mantis
google/mantis/AGENTS.md
modifies files, stage the changes and amend your commit. ## ADK Invariant Architecture & Deterministic Gates Security invariants (INV-1 through INV-6) are enforced deterministically by the Google ADK Python runtime
How real projects brief Codex, Cursor and every other agent that reads AGENTS.md.
google/mantis/AGENTS.md
modifies files, stage the changes and amend your commit. ## ADK Invariant Architecture & Deterministic Gates Security invariants (INV-1 through INV-6) are enforced deterministically by the Google ADK Python runtime
0xSteph/pentest-ai/AGENTS.md
secrets in code or tests. `.env*` is gitignored. ## Authorization & safety This is offensive-security tooling. **Never run it against systems you do not own or have written authorization to test
shiwenwen/hope-agent/AGENTS.md
或同源登录 body;同源浏览器换 HttpOnly Cookie,跨源 WebSocket / iframe 用短时、受限票据,资源票据保持只读允许列表。出站 HTTP 走 `security::ssrf::check_url`;Tauri CSP 不放行外部域名。 - **授权失败保持关闭**:工具沿权限引擎与执行守卫调用,不新增旁路;strict 审批不得由 Smart、AllowAlways、超时或无人值守 `proceed
theopenco/llmgateway/AGENTS.md
# AGENTS.md This file provides guidance to AI agents when working with code in this
phronesis-io/eigenflux/AGENTS.md
impression recording, 5-level cache architecture, cache config and testing | | `auth.md` | Authentication flow, OTP, security mechanisms, mock OTP whitelist | | `notification.md` | Notification service DAL, Redis keys, delivery dedup, audience expressions | | `api_endpoints.md
Lynpoint/CyberVerse/AGENTS.md
real root cause. - Reject fixes that only patch symptoms. - Reject changes that damage architecture, security, performance, maintainability, or type safety. - Prefer minimal correct fixes over large unnecessary rewrites. - Explain
cbrock84/headcount/AGENTS.md
finance` — Finance - `operations` — Operations - `pmo` — Program Management Office - `people` — People - `legal-risk` — Legal & Risk - `security` — Security - `customer-experience` — Customer Experience - `data-analytics` — Data & Analytics - `corporate-strategy` — Corporate Strategy
Asymptote-Labs/agent-beacon/beacon-sandbox/AGENTS.md
user wants: `ANTHROPIC_API_KEY`, `--api-key-command CMD`, or `--modal-secret NAME` (most secure; the value never enters this process, at the cost of the artifact leak check reporting
Agents365-ai/video-podcast-maker/AGENTS.md
pytest -q`, preview, or render validation), and screenshots when UI or thumbnail output changes. ## Security & Configuration Tips Do not commit real API keys or generated customer media. Keep secrets
agentlas-ai/Agentlas-OS/AGENTS.md
Cloud-ready packages must pass the local setup wizard contract: `agentlas.json` exists, the Hephaestus security scan is `PASS` or reviewable `WARN`, the runtime bundle compiles from manifest allowlists, and denied
openai/openai-java/AGENTS.md
checker and effective budget come from main, not the PR. Keep default CODEOWNERS. ## Security requirements - Never commit OpenAI API keys, bearer tokens, AWS/Bedrock credentials, Sonatype tokens, GPG private keys
LakshmanTurlapati/Review-Gate/AGENTS.md
primary product surface and focuses on installation correctness, session reliability, IPC security, automated verification, and release consistency. ## Workflow Before making file changes, start work through a GSD command so planning
mxsm/rocketmq-rust/AGENTS.md
tokens, message bodies, or entire request/config objects; avoid unsampled per-message spans. - Preserve the security and product boundaries defined in local MCP, MCP-control, SRE, and dashboard guides. Lighter development
silverstein/minutes/AGENTS.md
docs, refactoring) - `epic` - Large feature with subtasks - `chore` - Maintenance (dependencies, tooling) ### Priorities - `0` - Critical (security, data loss, broken builds) - `1` - High (major features, important bugs) - `2` - Medium (default, nice
eatmoreduck/boss-zhipin-scraper/AGENTS.md
/tmp`,不进仓库。 7. **合规红线**:只做被动捕获(Network 域旁听页面自身请求)和请求节奏控制。**禁止**主动伪装类手段:指纹伪造、验证码绕过、代理池轮换。遇到 `_security_check` 验证页时提示用户人工处理,不自动绕过。 ## 架构关键点(容易踩坑) - `scripts/boss_cdp_raw.py` 是一个**长单文件**,包含:`CDPSession` 类(WebSocket 连 CDP,含事件缓冲
microsoft/fluentui-react-native/packages/agentic/desktop-driver/AGENTS.md
relevant reference: [architecture](references/architecture.md), [service integration](references/service.md), [native helpers](references/native-helpers.md), [test integration](references/test-integration.md), or [security](references/security.md). 2. For macOS native work, also read [native/macos/README.md](native/macos/README.md). For Windows or Win32 native
inkeep/agents/AGENTS.md
clear acknowledgement and plan - missing critical dimensions to feautre development relevant, like authorization or security - identify any side effects of the work that is being asked - implementations that contradict
openclaw/crabbox/AGENTS.md
tokens plus the codesign identity and notary profile), not just `GH_TOKEN`/`GITHUB_TOKEN`. ## Security & Configuration Tips The authentication and isolation model is documented in `SECURITY.md` and `docs/security.md`. Keep provider
hesamsheikh/octogent/AGENTS.md
tradeoffs, or non-obvious reasoning. - Design defensively. Validate assumptions, handle edge cases, and treat security boundaries as part of the implementation, not a follow-up. ## Project Structure - Monorepo: `apps
preset-io/agor/AGENTS.md
context/`** — small set of agent-oriented cheat sheets and design docs (file pointers, gotchas, security contracts). Start with [`context/README.md`](context/README.md). **Rule of thumb:** If a topic has a guide page
An open format for instructions to coding agents, read by Codex, Cursor and others. Think of it as a README written for agents.
At the repository root, with more specific files in subdirectories. Agents read the one closest to the file they're editing.
Setup and test commands, code style, and the rules a new contributor would need to know.
Claude Code reads CLAUDE.md. A one-line CLAUDE.md that points at AGENTS.md covers both.