docs: secure-coding rules for agents, and refresh stale AGENTS.md top-matter #16

Merged
sulthan merged 2 commits from docs/agent-security-rules into main 2026-08-06 20:07:35 +07:00

2 Commits

Author SHA1 Message Date
sulthan 5d4d890c34 docs: propagate novel library + new sites into stale AGENTS.md top-matter
The rebrand (4229c17) rewrote root AGENTS.md as a compression pass and
switched Bromite->Violentmonkey, but the description still called the
project a manga-only tracker over two sites. Six sites, two libraries and
two userscripts now exist.

Root AGENTS.md:
- 'What this is' names both scripts and their sites, the kind column, and
  the <site>:<series_id> key shape.
- Origins constraint generalised past Asura/Demonic.
- Records that kagane and novelfull are reliably Cloudflare-challenged and
  browser-polled, which is the standing exception to the 'blocking is
  IP-reputation-based and not reproducible' note directly above it.
- Diagram says two userscripts.

backend/AGENTS.md:
- Store key list gained novelfull|lightnovelworld and the kind column.
- NOVEL_USERSCRIPT_PATH documented; it shipped in main.go:150 undocumented.

Child userscript/AGENTS.md already covered the novel adapters, so it is
untouched.
2026-08-06 18:16:05 +07:00
sulthan 91565252d5 docs: add Go and userscript secure-coding rules to AGENTS.md
Repo had two security invariants (bearer auth, CORS) but no guidance for
code an agent writes. Studies put AI-generated web/backend code at ~40%
vulnerable, concentrated in broken access control, injection, session and
error handling — the exact surfaces here.

Rules are extracted, not pasted from a generic checklist: each one names a
guard that already exists in-tree (fetchableSeriesURL, maxBodyBytes,
ConstantTimeCompare, MaxBytesReader, el({text})), so the instruction is
match-this rather than invent-something. Per OpenSSF guidance, irrelevant
rules make a model generate code compensating for attacks that cannot
happen, so container signing, IaC, PII and memory-safety items are left out.
2026-08-06 18:11:35 +07:00