The rebrand (4229c17) rewrote root AGENTS.md as a compression pass and
switched Bromite->Violentmonkey, but the description still called the
project a manga-only tracker over two sites. Six sites, two libraries and
two userscripts now exist.
Root AGENTS.md:
- 'What this is' names both scripts and their sites, the kind column, and
the <site>:<series_id> key shape.
- Origins constraint generalised past Asura/Demonic.
- Records that kagane and novelfull are reliably Cloudflare-challenged and
browser-polled, which is the standing exception to the 'blocking is
IP-reputation-based and not reproducible' note directly above it.
- Diagram says two userscripts.
backend/AGENTS.md:
- Store key list gained novelfull|lightnovelworld and the kind column.
- NOVEL_USERSCRIPT_PATH documented; it shipped in main.go:150 undocumented.
Child userscript/AGENTS.md already covered the novel adapters, so it is
untouched.
Repo had two security invariants (bearer auth, CORS) but no guidance for
code an agent writes. Studies put AI-generated web/backend code at ~40%
vulnerable, concentrated in broken access control, injection, session and
error handling — the exact surfaces here.
Rules are extracted, not pasted from a generic checklist: each one names a
guard that already exists in-tree (fetchableSeriesURL, maxBodyBytes,
ConstantTimeCompare, MaxBytesReader, el({text})), so the instruction is
match-this rather than invent-something. Per OpenSSF guidance, irrelevant
rules make a model generate code compensating for attacks that cannot
happen, so container signing, IaC, PII and memory-safety items are left out.