Request** is opened.
- **Action:** The agent reviews the code changes (diff), looking for bugs, security issues, and style improvements.
- **Output:** It posts review comments directly on the PR.
- **Note
choices remain open, stop before
edits; configurable defaults are not authority.
- For architecture, reliability, security, or quality invariant work, read
`docs/patterns/encoding-invariants.md` and enforce only accepted rules.
- Report reusable agent friction
used to drop input validation at trust boundaries, error handling that prevents data loss,
security measures, accessibility, or one runnable check behind non-trivial logic. If an
implementation exceeds
with a previously valid sessionId/participantId. Do not rely on `participantHandle`/sessionId opacity as a security boundary.
- **Stop is real revocation, not just a UI toggle.** Stopping Live Transcript or revoking
type-check` before requesting review, calling out any skipped checks with rationale.
## Security & Configuration Tips
- Store secrets in `.env`; use `hephaestus_config.yaml` or `config/agent_config.yaml` for overrides and never commit credentials.
- Reset
command are in [knowledge/conventions/screenshots.md](knowledge/conventions/screenshots.md).
- Update docs and localization as needed (run `make l10n`).
## Security & Configuration Tips
- Never commit secrets. Use `.env` for local config; keep
docs` branch
and at https://azure.github.io/GPT-RAG/.
## Priority
Follow, in this order:
1. Security, privacy, authorization, and platform instructions.
2. Task requirements and acceptance criteria.
3. Executable configuration and versioned
coverage and manual steps.
- Before opening PR: `pnpm check` (lint+types+tests) should pass.
## Security & Configuration Tips
- Copy `.env.example` to `.env`; never commit secrets. For local HTTP use `NO_HTTPS
breaking changes, list validation commands, and include the AI usage statement requested by `.github/pull_request_template.md`.
## Security & Configuration Tips
Do not commit secrets, local virtual environments, caches, `.powercontext/`, `dist/`, or generated website
entries go under `## [Unreleased]`, in the right subsection (`### Added`, `### Changed`, `### Fixed`, `### Removed`, `### Security`, `### Refactored`). Read the section first and append to existing subsections; never duplicate them.
- One bullet per issue/PR
warm pool management, and authentication — all via Hono.
Consumer-facing documentation (API reference, deployment, security) lives in [`bridge/worker/README.md`](../../../../bridge/worker/README.md).
## Key files
- `index.ts` — `bridge()` factory: resolves DO bindings at module evaluation
access — station instructions especially, since stations see none of the root's surface.
## Security
- **Never ask the user for API keys, client secrets, or any other credentials.**
- **Never commit secrets