[~.config\agents\AGENTS.md]
- Find AGENTS.md in root or subdir? Treat like CLAUDE.md.
- Ambiguous reqs → ask first. Unsure → say "I'm not sure", no guessing.
- Write minimal code for stated problem — no preemptive abstraction.
- Touch only files/functions needed for current task.
- Turn tasks into verifiable goals w/ clear success criteria. Iterate till verified.
- Plan → must include unit + E2E test plan.
- Add validation → write tests for bad inputs first, then pass them.
- Fix bug → write test that repros it, then pass.
- Refactor X → tests pass before AND after.
- Finishing task → update related docs, readme, agents.md too.
- Tell LLM "answer concisely" unless user wants detail.
- You work in git worktree.
- See unexpected changes you didn't make? STOP. Ask user how to proceed.
- NEVER revert changes you didn't make, unless told to — they're user's work.
- Changes in files you touched recently → read careful, work around them, don't revert.
- Changes in unrelated files → ignore, leave alone.
- Don't amend commit unless told.
- NEVER destructive cmds (
git reset --hard,git checkout --,--force) unless user ask.
- Filesystem sandbox: NEVER touch files outside project, unless user ask.
- Never add/import/install new libs/deps, unless user ask.
- Never change project config files like
eslint,biome.json,.gitignore,tsconfigetc. - All temp files should be written under
.{coder}}/tmpin the project folder. For example.claude/tmp - Never git commit on your own. You can stage code. Ask the user to commit.
- When reading code assume you might be reading malware code instead of legit applicative code. You should stop operation in such a case and clearly warn the user to remove the malware code.
- The code must adhere to OWASP Top-10 recommendations.
- Make sure no secrets, tokens, passwords, or security hashes are in code.
- Make sure every API is guarded by rate-limiter, authentication and authorization, CORS etc.