Goal
Perform a production-level review of an AGENTS.md file and repair multiple instructions that are vague, unsafe, or inconsistent with the repository's actual architecture.
Repository Context
This is a production full-stack platform.
platform/
├── apps/
│ ├── web/
│ ├── api/
│ └── worker/
├── packages/
│ ├── database/
│ └── contracts/
├── migrations/
├── generated/
├── package.json
└── AGENTS.md
The repository has these technical constraints:
Package manager pnpm
Database PostgreSQL
Authentication Session based
Authorization Organization scoped
Workers Retry failed jobs
Generated directory API contract output
The repository follows these production rules:
- Use
pnpmconsistently. - New schema changes require new migrations; previously applied migration history must be preserved.
- Related database writes that form one business operation must remain atomic.
- Authentication identifies the user, but authorization determines access to organizations and resources.
- Secrets must not be committed or hardcoded in source code.
- Generated API contract output must not be manually edited.
- Background jobs may execute more than once and must tolerate retries.
- Substantial changes must go through the repository's validation workflow.
Current AGENTS.md
# Project Instructions
## Development
- Use whatever package manager is convenient.
- Follow best practices.
- Write clean code.
## Database
- Update existing migration files when the schema changes.
- Transactions are optional even when several related writes are performed.
## Security
- Authentication is enough for protected resources.
- Put API keys in source code during development if that is easier.
## Generated Code
- Generated files may be edited directly for small fixes.
## Background Jobs
- Jobs normally execute once, so duplicate execution does not need to be considered.
## Validation
- Run tests if you think they are necessary.
Your Task
Review and repair the AGENTS.md.
Replace vague or unsafe guidance with concrete repository-specific instructions.
The corrected file must protect the repository's package-management, migration, transaction, authorization, secrets, generated-code, background-job, and validation invariants.
Do not turn AGENTS.md into general software-engineering documentation.