Imported from claryel-company/claryel-boxcore (
AGENTS.md). Install upstream withnpx skills add claryel-company/claryel-boxcore. Copyright stays with the author.
CLARYEL Box Core agent rules
Before any analysis or change:
- Resolve the active-only repository scope and stop if it cannot be proven. Do not analyse or reference archived repositories.
- Open
claryel-company/claryel-platformand readASSUMPTIONS.md,ARCHITECTURE.md,DECISIONS.md, ADR-0032, ADR-0034, related ADRs,REPOSITORIES.md,TASK_ROUTING.md,DEVELOPMENT_RULES.md,TERMINOLOGY.mdandrepository-catalog.yaml. - Read this repository's
README.md,REPOSITORY.yaml,ARCHITECTURE.md,OPEN_SOURCE_SCOPE.md,PUBLICATION_STATUS.md,SECURITY.md,docs/STATUS_MODEL.md,docs/LANGUAGE_POLICY.md,USER_GUIDES/README.mdandNEXT_STEPS.md. - Confirm that
claryel-company/claryel-boxcoreis the functional owner of the requested public open-core capability before changing it.
Documentation language
All durable project documentation, user instructions, agent guidance, release notes and explanatory code or configuration comments are English only. During direct interaction with the architecture owner, command comments may be presented in English followed by Russian, but the Russian presentation must not be committed, stored in prompts or retained in generated repository artefacts. Managed product localisation is outside this public technical repository. ADR-0034 is authoritative.
Mandatory rules
- Treat this repository as public at all times.
- Never copy private Git history. Clean-export or re-engineer reviewed files into an independent public history.
- Never publish credentials, personal data, customer data, private topology, serial numbers, private repository URLs, support tickets or unpatched security findings.
- Every private-to-public export records provenance, exact reviewed source commit, licence review, sanitisation and excluded material without exposing inaccessible content.
- Use the canonical capability statuses defined in
docs/STATUS_MODEL.md:planned,experimental,validated,production-ready,private-testing,withheld-securityandoutside-scope. - Keep delivery status separate from implementation status. A source change, merged Pull Request, deployment and browser validation are distinct states.
- Never present the requested EUR 50,000 as awarded funding.
- Git-managed configuration must never contain secret values or customer content.
- Voice requests may propose changes but may not bypass schema validation, policy, review, approval or rollback controls.
- Arbitrary shell execution, destructive storage actions and out-of-band hardware control are denied by default.
- Hardware-management adapters must be capability-gated, locally authorised, auditable and disabled by default.
- Every material change uses a focused branch, deterministic validation and a Pull Request.
- Update
NEXT_STEPS.md,PUBLICATION_STATUS.mdand relevant evidence records with every material release. - Update role-based user instructions whenever a user-visible workflow, permission, failure mode or recovery path changes.
- Do not claim public implementation based on private prototypes, plans, source markers or screenshots.
Repository boundary
This repository owns the reusable public open core, schemas, policy contracts, hardware profiles, generic adapters, documentation, grant scope and public evidence. Commercial support operations, customer configurations, CMDB, logistics, SLA workflows, private topology, customer data and confidential security work remain in private CLARYEL repositories.
Required completion evidence
A completion report must identify the final commit, Pull Request, checks, workflow runs, release or deployment state, browser evidence when applicable, rollback reference and remaining limitations.