docs: secure-coding rules for agents, and refresh stale AGENTS.md top-matter #16
Reference in New Issue
Block a user
Delete Branch "docs/agent-security-rules"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Two doc commits: a new secure-coding rules section, plus a fix for top-matter the rebrand left stale.
9156525— secure-coding rulesAGENTS.mdcarried two security invariants (bearer auth, CORS) but nothing about the code an agent actually writes here. That is the gap worth closing: measured rates for AI-generated web/backend code are ~40% vulnerable (Pearce et al.), 45% failing security tests (Veracode 2025), and users with assistants shipped SQLi at 36% vs 7% for the control group (Perry et al., Stanford). The failure classes cluster on broken access control, injection, session/error handling and invented dependencies — all live surfaces in this repo.Rules were extracted, not pasted. Every one names a guard that already exists in-tree, so the instruction is match this, not invent something:
store.go— all queries use?html/templateonly; notemplate.HTMLon stored dataweb.go:85poller.go:144 fetchableSeriesURLfetch.go:16 maxBodyBytessubtle.ConstantTimeCompare, never==middleware.go:22,session.go:61web.go:151X-Forwarded-Protofor Secure; rightmost XFF for IPsession.go:68,101session.go:72-94,Verifyhandlers.go:48MaxBytesReader64 KB, 400 on bad key/status/kindel({text}), never{html}el()in both userscriptsfetch()/authHeaders()→API_BASEonlyauthHeaderslocalStorage= cache/queue, never credentialsPlus a dependency rule (stdlib first; verify a package exists before adding — ~20% of LLM-proposed packages don't resolve, which is the slopsquatting vector) and a review gate marking auth/CORS/session/crypto/fetch-gate as security-critical.
Deliberately excluded: container signing, k8s admission control, IaC scanning, PII/HIPAA/PCI, C/C++ memory safety. Per OpenSSF's guide for AI assistant instructions, irrelevant rules make a model generate code compensating for attacks that cannot happen. None of those apply to a single-user Go + SQLite + userscript stack.
Sources: OWASP AISVS 1.0 Appendix C, OWASP Top 10 / ASVS v5, OpenSSF Security-Focused Guide for AI Code Assistant Instructions (2025-08-01).
5d4d890— stale top-matterThe rebrand rewrote root
AGENTS.mdas a compression pass and switched Bromite -> Violentmonkey, but left the project described as a manga-only tracker over two sites. Six sites, two libraries and two userscripts now exist.Root
AGENTS.md:kindcolumn, and the<site>:<series_id>key shape.backend/AGENTS.md— two instances of the same defect, found while verifying the above:novelfull|lightnovelworldand thekindcolumn.NOVEL_USERSCRIPT_PATHdocumented — it shipped inmain.go:150undocumented.The dated Cloudflare paragraph is left verbatim: it is a timestamped observation ("Verified 2026-07-26"), so rewriting it would falsify a record rather than update it.
userscript/AGENTS.mdis untouched; it already documents both novel adapters and theLIBRARY/STORE_PREFIXsplit.Verification
Docs-only, no code touched. Every code reference above was read at
4229c17before being cited — the fetch gate, body cap, constant-time compares, cookie flags, handler validation,el()helper and both route registrations. No invented line numbers.Not addressed here
The
API_TOKENliteral is committed in plaintext in both userscripts and in their@downloadURL/@updateURLlines. The new rules say not to propagate it, but the actual remedy is rotation plus build-time substitution, since the value is already in git history. Separate change; flagging it so it does not get lost.Repo had two security invariants (bearer auth, CORS) but no guidance for code an agent writes. Studies put AI-generated web/backend code at ~40% vulnerable, concentrated in broken access control, injection, session and error handling — the exact surfaces here. Rules are extracted, not pasted from a generic checklist: each one names a guard that already exists in-tree (fetchableSeriesURL, maxBodyBytes, ConstantTimeCompare, MaxBytesReader, el({text})), so the instruction is match-this rather than invent-something. Per OpenSSF guidance, irrelevant rules make a model generate code compensating for attacks that cannot happen, so container signing, IaC, PII and memory-safety items are left out.