across an organization. It provides a **REST API
backend**, a **React web UI**, a **security scanner**, and a **ClawHub CLI compatibility layer**.
## Quick Reference
| Item | Value |
|------------|------------------------------------------------------------|
| Backend | Spring Boot
rounds. Ask the reviewer to independently inspect all current modifications and report correctness, regression, security, performance, UX, and test-coverage issues.
- Validate every finding against the code. Make minimal fixes
wide checks when explicitly requested as well.
- Review this task's changes for correctness, security, and regressions. For local work, inspect unstaged/staged diffs (`git diff`, `git diff --cached
symbol — callers, callees, which execution flows it participates in — use `context({name: "symbolName"})`.
- For security review, `explain({target: "fileOrSymbol"})` lists taint findings (source→sink flows; needs `analyze --pdg`).
## Never
terms precisely. In particular, do not use workspace, allowed root, checkout, and worktree interchangeably.
## Security boundaries
Filesystem tools enforce approved-root containment. Shell commands run with the local user
Markdown dependency, another block scanner, or a definition grammar. The security-sensitive `Bun.markdown.render` review-authority check is a deliberately separate code path.
- The orchestrator skill (`harness/ /skills/aidlc/SKILL.md`) is per-harness
repository is `homeassistant-ai/ha-mcp`; the package is `ha-mcp` on PyPI.
## Security
Read [`SECURITY.md`](SECURITY.md) before changing authentication, OAuth, webhooks, network exposure, proxies, filesystem access, or trust boundaries
developers) working on the **Deep Research** repository. Adhere to these patterns to ensure consistency, security, and maintainability.
---
## 🚀 Development Workflow & Commands
The project uses **pnpm** as the primary package manager.
### Core
invoked directly.
Next.js documentation explicitly states: "Treat Server Actions with the same security considerations as public-facing API endpoints, and verify if the user is allowed to perform a mutation
callLLM")
assertNodes {
askLLM withInput "Hello" outputs Message.Assistant("Hello!")
}
}
}
}
```
For comprehensive testing examples, see `agents/agents-test/TESTING.md`.
## Security
### API Key Management
- **NEVER** commit API keys or secrets to the repository
- Use environment variables
ignores)
- Dependencies that use wasm are not allowed (exception: sql.js for SQLite, approved for security sandboxing). Binary npm packages are fine
- When you implement multiple tasks (such as multiple commands
capabilities, or hook paths. Document what you rely on before treating it
as a security boundary.
## Conventions & pitfalls
- **ID schemes differ — not interchangeable.** `ContainerId::new` strips
dashes and TRUNCATES
nono agent guide
nono is a security-critical, capability-based sandbox for untrusted AI agents.
It uses Landlock on Linux and Seatbelt on macOS. Treat every change as a
security