The block the generator copies verbatim into every project's AGENTS.md,
between its marks. Everything outside the marks is layer 2: the project's own,
and the harness never touches it.
Every rule earns its place by three questions: is it true and does it bring its evidence? Would an agent get this wrong without the line? And does the harness not already write the file the rule asks for? A rule that a file makes unnecessary does not qualify.
Rules are cited by number and by text («rule 1, verify before asserting»): numbers shift when a rule leaves, and the text survives.
Everything above the line stays here. From the --- down is what travels.
-
Verify before asserting, and with whatever consumes it. Never take a file's word about the environment: run the tool that reads it and trigger what it controls. What cannot be checked stays
❓ pending, said out loud.Asking is not enough:
pnpm config getanswered42for a key that does not exist, andtruefor one that changed nothing. -
"Done" means verified by CI, not asserted. What has not passed the gate stays pending, and that is said.
A green on your machine only proves your machine.
-
.env, credentials and real data dumps: neither read without explicit permission, nor committed. What the agent reads enters the conversation, and from there it does not come back..env.exampleis what travels. -
The AI installs and configures nothing on its own: it proposes, the owner decides.
An install or a config change lands in everyone's lockfile and CI, and neither shows in the diff the agent presents.
-
Nothing destructive without a
--dry-runfirst, showing what would be deleted.A
git clean -fdtook three unrecoverable directories. -
The AI commits; the person decides the push. Local commits pile up until the go-ahead, and one go-ahead covers one push, not the next ones.
-
No AI trace in commits or output: no
Co-Authored-By, no "Generated with…".Tools add it by default. History says what changed and why, not with which tool.
-
Conventional Commits, in English:
type(scope): summary, with!for a breaking change. The types:feat·fix·docs·style·refactor·perf·test·build·ci·chore·revert. The body carries only the list of changes and the reason for each — the how is already in the diff.
-
An agent session has no Node auto-switch. The hook lives in the shell profile and a non-interactive session never loads it: the session runs on whatever Node it inherited when it was launched, and
cdinto another project does not change it.Start the session from a terminal already on the repo's version — enter the directory, let fnm/nvm switch, then launch the agent. One session per project.
If that was not done, activate it on every invocation:
fnm use <major>then the command.fnm exec --using=N pnpmdoes not work on Windows —pnpmis a.cmdandfnm execonly launches real executables. -
pnpm, never npm.
npm install leaves a package-lock.json next to pnpm-lock.yaml, and two
installers disagree in silence.
- pnpm settings live in
pnpm-workspace.yaml;.npmrccarries registry and authentication only — from pnpm 11 anything else there is ignored, and pnpm 10 still reads it, so it works today and stops on upgrade. Every repo with dependencies setsminimumReleaseAgethere.
-
State lives in
docs/SESSION.md, written when a task closes — at session close there is no context left — and overwritten: git keeps the history. Nothing the code orgit logalready tells goes in. -
The reasoning lives in
docs/DECISIONS.md, append-only. A decision that changes is not edited: another is appended revising it, and the old one is marked, never deleted. Knowing what was believed is part of the record. -
An exception is declared in the project's
AGENTS.md, with its reason and its scope; failing silently is not an option. Does not apply to security, AI traces or pushing.
- File names, configuration keys and identifiers in English.
- Skills are per project.
npx autoskillsinstalls them into<repo>/.claude/skills/, which is git-ignored and rebuilt likenode_modules;skills-lock.jsonis committed — it carries each skill's source and hash, and it is what makes three machines rebuild the same set. The developer runsautoskills, not the agent —npxdownloads a package, and installing is not the agent's call.
Global skills in ~/.claude/skills/ are the machine's, not the project's.
- Official docs and MCPs are consulted and never silenced, at the
installed version — from the lockfile, not the
^range. Context7 is the one every project uses:resolve-library-id, thenquery-docsat that version. If the MCP does not answer, say so instead of pretending it was consulted.
- When work is reviewed, this is the shape.
architectbefore building;reviewerandsecurityover what was built, read-only;testerto verify. Run them whenever you want, together or on their own.