2fb067ecbf
checklocks / checklocks (push) Has been cancelled
CodeQL / Analyze (go) (push) Has been cancelled
natlab-integrationtest / natlab-integrationtest (push) Has been cancelled
CI / gomod-cache (push) Has been cancelled
CI / race-root-integration (1/4) (push) Has been cancelled
CI / race-root-integration (2/4) (push) Has been cancelled
CI / race-root-integration (3/4) (push) Has been cancelled
CI / race-root-integration (4/4) (push) Has been cancelled
CI / test (-race, amd64, 1/3) (push) Has been cancelled
CI / test (-race, amd64, 2/3) (push) Has been cancelled
CI / test (-race, amd64, 3/3) (push) Has been cancelled
CI / test (386) (push) Has been cancelled
CI / test (amd64) (push) Has been cancelled
CI / Windows (benchmarks) (push) Has been cancelled
CI / Windows (1/2) (push) Has been cancelled
CI / Windows (2/2) (push) Has been cancelled
CI / macos (push) Has been cancelled
CI / privileged (push) Has been cancelled
CI / vm (push) Has been cancelled
CI / cross (386, linux) (push) Has been cancelled
CI / cross (amd64, darwin) (push) Has been cancelled
CI / cross (amd64, freebsd) (push) Has been cancelled
CI / cross (amd64, openbsd) (push) Has been cancelled
CI / cross (amd64, windows) (push) Has been cancelled
CI / cross (arm, 5, linux) (push) Has been cancelled
CI / cross (arm, 7, linux) (push) Has been cancelled
CI / cross (arm64, darwin) (push) Has been cancelled
CI / cross (arm64, linux) (push) Has been cancelled
CI / cross (arm64, windows) (push) Has been cancelled
CI / cross (loong64, linux) (push) Has been cancelled
CI / ios (push) Has been cancelled
CI / crossmin (amd64, illumos) (push) Has been cancelled
CI / crossmin (amd64, plan9) (push) Has been cancelled
CI / crossmin (amd64, solaris) (push) Has been cancelled
CI / crossmin (ppc64, aix) (push) Has been cancelled
CI / android (push) Has been cancelled
CI / wasm (push) Has been cancelled
CI / tailscale_go (push) Has been cancelled
CI / fuzz (push) Has been cancelled
CI / depaware (push) Has been cancelled
CI / go_generate (push) Has been cancelled
CI / make_tidy (push) Has been cancelled
CI / licenses (push) Has been cancelled
CI / staticcheck (macOS) (push) Has been cancelled
CI / staticcheck (Linux) (push) Has been cancelled
CI / staticcheck (Windows) (push) Has been cancelled
CI / staticcheck (Portable (1/4)) (push) Has been cancelled
CI / staticcheck (Portable (2/4)) (push) Has been cancelled
CI / staticcheck (Portable (3/4)) (push) Has been cancelled
CI / staticcheck (Portable (4/4)) (push) Has been cancelled
CI / notify_slack (push) Has been cancelled
CI / merge_blocker (push) Has been cancelled
CI / check_mergeability_strict (push) Has been cancelled
CI / check_mergeability (push) Has been cancelled
Dockerfile build / deploy (push) Has been cancelled
test installer.sh / test (curl, alpine:3.21) (push) Has been cancelled
test installer.sh / test (curl, alpine:edge) (push) Has been cancelled
test installer.sh / test (curl, alpine:latest) (push) Has been cancelled
test installer.sh / test (curl, amazonlinux:latest) (push) Has been cancelled
test installer.sh / test (curl, archlinux:latest) (push) Has been cancelled
test installer.sh / test (curl, debian:oldstable-slim) (push) Has been cancelled
test installer.sh / test (curl, debian:sid-slim) (push) Has been cancelled
test installer.sh / test (curl, debian:stable-slim, 1.80.0) (push) Has been cancelled
test installer.sh / test (curl, debian:testing-slim) (push) Has been cancelled
test installer.sh / test (curl, elementary/docker:stable) (push) Has been cancelled
test installer.sh / test (curl, elementary/docker:unstable) (push) Has been cancelled
test installer.sh / test (curl, fedora:latest, 1.80.0) (push) Has been cancelled
test installer.sh / test (curl, kalilinux/kali-dev) (push) Has been cancelled
test installer.sh / test (curl, kalilinux/kali-rolling) (push) Has been cancelled
test installer.sh / test (curl, opensuse/leap:latest) (push) Has been cancelled
test installer.sh / test (curl, opensuse/tumbleweed:latest) (push) Has been cancelled
test installer.sh / test (curl, oraclelinux:8) (push) Has been cancelled
test installer.sh / test (curl, oraclelinux:9) (push) Has been cancelled
test installer.sh / test (curl, parrotsec/core:latest) (push) Has been cancelled
test installer.sh / test (curl, rockylinux:8.7) (push) Has been cancelled
test installer.sh / test (curl, rockylinux:9) (push) Has been cancelled
test installer.sh / test (curl, ubuntu:20.04) (push) Has been cancelled
test installer.sh / test (curl, ubuntu:22.04) (push) Has been cancelled
test installer.sh / test (curl, ubuntu:24.04, 1.80.0) (push) Has been cancelled
test installer.sh / test (wget, debian:oldstable-slim) (push) Has been cancelled
test installer.sh / test (wget, debian:sid-slim) (push) Has been cancelled
update-flake / update-flake (push) Has been cancelled
tailscale.com/cmd/vet / vet (push) Has been cancelled
test installer.sh / notify-slack (push) Has been cancelled
Client security fixes (cmd/tailscale-tray/main.go): - SSRF protection in Add Server dialog (validateControlURL): reject private/loopback/link-local/cloud-metadata IPs via DNS resolution - RCE gate on AuthURL/BrowseToURL exec paths (validateAuthURL) - Sanitized URL logging (sanitizeURLForLog drops query auth tokens) - Error handling on exec.Command with user-facing showError() Admin panel security (web-admin): - Bcrypt password hashing (replaces SHA256) - Rate limiting: 5 failed logins → 15-min lockout - Session + login attempt cleanup goroutine (hourly) - url.QueryEscape / encodeURIComponent for all API params - Fail-hard startup when no TLS and non-loopback bind - ADMIN_PASSWORD required (no default), password min 12 chars - Username regex whitelist Installer hardening (Setup.wxs): - util:PermissionEx restricts SCM access: only Administrators + SYSTEM can start/stop/reconfigure service. Authenticated Users limited to QueryStatus/QueryConfig/Interrogate - Vital="yes" on ServiceInstall Docs & roadmap: - PRODUCTION_ROADMAP.md: 5-milestone plan (security + features + distribution + ops) with granular tasks, effort, done-when - CLIENT_SECURITY_AUDIT.md, SECURITY_FIXES.md, DEPLOYMENT.md - AI assistant rules (.cursorrules, .antigravityrules, etc.) Build & distribution: - build-msi.ps1, deploy-and-sign.ps1, sign-release.ps1 - redeploy.ps1, tray-deploy.ps1, test-msi.ps1 - installer/msi/ alternative WXS setup - Restored .github/workflows/ removed in mirror cleanup .gitignore hardened: *.pfx, *.p12, *.key, *.pem, .env*
219 lines
7.9 KiB
Plaintext
219 lines
7.9 KiB
Plaintext
# Antigravity Agent Kit — Antigravity Rules
|
|
|
|
> This workspace has an AI toolkit at `.agent/`. Read `.agent/ARCHITECTURE.md` first.
|
|
|
|
---
|
|
|
|
## What is `.agent/`?
|
|
|
|
This workspace contains the Antigravity AI capability expansion toolkit. It provides:
|
|
|
|
- **Agents** (`.agent/agents/*.md`) — 20 specialist AI personas (frontend, backend, security, etc.)
|
|
- **Skills** (`.agent/skills/*/SKILL.md`) — 37 domain-specific knowledge modules
|
|
- **Workflows** (`.agent/workflows/*.md`) — 12 step-by-step procedures triggered by slash commands
|
|
|
|
**Read `.agent/ARCHITECTURE.md` first** to understand the full system map.
|
|
|
|
---
|
|
|
|
## Agent Routing Protocol (MANDATORY)
|
|
|
|
Before writing any code or making design decisions:
|
|
|
|
1. **Identify the domain** of the user's request (Frontend, Backend, Security, Database, etc.)
|
|
2. **Select the matching agent** from `.agent/agents/`
|
|
3. **Read that agent's `.md` file** to understand its rules, persona, and linked skills
|
|
4. **Load linked skills** listed in the agent file's frontmatter (`skills:` field) — read `SKILL.md` first, then only sections matching the task
|
|
5. **Apply the agent's rules** when generating your response
|
|
6. **Announce**: State which agent expertise is being applied
|
|
|
|
### Agent Selection Guide
|
|
|
|
| Domain | Agent File | Key Skills |
|
|
|--------|-----------|------------|
|
|
| Web UI/UX | `frontend-specialist.md` | frontend-design, react-best-practices |
|
|
| API/Backend | `backend-specialist.md` | api-patterns, nodejs-best-practices |
|
|
| Database | `database-architect.md` | database-design |
|
|
| Mobile | `mobile-developer.md` | mobile-design |
|
|
| Security | `security-auditor.md` | vulnerability-scanner |
|
|
| Testing | `test-engineer.md` | testing-patterns, webapp-testing |
|
|
| Debugging | `debugger.md` | systematic-debugging |
|
|
| Planning | `project-planner.md` | brainstorming, plan-writing |
|
|
| Multi-domain | `orchestrator.md` | parallel-agents |
|
|
|
|
---
|
|
|
|
## Skill Loading Protocol
|
|
|
|
Skills are modular knowledge packages inside `.agent/skills/`.
|
|
|
|
1. Read `SKILL.md` inside the skill folder (e.g., `.agent/skills/clean-code/SKILL.md`)
|
|
2. Only read the sections relevant to the current task (**selective reading**)
|
|
3. If the skill has a `scripts/` folder, those scripts can be executed for validation
|
|
|
|
### Skill Structure
|
|
|
|
```
|
|
.agent/skills/{skill-name}/
|
|
├── SKILL.md # Main instructions (REQUIRED — read this first)
|
|
├── scripts/ # Runnable validation scripts (optional)
|
|
├── references/ # Templates and docs (optional)
|
|
└── assets/ # Images, resources (optional)
|
|
```
|
|
|
|
### Global Mandatory Skill
|
|
|
|
**`clean-code`** applies to ALL code output. Always follow `.agent/skills/clean-code/SKILL.md`.
|
|
|
|
---
|
|
|
|
## Workflow Conventions
|
|
|
|
Workflow files in `.agent/workflows/*.md` are triggered by slash commands (e.g., `/debug`, `/deploy`, `/ins-develop`).
|
|
|
|
### Special Annotations
|
|
|
|
When reading workflow files, understand these Antigravity-specific markers:
|
|
|
|
| Marker | Meaning |
|
|
|--------|---------|
|
|
| `$ARGUMENTS` | Placeholder for user-provided arguments after the slash command |
|
|
| `// turbo` | The NEXT step can be auto-executed without user confirmation |
|
|
| `// turbo-all` | ALL subsequent steps in this section can be auto-executed |
|
|
|
|
### Available Workflows (12)
|
|
|
|
| Command | Purpose |
|
|
|---------|---------|
|
|
| `/brainstorm` | Socratic discovery |
|
|
| `/create` | Create new features |
|
|
| `/debug` | Systematic debugging |
|
|
| `/deploy` | Production deployment |
|
|
| `/enhance` | Improve existing code |
|
|
| `/ins-develop` | INS Module development lifecycle |
|
|
| `/orchestrate` | Multi-agent coordination |
|
|
| `/plan` | Task breakdown |
|
|
| `/preview` | Preview changes |
|
|
| `/status` | Check project status |
|
|
| `/test` | Run tests |
|
|
| `/ui-ux-pro-max` | UI design with 50+ styles |
|
|
|
|
---
|
|
|
|
## Request Classification
|
|
|
|
Before any action, classify the request type:
|
|
|
|
| Request Type | Trigger | Action |
|
|
|-------------|---------|--------|
|
|
| **Question** | "what is", "explain" | Text response only |
|
|
| **Survey** | "analyze", "overview" | Research, no file changes |
|
|
| **Simple Code** | "fix", "add" (single file) | Direct inline edit |
|
|
| **Complex Code** | "build", "implement", "refactor" | Plan first, then implement |
|
|
| **Design/UI** | "design", "page", "dashboard" | Agent routing + plan required |
|
|
| **Slash Command** | `/command` | Read matching workflow file |
|
|
|
|
---
|
|
|
|
## Rules Priority
|
|
|
|
When rules conflict, apply this priority:
|
|
|
|
1. **P0** — This rules file (global)
|
|
2. **P1** — Agent-specific rules (from `.agent/agents/*.md`)
|
|
3. **P2** — Skill-specific rules (from `.agent/skills/*/SKILL.md`)
|
|
|
|
---
|
|
|
|
## Code Standards
|
|
|
|
- ALL code follows `clean-code` skill rules — no exceptions
|
|
- Use **English** for code, comments, and variable names
|
|
- Respond in the **user's language** for explanations
|
|
- Before modifying files, check for dependencies and update all affected files together
|
|
- For complex requests: **ask questions first** before implementing (Socratic Gate)
|
|
|
|
---
|
|
|
|
## Important Paths
|
|
|
|
```
|
|
.agent/
|
|
├── ARCHITECTURE.md # System overview — READ THIS FIRST
|
|
├── agents/ # 20 specialist agent definitions
|
|
├── skills/ # 37 knowledge modules
|
|
├── workflows/ # 12 slash command procedures
|
|
├── rules/ # IDE-specific instruction files
|
|
└── scripts/ # Master validation scripts
|
|
```
|
|
|
|
---
|
|
|
|
## Validation Scripts
|
|
|
|
| Script | Purpose | When |
|
|
|--------|---------|------|
|
|
| `checklist.py` | Priority-based project audit | Development, pre-commit |
|
|
| `verify_all.py` | Comprehensive verification | Pre-deployment |
|
|
|
|
```bash
|
|
python .agent/scripts/checklist.py .
|
|
python .agent/scripts/verify_all.py . --url http://localhost:3000
|
|
```
|
|
|
|
---
|
|
|
|
## 🛡️ AUTO-PROTECTION RULES (Always Active — Zero Config)
|
|
|
|
> These rules are **ALWAYS enforced automatically**. No configuration needed.
|
|
|
|
### Scout Block — Forbidden Directories
|
|
|
|
**NEVER read/list/explore:** `node_modules/`, `.git/`, `dist/`, `build/`, `out/`, `__pycache__/`, `.next/`, `.nuxt/`, `.turbo/`, `vendor/`, `target/`, `coverage/`, `bin/`, `obj/`, `packages/`, `.vs/`, `.idea/`
|
|
|
|
- Use `package.json` or `*.csproj` instead of reading `node_modules` or `packages/`
|
|
- Use `git` CLI instead of reading `.git/`
|
|
- Read source instead of build outputs
|
|
- If user insists → warn about context waste first
|
|
|
|
### Privacy Protection — Sensitive Files
|
|
|
|
**ASK before reading:** `.env`, `.env.*`, `*.key`, `*.pem`, `*.crt`, `*secret*`, `*credential*`, `appsettings.*.json`, `Web.config`, `launchSettings.json`, `*.pfx`, `*.p12`
|
|
|
|
> 🔒 "This file may contain sensitive data. Should I read it? I will NOT include secret values in my responses."
|
|
|
|
When approved: NEVER echo passwords/API keys. Replace with `[REDACTED]`.
|
|
|
|
### Post-Edit Awareness
|
|
|
|
After editing **5+ files** in one session, suggest a review:
|
|
> 📝 "Should I review changes for: complexity, duplication, dead code, shared utilities?"
|
|
|
|
### Context Efficiency
|
|
|
|
- **Search before read** — find specific content first, read targeted lines second
|
|
- **Don't re-read** — remember info from earlier in conversation
|
|
- **Read ranges** — for large files, read 50-100 lines at a time
|
|
- **Batch reads** — read multiple files in parallel, not sequential turns
|
|
- **Use manifests** — read `package.json` or `*.csproj`/`*.sln` instead of exploring deps
|
|
|
|
### Naming Enforcement
|
|
|
|
- C# source: `PascalCase` (`UserService.cs`)
|
|
- JS/TS source: `kebab-case` (`user-service.ts`)
|
|
- Components: `PascalCase` (`UserProfile.tsx`, `NavMenu.razor`)
|
|
- Tests (JS): `{name}.test.{ext}` | Tests (C#): `{Name}Tests.cs`
|
|
- **KEY**: Match the project's existing convention. Never mix styles.
|
|
- Warn on vague names (`Utils.cs` → suggest `StringUtils.cs`)
|
|
|
|
### Coding Level Auto-Detection
|
|
|
|
| Signal | Level | Style |
|
|
|---|---|---|
|
|
| Asks "what is X?" | Beginner | Explain with analogies |
|
|
| Writes pseudo-code | Intermediate | Working code + WHY |
|
|
| Gives file paths, function names | Senior | Code-first, trade-offs |
|
|
| "just do it", terse | Expert | Zero explanation, pure code |
|
|
|
|
**Default: Senior.** Match user's language register and formality.
|