Testing).
- **E2E validation, not just green unit mocks.** Anything touching resolution chains, config
propagation, security boundaries, remote backends, or file/network I/O must exercise the
real path with real imports against
DEFAULT_*` constant or test hook is not configurability. Protocol constants, external specs, and security invariants stay fixed.
- **Misconfiguration fails loud** at load when self-contained, otherwise at the earliest resolvable
packages through `devDependencies`; examples may load them explicitly.
- Experimental status does not relax engineering, security, documentation, lifecycle, testing, invariant, or snapshot requirements.
- Publishing an experimental package does not promote
ticket in Linear - use the branch name
suggested by Linear, **unless it is a security fix** (see Security Fix
Hygiene below)
- Use mermaid diagrams in MD files when you need
FAMILY`, which is process-scoped and would leak across every session in the window.
> **Security note.** The setting is application-scoped (not workspace-configurable) and forwarded to the agent host
document provides context to understand the LangChain Python project and assist with development.
## Corridor security analysis
When Corridor's `analyzePlan` tool is available, create a plan and use the tool
efficiency), input validation at trust boundaries, error handling that prevents data loss, security, accessibility, the calibration real hardware needs (the platform is never the spec ideal, a clock drifts
boilerplate
- Double-check highlights by counting lines from 1 within each code block
### Server Security: Internal Header Filtering
Next.js strips internal headers from incoming requests via `filterInternalHeaders()` in `packages/next/src/server/lib/server-ipc/utils.ts`. This