Imported from jussray/jussbeautifulhair-site (
AGENTS.md). Install upstream withnpx skills add jussray/jussbeautifulhair-site. Copyright stays with the author.
Agent Instructions
Use these instructions whenever Claude, Codex, ChatGPT, Perplexity, GitHub-connected agents, or other AI coding agents work in this repository.
Founder Intelligence Constitution
Before material planning, implementation, review, automation, product or price presentation, publishing, checkout work, customer communication, deployment, or cross-repository coordination, read AGENTS_FOUNDER_INTELLIGENCE.md and docs/FOUNDER_INTELLIGENCE_CONSTITUTION.md.
The constitution adds the required /human → /futureyou → /truthmode → /confess → /billgates → /elonmusk remembrance loop. It supplements the repository rules below and never weakens customer agency, truthful commerce, privacy, security, brand ownership, payment boundaries, evidence, rollback, or founder approval.
Founder operating stack
Use the full founder stack for nontrivial work:
/elonmusk /garyvee lindymode redteam l99 redteam ooda /truthmode
/elonmusk adds first-principles reduction, bottleneck identification, leverage analysis, and deletion of unnecessary complexity. It does not replace the founder stack. The first redteam attacks the premise. L99 maps provenance, state, release, rollback, and long-term drift. The second redteam attacks the selected implementation.
Truth hierarchy
- Current repository, branch, exact commit, and deployed configuration actually inspected.
- Founder Control Room records, especially release-truth, outage, merge, Cloudflare, and cross-repo evidence.
- Current test results, Playwright evidence, logs, schemas, runtime behavior, and Cloudflare build/deploy evidence.
- Explicit founder decisions and approved project records.
- Current official provider documentation.
- Prior summaries, memory, generated plans, and assumptions.
Do not claim a file, feature, migration, deployment, fix, test, or merge exists without evidence.
Infrastructure outage and CI classification
When GitHub Actions fails, classify the evidence before blaming code:
runner_startup_failure: GitHub runner or job startup failed before meaningful steps executed, especially when jobs show no steps, no logs, or null log URLs.workflow_no_jobs: the workflow itself schedules no jobs or is skipped before jobs exist.workflow_step_failure: at least one job executed steps and logs show a concrete failing command, assertion, build, lint, type, or Playwright step.
Never call a zero-step/no-log GitHub Actions failure a code regression. Treat it as infrastructure evidence. However, an infrastructure outage can still gate merge, release, and deployment truth under this repo's release rules until Founder Control Room and any available Cloudflare/runtime evidence explain the situation.
Control Room and Cloudflare release truth
Look to Founder Control Room first for release-truth interpretation. Capture the exact repository, PR, branch, head SHA, workflow, run, job evidence, classification, Cloudflare build status, runtime evidence, and next gate.
Cloudflare build or deploy success is separate from GitHub Actions success. GitHub Actions outage is not application failure, and Cloudflare success is not proof that all app, auth, data, privacy, or Playwright gates passed. Record both without blending them.
Work completion rule
Continue working the requested task until it is done or until a real blocker is reached. Do not stop at a plan when a focused implementation, verification, or documentation update is available.
Every handoff must state what was changed, what was verified, what remains blocked, and the next gate.
Exact-fix doctrine
The target is the exact evidence-backed fix, not the smallest diff, fewest files, shortest answer, or lowest-effort patch.
- Define the complete root-cause fix before reducing scope.
- Include every coupled change required for correctness, security, data integrity, user experience, operability, verification, rollout, and rollback.
- Remove unrelated work, but never remove required work merely to make the patch look smaller.
- Do not call a partial mitigation complete while a known required gap remains.
- A fix may be delivered in reversible stages, but the full correctness boundary must remain intact until the required outcome is satisfied.
- Expand or contract the implementation when evidence changes; optimize for exactness, not patch size.
Codex provider baseline
When a repo-running Codex agent needs model-provider configuration, keep it machine-local and use OpenAI/Codex as the default coding engine:
model = "gpt-5.3-codex"
model_provider = "openai"
model_reasoning_effort = "high"
model_reasoning_summary = "auto"
model_supports_reasoning_summaries = true
model_auto_compact_token_limit = 900000
Store the API key outside the repository, for example in ~/.codex/.env:
OPENAI_API_KEY=replace_with_local_secret
Never commit .codex/.env, OPENAI_API_KEY, MODEL_API_KEY, service-role keys, provider tokens, or any other secret. Model choice does not override this file, local provider roles, verification gates, Founder Control Room truth, or explicit founder approval gates.
Playwright verification
For UI, route, browser, release, onboarding, checkout, auth-flow, or runtime behavior changes, verify with Playwright on the exact changed head before calling the task complete. If Playwright is not applicable, say why. If Playwright cannot run because of infrastructure, missing secrets, missing browser dependencies, or a GitHub runner outage, record that as a verification blocker rather than converting it into code blame.
Merge authority
Agents may merge when the merge is the correct evidence-backed integration step, not merely because a PR exists or a badge looks green.
A merge is safe only when repository, target branch, PR, and exact head SHA are verified; the scope is focused; changed files have been reviewed; required checks have genuinely executed and passed, or a documented infrastructure outage is classified and the remaining evidence is sufficient for the specific change; Playwright has passed for any changed user-facing web/runtime path, or is explicitly inapplicable; Founder Control Room and Cloudflare evidence have been checked when release truth or deployment is involved; no unresolved critical review thread remains; privacy, security, brand/IP, credentials, user data, and project boundaries remain intact; rollback or safe forward-fix is understood; and the merge itself does not silently perform deployment, migration, auth/RLS changes, billing/spending, external publication, destructive deletion, credential movement, or any other separately gated action.
If those conditions are not met, keep working or leave the PR open with the exact blocker.
Provider roles
- Claude: long-context repo reasoning, focused implementation, refactor planning, and documentation. Read
AGENTS.mdand any localCLAUDE.mdbefore acting. - Codex: code edits, tests, Playwright, CI triage, and repository operations. Keep fixes exact, complete, reversible, and evidence-backed. Use the Codex provider baseline above when local model-provider configuration is needed.
- ChatGPT: reasoning, review, debugging, threat modeling, data analysis, and founder-readable decisions. Separate fact, inference, and action.
- Perplexity: current public research and source discovery. It is not private repository, account, Supabase, Cloudflare, or production truth unless those systems are explicitly connected and inspected.
Separate gates
Do not deploy, roll back production, run destructive migrations, alter auth/RLS, rotate or expose secrets, spend funds, publish externally, send external communications, delete user material, or change production routing without explicit approval for that exact action.
Never delete Ray/Juss material without explicit approval for that specific deletion.
Repository role
This is the public React/Vite storefront and minimal Cloudflare payment-session Worker for jussbeautifulhair.com.
Before nontrivial work, read:
.agents/skills/jbh-storefront-operator/SKILL.mdfor 5W1H, public-storefront identity, proof, and rollback;.agents/skills/sales/SKILL.mdfor positioning, merchandising, offer clarity, checkout support, conversion, and retention;.agents/skills/devil/SKILL.mdfor premise and selected-plan attacks before material public commercial changes.
For commercial work add to the founder stack:
/sales /devil
Keep private admin pages, vendors, costs, sourcing records, customer/order exports, credentials, and strategy in the private repository. Keep Juss Beautiful Hair and Untold Stories catalogs, customers, suppliers, checkout, and fulfillment separate. Never use dark patterns, deceptive urgency, unsupported claims, sensitive traits, or private customer content for persuasion.
Figma build and implementation
For every Figma, design-system, storefront-design, design-to-code, Code Connect, or visual QA task, also read .agents/skills/figma-build-implement/SKILL.md and .figma/repository-profile.json.
Figma must remain public-storefront-only. It may not absorb private admin, vendor, sourcing, order, customer, secret, or payment-authority data. An editable design or prototype is not checkout, catalog, Worker, domain, or deployment proof.