They are non-negotiable.
## Secrets
- NEVER put API keys, database credentials, or tokens in frontend code (anything under src/, app/, pages/, components/, public/)
- NEVER put secret keys in environment variables
bearing (see §3 rule 11). There is
no separate `src/agentplatform/` package and no standalone `frontend/` app in
active use — the official React web client is served from
`src/agent_manager/api/static/widget
Preserve existing standard-mode behavior unless explicitly changed.
- Run all relevant backend, frontend, evaluation, migration, and security tests.
- Report commands run and checks that could not be executed
service; entry `app.py`, settings `config.py`, logic in `services/`, routes in `routers/`, helpers in `utils/`.
- `frontend/` Vue 3 + TypeScript dashboard; pages in `views/`, shared UI in `components/`, API wrappers in `services
core MUST house all reusable language/runtime logic. Private harness adapters and the `unigent-cli` frontend contain only the minimum translation and presentation glue. Public SDK consumers import the bundled facade
docs/backend-development.md#verification`](docs/backend-development.md#verification).
Done: `uv run pytest -q` exits 0 against that database.
Frontend checks:
```bash
bun run --cwd apps/web typecheck
bun run --cwd apps/web test src/hosted/oss-clean.test.ts
bunx biome
cross-cutting telemetry and reusable
helpers.
- `src/schemas.py` and `contracts/`: API and cross-repository contracts.
- `frontend/`: the optional React/Vite administration dashboard.
- `scripts/`, `.azure/`, `azure.yaml`, `Dockerfile`, and `infra/`: deployment
and operational assets
teach judgment for a discipline: frameworks, decision models, ownership boundaries, and process (`backend-engineering`, `frontend-engineering`, `data-engineering`, `platform-engineering`, `ml-engineering`, `qa-methodology`, `site-reliability-engineering`, `release-engineering