Skip to content

docs: add security guidance for agents - #2364

Draft
NnnOooPppEee wants to merge 1 commit into
mainfrom
codex/sec-3066/developer-portal-security-guidance
Draft

NnnOooPppEee wants to merge 1 commit into
mainfrom
codex/sec-3066/developer-portal-security-guidance

Conversation

@NnnOooPppEee

Copy link
Copy Markdown
Contributor

PR Type

  • Regular Task
  • Bug Fix
  • QA Tests

Description

Summary

Add matching security guidance to AGENTS.md and CLAUDE.md covering role permissions, resource isolation, data disclosure, protected fields and review state, authentication and invitations, input validation, and replay prevention. Include nullifier validation, lossless representation, and API wire-format compatibility.

Why

Give agents explicit security checks across API handlers, server actions, and Hasura permissions, with rules that apply to different roles and authentication methods.

SEC-3066

Test plan

  • git diff --check
  • web/node_modules/.bin/prettier --check AGENTS.md CLAUDE.md
  • pnpm exec tsc --noEmit --incremental false in web/
  • pnpm exec jest tests/unit --runInBand --silent in web/

Checklist

  • I have self-reviewed this PR.
  • I have left comments in the code for clarity.
  • I have added necessary unit tests.
  • I have updated the documentation as needed.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The documentation changes are consistent, complete, and match the stated security-guidance scope.

Review effort: Balanced
Findings: None

What changed in this PR

Adds consistent security guidance for coding agents across both repository instruction files.

Changes:

  • Documents authorization, resource isolation, input validation, and replay protections.
  • Defines lossless nullifier handling requirements and wire-format compatibility.

No critical issues identified.

File Description
AGENTS.md Adds security and nullifier guidance.
CLAUDE.md Mirrors the same guidance for Claude agents.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch was successfully deployed

1 active deployment
development — 15c23b7f Deployed Oct 2, 2026 by NnnOooPppEee via End-to-end Tests #4920
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants