bash
# Run with auto-discovery
devui ./agents
# Run with specific entities
devui --entities my_agent.py
```
## Security Posture
DevUI is a development-only sample app, not a production hosting surface. Authentication
factory methods instead
- No `Token` type in props
- `SecretValue` type for any password/secret/token properties
## Security Rules
- SHOULD prefer specific IAM actions over full-service wildcards (`s3:*`), but suffix wildcards
services and endpoints, detecting uptime/downtime |
| `auditbeat` | Gathers audit data from systems to track security events, user activities, and compliance requirements |
| `packetbeat` | Analyzes network traffic by capturing and inspecting packets
Install GitHub CLI: `brew install gh` (macOS) or visit https://cli.github.com for other platforms.
## Security & Configuration Tips
Store API keys and provider URLs in `.env` or your MCP client config
checker and effective budget come from main, not the PR. Keep default CODEOWNERS.
## Security and lifecycle correctness
- Never commit API keys, tokens, private keys, `.env` files, customer data, or other
release`](.claude/skills/release/SKILL.md) | Cutting a release: bump on `v2/main`, milestone merge, tag `origin/main`, publish | `/release` |
| [`security-advisory`](.claude/skills/security-advisory/SKILL.md) | A privately reported vulnerability end to end: the draft card, who owns
Keep it simple
Codex Security is a thin wrapper around Codex and its security plugin.
- Trust local tools and processes running as the current user.
- Treat repository contents, model output
Codex Security CLI
Codex Security is a thin CLI and SDK wrapper around Codex and its security
plugin. Use their existing behavior instead of building another runtime.
## Threat model
controls may ship without a corresponding tool, especially for secret input until a secure tool-driven input flow exists. Do not add a tool when the agent can already
prefix, prefix cache, the
four bounds on context growth), and
[`docs/security-model.md`](docs/security-model.md) (per-layer security). Don't duplicate
those here — link to them.
## What this recipe teaches
Horizon leans
rethink the design); and prefer reusing existing mechanisms over adding parallel ones. Capability-based security note: a resource becomes "ambient" (auto-injected) only by user/admin configuration — a gatekeeper must never
block already says.
Comments are appropriate for gotchas, non-obvious invariants, external constraints, security or
performance reasoning, and deliberate departures from a convention. Explain why the surprising
choice is necessary
variable
#### MySQL Analyzer
- **Issue**: Connection timeout or permission denied
- **Solution**: Verify AWS credentials, check Security Group rules, ensure RDS Data API is enabled
- **Debug**: Set `FASTMCP_LOG_LEVEL=DEBUG
Before writing a fix, confirm how Next.js handles the same scenario. This applies to security fixes, bug reports, and behavioral changes. We have repeatedly shipped fixes that diverged from Next.js
request
and response bodies, headers, credentials, tokens and API keys are customer
content or security material, at every level including debug. Log the shape
instead — a type, a count
direct request proceeds after warning about missing or incomplete expected labels.
- **Security:** `review-security-issue` → `fix-security-issue`
- General build agents must not process `topic:security` issues. For unattended processing