Imported from CruxCoach/CruxCoach (
AGENTS.md). Install upstream withnpx skills add CruxCoach/CruxCoach. Copyright stays with the author.
CruxCoach agent rules
These rules apply to every human-assisted coding agent in this repository.
Start at the documentation index and core concepts and source map. Code establishes implementation, release artifacts establish publication, and specs record intent. For the current candidate, use the 0.2.3 checklist.
Contributions and branches
- Work on a focused
feat/*,fix/*,docs/*, orchore/*branch. Never push directly tomain. Only the project owner personally merges tomain; agents may prepare PRs but must never perform that merge. Required GitHub checks and owner review precede publication. - Anyone may propose a pull request. Only logins in
.github/authorized-feature-maintainers.txtmay cause mergedfeat/*commits to be published. Never weaken that check from feature code. - Files below
.github/,.apktrack/, Gradle/release configuration, signing scripts,AGENTS.md, andSECURITY.mdare trust-boundary files and require the project owner's review.
APKTrack feature publishing
- One full
feat/*branch maps to exactly one permanent APKTrack track and one permanent Android package. Usepython3 scripts/feature_identity.py --branch <branch>; never invent or override the mapping by hand. The existing Fips override is compatibility-critical. - Feature branches build unsigned/debug transport APKs. GitHub and contributors never receive an Android signing key. APKTrack applies the central development signature and verifies the final package, certificate, branch, track, version, and hash against the Root policy.
- Feature code never receives
APKTRACK_FEATURE_TOKENorAPKTRACK_FIPS_TOKEN. Only the trusted-mainworkflow_runpublisher may read them, and that publisher must never execute the downloaded feature artifact. stableis production/manual-only. Never publish it from a remote agent or CI feature workflow.- A queued APKTrack job is not success. Success requires
status="published"andreceipt_delivered=true.
Change hygiene
- Preserve unrelated user/agent changes. Stage only task-owned hunks and inspect the cached diff.
- Run only focused, change-specific tests locally. Full Gradle test suites, full APK builds, Android lint, and other repository-wide verification runs must run through CI, not locally. Do not duplicate checks locally that the branch CI already performs.
- New UI strings must update the default English and German resources together.
- Never print, persist, commit, or place in process arguments Android keys, Nostr keys, bunker connections, APKTrack tokens, signing passwords, or release credentials.
