NODEDC_MISSION_CORE/AGENTS.md

41 lines
1.9 KiB
Markdown

# Repository operating rules
This repository investigates an owner-controlled XGRIDS/LixelKity K1 as a
black-box sensor. Preserve the device, the Mac, the working LAN, and raw
evidence.
## Non-negotiable safety boundaries
- Default to non-mutating discovery or read-only operations. CoreBluetooth BLE
scanning on macOS is active discovery, not passive radio sniffing.
- Do not send BLE writes until the exact service, characteristic, framing,
payload semantics, rollback, and expected state transition are documented.
- BLE notification subscription may perform the standard temporary CCCD write;
disclose it explicitly and do not conflate it with provisioning writes.
- Do not fuzz, brute-force, upload firmware, delete device files, guess SSH/ADB
credentials, or probe unrelated LAN devices.
- Network probes must target the confirmed K1 IP. A full home-subnet scan is
not a default operation.
- Never place a Wi-Fi password in CLI arguments, logs, manifests, source, test
fixtures, or Git history.
- Do not install Python packages globally. Use the repository-local `.venv`
managed by `uv`.
- Do not install or alter Homebrew/system components unless the user explicitly
authorizes that concrete change.
## Evidence rules
- Reference inputs under `docs/reference/` are immutable; write corrections in
audits or ADRs.
- Every real experiment gets a session ID, UTC and monotonic timestamps, a
redacted manifest, operator notes, and SHA-256 hashes for raw artifacts.
- Real PCAP, K1 projects, logs, images, point clouds, credentials, serials, and
router client lists stay out of normal Git. Git LFS solves size, not secrecy.
- Synthetic or explicitly redacted fixtures may be committed under
`tests/fixtures/`.
## Implementation order
Follow the gates in `docs/01_IMPLEMENTATION_PLAN.md`. Do not build heavy
decoders before BLE/Wi-Fi/data-session evidence exists.