interface BuildOptions { out?: string; json?: boolean; apiKeys?: { anthropic?: string; key: string : string undefined; }; sections?: S… 证据：`packages/company-dossier/src/core.ts`
- **Mcp Server**（source_file）：import { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js'; import { z } from 'zod'; import { buildDossier, SECTIONS, type SectionId } from './core.js'; ⋮---- export function registerTools server: McpServer : void export function createServer : McpServer 证据：`packages/company-dossier/src/mcp-server.ts`
- **Discoverability & AI-citation playbook**（documentation）：Discoverability & AI-citation playbook 证据：`growth/DISCOVERABILITY.md`
- **Off-site submission kit ready to paste**（documentation）：Off-site submission kit ready to paste 证据：`growth/OFFSITE_SUBMISSIONS.md`
- **Company Dossier — Knowledge Base**（documentation）：This directory is written in the Open Knowledge Format OKF v0.1 — a directory of markdown files with YAML frontmatter — so AI agents and humans can consume it without translation. It describes what Company Dossier is, the concepts it works with, and how it works. 证据：`knowledge/index.md`
- **Ecosystem**（documentation）：Open-source repositories and tools in the broader company intelligence / OSINT landscape. Organized by category with relevance notes for dossier builders. 证据：`methodology/ECOSYSTEM.md`
- **Company Dossier**（documentation）：The complete playbook for building intelligence packages on private companies 证据：`methodology/OVERVIEW.md`
- **Sources**（documentation）：Repositories, tools, and methodologies that directly informed or were used in building the BROGAV dossier. 证据：`methodology/SOURCES.md`
- **Output Structure Architecture**（documentation）：This document defines the folder architecture, file conventions, and design rationale for a finished company intelligence dossier. Based on the BROGAV Solutions dossier June 2026 . 证据：`methodology/architecture.md`
- **Building the BROGAV Solutions Intelligence Dossier: A Case Study**（documentation）：Building the BROGAV Solutions Intelligence Dossier: A Case Study 证据：`methodology/case_study.md`
- **Collection Phases**（documentation）：This document provides detailed playbooks for all six data collection methods used in the dossier-building process. Each phase can be executed independently or as part of the full pipeline. 证据：`methodology/collection_phases.md`
- **YAML Frontmatter Templates**（documentation）：Copy-paste templates for every file type in the dossier. Every .md file must have frontmatter. 证据：`methodology/frontmatter.md`
- **Lessons Learned**（documentation）：What worked, what didn't, and what we'd do differently next time. Based on building the BROGAV Solutions dossier June 2026 . 证据：`methodology/lessons_learned.md`
- **Media Capture: Overcoming Rate Limits & Downloading Video/Audio Across Platforms**（documentation）：Media Capture: Overcoming Rate Limits & Downloading Video/Audio Across Platforms 证据：`methodology/media_capture.md`
- **Methodology Overview**（documentation）：This methodology operates on four foundational principles: 证据：`methodology/methodology.md`
- **Naming, Indexing & Agent-Readability**（documentation）：Naming, Indexing & Agent-Readability 证据：`methodology/naming_and_indexing.md`
- **Cross-Cutting Patterns Across All 20 Skills**（documentation）：Cross-Cutting Patterns Across All 20 Skills 证据：`methodology/patterns.md`
- **Prompts That Built the BROGAV Dossier**（documentation）：Prompts That Built the BROGAV Dossier 证据：`methodology/prompts.md`
- **Quality Assurance: The Dossier Audit Process**（documentation）：Quality Assurance: The Dossier Audit Process 证据：`methodology/quality_assurance.md`
- **Dossier Skeleton**（documentation）：Use this as the starting point when building a new company dossier. Create this folder structure FIRST, then fill it with research. 证据：`methodology/skeleton.md`
- **Agent Skills Reference**（documentation）：All 20 research-related skills available for AI-agent-driven company intelligence dossier construction. Each skill is a reusable agent workflow stored as a SKILL.md file in the canonical skills repository. 证据：`methodology/skills.md`
- **Tools Reference**（documentation）：Comprehensive reference for every tool used and considered during AI-agent-driven company intelligence dossier construction. Based on the BROGAV Solutions dossier project June 2026 . 证据：`methodology/tools.md`
- **Visual Intelligence: Extracting Intel from Video Frames**（documentation）：Visual Intelligence: Extracting Intel from Video Frames 证据：`methodology/visual_intelligence.md`
- **Copy audit — high-impact tweaks advisory**（documentation）：Copy audit — high-impact tweaks advisory 证据：`reports/COPY-AUDIT.md`
- **Mobile / Responsive / Accessibility Audit — Company Dossier**（documentation）：Mobile / Responsive / Accessibility Audit — Company Dossier 证据：`reports/MOBILE-AUDIT.md`
- **Company Dossier — Security Audit**（documentation）：Scope: companydossier.lol static site site/ → docs/ , GitHub Pages , the client-side in-browser generator widget /generate/ , the npm package packages/company-dossier CLI / library / MCP server , and integrations/ . 证据：`reports/SECURITY-AUDIT.md`
- **Custom GPT — Company Dossier**（documentation）：This file is the spec for the "Company Dossier" Custom GPT. Copy each section into the corresponding field in the GPT editor Configure tab at https://chatgpt.com/gpts/editor. 证据：`integrations/chatgpt/gpt/instructions.md`
- **The nine sections**（documentation）：Reference for what belongs in each section of a Company Dossier. Every entry in every section must carry a source and a confidence tag High / Medium / Low . Public sources only. 证据：`integrations/claude-skill/company-dossier/reference/sections.md`
- **Company dossier**（documentation）：A company dossier is a complete, structured, source-attributed profile of a company, compiled entirely from public sources . It answers, in one file: what the company is, who runs it, who it's hiring, its financial shape, where it operates, the technology it runs, its news/timeline, its relationships customers, partners, rivals , and its risk flags. 证据：`knowledge/concepts/company-dossier.md`
- **Concepts**（documentation）：Concepts - Company dossier company-dossier.md — the definition. - The nine sections nine-sections.md — the structure of every dossier. 证据：`knowledge/concepts/index.md`
- **The nine sections**（documentation）：1. Overview & identity — what the company does, founding, ownership, size, brand. 2. People & org chart — leadership, notable hires, reporting structure. 3. Hiring radar — open roles and where headcount is growing. 4. Money trail — funding, investors, filings, revenue signals. 5. Locations — HQ and offices, mapped. 6. Tech fingerprint — the stack and tools the company runs. 7. News & timeline — press, launches and milestones, dated. 8. Relationship web — customers, partners and rivals as a network. 9. Risk flags — lawsuits, layoffs and reputation notes worth a second look. 证据：`knowledge/concepts/nine-sections.md`
- **Methodology**（documentation）：Methodology - The research pipeline pipeline.md — from a company name to a finished, sourced file. 证据：`knowledge/methodology/index.md`
- **The research pipeline**（documentation）：1. Plan — enumerate public sources and the questions to answer. 2. Gather — pull signals from job boards, public filings, news/press, the open web, maps & places, reviews, and the company site. 3. Assemble & de-dupe — cross-reference and sort signals into the nine sections ../concepts/nine-sections.md . 4. Source — attribute every derived claim; tag confidence; mark unknowns as gaps. 5. Read or export — skim in minutes; export markdown + dossier.json , or push to a repo. 证据：`knowledge/methodology/pipeline.md`
- **Company Dossier**（documentation）：Free, public-sources-only tool that compiles the nine-section dossier ../concepts/nine-sections.md . 证据：`knowledge/product/company-dossier-tool.md`
- **Product**（documentation）：Product - Company Dossier tool & channels company-dossier-tool.md — web widget, npm CLI/library, VS Code extension, ChatGPT app, Claude app/skill, MCP server. 证据：`knowledge/product/index.md`
- **Manifest.Example**（structured_config）：{ " comment": "EXAMPLE Apps-SDK / MCP connector manifest for the Company Dossier ChatGPT App. Placeholder values are marked REPLACE ME or noted with comment fields. The Apps SDK manifest schema is evolving — verify exact field names against https://developers.openai.com/apps-sdk before submitting. Do not ship this file unedited.", 证据：`integrations/chatgpt/apps-sdk/manifest.example.json`
- **Tsconfig**（structured_config）：{ "compilerOptions": { "target": "ES2022", "module": "NodeNext", "moduleResolution": "NodeNext", "lib": "ES2022", "DOM" , "declaration": true, "strict": true, "esModuleInterop": true, "skipLibCheck": true, "forceConsistentCasingInFileNames": true, "resolveJsonModule": true, "outDir": "dist", "rootDir": "src" }, "include": "src" , "exclude": "node modules", "dist" } 证据：`packages/company-dossier/tsconfig.json`
- **OS**（source_file）：Generated site output built in CI by .github/workflows/pages.yml docs/ 证据：`.gitignore`
- **Cname**（source_file）：companydossier.lol 证据：`CNAME`
- **Cloudfront Router**（source_file）：function handler event 证据：`infrastructure/cloudfront-router.js`
- **Deploy Dossier**（source_file）：// Publish a built dossier site to .companydossier.lol // Usage: node deploy-dossier.mjs // Requires AWS creds in the environment S3 PutObject on the bucket . ⋮---- function slugify name async function walk dir ⋮---- async function main 证据：`infrastructure/deploy-dossier.mjs`
- **Company Dossier**（source_file）：Build a complete, source-attributed intelligence dossier on any company from PUBLIC data — people, hiring, money, locations, tech, news, relationships and risk — in one file. Free. Available as a website widget, an npm package CLI + library + MCP server , a VS Code extension, a Claude skill, and a ChatGPT app. 证据：`llms.txt`
- **Ai Icons**（source_file）：// Icons: Lobe Icons MIT — github.com/lobehub/lobe-icons // Source set: @lobehub/icons / lobe-icons, MIT License Copyright c 2023 LobeHub // Monochrome brand glyphs vendored from packages/static-svg/icons/ .svg. // All fills set to currentColor so they inherit the surrounding ink theme. 证据：`site/ai-icons.mjs`
- **Brand**（source_file）：// Company Dossier brand marks — single source of truth for the logo, favicon and app icons. // Refined "case file" mark: a folder file with a magnifying glass — search any company's file. // Monoline, scales from 16px favicon to 512px app icon. ⋮---- // Inner geometry of the mark, drawn in a 0..64 box. strokeW lets favicon use heavier lines. function markPaths strokeW = 3.4, ⋮---- // The inner content used in the on-page icon sprite id="i-logo" . ⋮---- // Scalable favicon: a small cream "case-file chip" with a heavier mark so it reads at 16px. export function faviconSvg ⋮---- // App / maskable icon. maskable=true = full-bleed background within the safe zone. export function appIconSvg size… 证据：`site/brand.mjs`
- 其余 4 条证据见 `AI_CONTEXT_PACK.json` 或 `EVIDENCE_INDEX.json`。

## 宿主 AI 必须遵守的规则

- **把本资产当作开工前上下文，而不是运行环境。**：AI Context Pack 只包含证据化项目理解，不包含目标项目的可执行状态。 证据：`README.md`, `growth/README.md`, `infrastructure/README.md`
- **回答用户时区分可预览内容与必须安装后才能验证的内容。**：安装前体验的消费者价值来自降低误装和误判，而不是伪装成真实运行。 证据：`README.md`, `growth/README.md`, `infrastructure/README.md`

## 用户开工前应该回答的问题

- 你准备在哪个宿主 AI 或本地环境中使用它？
- 你只是想先体验工作流，还是准备真实安装？
- 你最在意的是安装成本、输出质量、还是和现有规则的冲突？

## 验收标准

- 所有能力声明都能回指到 evidence_refs 中的文件路径。
- AI_CONTEXT_PACK.md 没有把预览包装成真实运行。
- 用户能在 3 分钟内看懂适合谁、能做什么、如何开始和风险边界。

---

## Doramagic Context Augmentation

下面内容用于强化 Repomix/AI Context Pack 主体。Human Manual 只提供阅读骨架；踩坑日志会被转成宿主 AI 必须遵守的工作约束。

## Human Manual 骨架

使用规则：这里只是项目阅读路线和显著性信号，不是事实权威。具体事实仍必须回到 repo evidence / Claim Graph。

宿主 AI 硬性规则：
- 不得把页标题、章节顺序、摘要或 importance 当作项目事实证据。
- 解释 Human Manual 骨架时，必须明确说它只是阅读路线/显著性信号。
- 能力、安装、兼容性、运行状态和风险判断必须引用 repo evidence、source path 或 Claim Graph。

- **Project Overview and Getting Started**：importance `high`
  - source_paths: README.md, packages/company-dossier/README.md, packages/company-dossier/package.json, knowledge/concepts/nine-sections.md
- **Core Engine, Module Architecture and Data Flow**：importance `high`
  - source_paths: packages/company-dossier/src/core.ts, packages/company-dossier/src/index.ts, packages/company-dossier/src/cli.ts, packages/company-dossier/src/utils.ts, packages/company-dossier/src/mcp-server.ts
- **Data Collectors and the Nine Dossier Sections**：importance `high`
  - source_paths: packages/company-dossier/src/collectors/website.ts, packages/company-dossier/src/collectors/dns.ts, packages/company-dossier/src/collectors/wayback.ts, packages/company-dossier/src/collectors/techstack.ts, packages/company-dossier/src/collectors/search.ts
- **MCP Server Deployment and AI Assistant Integrations**：importance `medium`
  - source_paths: packages/company-dossier/src/mcp.ts, packages/company-dossier/src/mcp-http.ts, packages/company-dossier/src/mcp-server.ts, packages/company-dossier/Dockerfile, packages/company-dossier/render.yaml

## Repo Inspection Evidence / 源码检查证据

- repo_clone_verified: true
- repo_inspection_verified: true
- repo_commit: `c39f8fb331b6d2e3cf9c5681a8a5af0c84eb953d`
- inspected_files: `README.md`, `packages/company-dossier/README.md`, `packages/company-dossier/deploy/README.md`, `packages/company-dossier/fly.toml`, `packages/company-dossier/package-lock.json`, `packages/company-dossier/package.json`, `packages/company-dossier/render.yaml`, `packages/company-dossier/src/cli.ts`, `packages/company-dossier/src/collectors/dns.ts`, `packages/company-dossier/src/collectors/search.ts`, `packages/company-dossier/src/collectors/techstack.ts`, `packages/company-dossier/src/collectors/wayback.ts`, `packages/company-dossier/src/collectors/website.ts`, `packages/company-dossier/src/core.ts`, `packages/company-dossier/src/generators/site.ts`, `packages/company-dossier/src/index.ts`, `packages/company-dossier/src/mcp-http.ts`, `packages/company-dossier/src/mcp-server.ts`, `packages/company-dossier/src/mcp.ts`, `packages/company-dossier/src/utils.ts`

宿主 AI 硬性规则：
- 没有 repo_clone_verified=true 时，不得声称已经读过源码。
- 没有 repo_inspection_verified=true 时，不得把 README/docs/package 文件判断写成事实。
- 没有 quick_start_verified=true 时，不得声称 Quick Start 已跑通。

## Doramagic Pitfall Constraints / 踩坑约束

这些规则来自 Doramagic 发现、验证或编译过程中的项目专属坑点。宿主 AI 必须把它们当作工作约束，而不是普通说明文字。

### Constraint 1: 可能修改宿主 AI 配置

- Trigger: 项目面向 Claude/Cursor/Codex/Gemini/OpenCode 等宿主，或安装命令涉及用户配置目录。
- Host AI rule: 列出会写入的配置文件、目录和卸载/回滚步骤。
- Why it matters: 安装可能改变本机 AI 工具行为，用户需要知道写入位置和回滚方法。
- Evidence: capability.host_targets | https://github.com/ever-just/company-dossier | host_targets=mcp_host, claude, chatgpt
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 2: 能力判断依赖假设

- Trigger: README/documentation is current enough for a first validation pass.
- Host AI rule: 将假设转成下游验证清单。
- Why it matters: 假设不成立时，用户拿不到承诺的能力。
- Evidence: capability.assumptions | https://github.com/ever-just/company-dossier | README/documentation is current enough for a first validation pass.
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 3: 维护活跃度未知

- Trigger: 未记录 last_activity_observed。
- Host AI rule: 补 GitHub 最近 commit、release、issue/PR 响应信号。
- Why it matters: 新项目、停更项目和活跃项目会被混在一起，推荐信任度下降。
- Evidence: evidence.maintainer_signals | https://github.com/ever-just/company-dossier | last_activity_observed missing
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

- Trigger: no_demo
- Evidence: downstream_validation.risk_items | https://github.com/ever-just/company-dossier | no_demo; severity=medium
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 5: 存在评分风险

- Trigger: no_demo
- Why it matters: 风险会影响是否适合普通用户安装。
- Evidence: risks.scoring_risks | https://github.com/ever-just/company-dossier | no_demo; severity=medium
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 6: issue/PR 响应质量未知

- Trigger: issue_or_pr_quality=unknown。
- Host AI rule: 抽样最近 issue/PR，判断是否长期无人处理。
- Why it matters: 用户无法判断遇到问题后是否有人维护。
- Evidence: evidence.maintainer_signals | https://github.com/ever-just/company-dossier | issue_or_pr_quality=unknown
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 7: 发布节奏不明确

- Trigger: release_recency=unknown。
- Host AI rule: 确认最近 release/tag 和 README 安装命令是否一致。
- Why it matters: 安装命令和文档可能落后于代码，用户踩坑概率升高。
- Evidence: evidence.maintainer_signals | https://github.com/ever-just/company-dossier | release_recency=unknown
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。
