Skip to content

Add AGENTS.md with project conventions for coding agents - #5339

Open
khushal-winner wants to merge 10 commits into
OWASP:mainfrom
khushal-winner:add-agents-md
Open

Add AGENTS.md with project conventions for coding agents#5339
khushal-winner wants to merge 10 commits into
OWASP:mainfrom
khushal-winner:add-agents-md

Conversation

@khushal-winner

Copy link
Copy Markdown
Contributor

Proposed change

Resolves #5330

Adds AGENTS.md to eliminate per-conversation repo structure rediscovery by
coding agents.

  • Repository layout, stack, Django settings classes (base/local/test/staging/production)
  • All make targets: app lifecycle, management commands by app, data pipeline order
  • Testing setup: pytest flags, coverage thresholds, conftest setup, Jest config details
  • Code conventions: ruff config, Prettier ignore rules, path aliases, commit message format
  • Architecture boundaries: auth/CSRF relay, NestBot structure, GitHub sync off-request-path

Checklist

  • Required: I followed the contributing workflow
  • Required: I verified that my code works as intended and resolves the issue as described
  • Required: I ran all required checks and tests locally; all warnings addressed and failures resolved
  • I used AI for code, documentation, tests, or communication related to this PR

@github-actions github-actions Bot added the docs Improvements or additions to documentation label Jul 30, 2026
@github-actions

Copy link
Copy Markdown

Contribution validation failed:

  • commit_sign_off: One or more commits are missing or have an invalid Signed-off-by trailer.

@coderabbitai

coderabbitai Bot commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Summary by CodeRabbit

  • Documentation
    • Added a comprehensive repository conventions and reference guide covering project layout, Docker-first workflows, testing, coverage, and dependency management.
    • Documented Django settings and model patterns, API boundaries, frontend routing and data-fetching conventions, required environment variables, and authentication and architecture guidance.

Walkthrough

Adds AGENTS.md as a project-wide guide covering repository structure, development commands, testing, dependencies, application architecture, environment variables, and authentication boundaries.

Changes

Agent Documentation

Layer / File(s) Summary
Repository structure and development workflows
AGENTS.md
Documents the repository layout, Django settings patterns, Docker-first commands, management commands, testing expectations, and dependency tooling.
Application and API boundaries
AGENTS.md
Describes Django model bases, REST and GraphQL APIs, internal endpoints, NestBot structure, frontend routing, and code-quality conventions.
Environment and authentication architecture
AGENTS.md
Defines environment-file purposes, required variables, architecture boundaries, and CSRF/session authentication responsibilities.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Suggested reviewers: arkid15r, kasya

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the addition of AGENTS.md and its purpose for coding agents.
Description check ✅ Passed The description directly explains the AGENTS.md addition and lists the documented repository conventions.
Linked Issues check ✅ Passed The PR adds AGENTS.md with the project layout, stack, commands, and conventions requested by issue #5330.
Out of Scope Changes check ✅ Passed The changes are limited to the requested AGENTS.md documentation and align with issue #5330.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@AGENTS.md`:
- Line 27: Update AGENTS.md to resolve the documentation lint warnings: add a
language identifier to the repository-layout code fence, add the missing period
after “etc”, and insert blank lines immediately before the shell fences around
the referenced sections. Preserve the existing documentation content and
commands.
- Around line 188-201: Update the “Data pipeline” description associated with
make sync-data to avoid claiming it runs every listed management command. Either
document the complete command sequence, including the omitted GitHub, OWASP, AI,
mentorship, and Slack commands, or change the wording to state that it runs only
the core stages shown.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 90565fcf-b532-4e73-ba16-10c96eb3c6b9

📥 Commits

Reviewing files that changed from the base of the PR and between 157e1e8 and 6cfbeb8.

📒 Files selected for processing (1)
  • AGENTS.md

Comment thread AGENTS.md Outdated
Comment thread AGENTS.md Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 1 file

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread AGENTS.md
Comment thread AGENTS.md Outdated
Comment thread AGENTS.md Outdated
@github-actions

Copy link
Copy Markdown

Contribution validation failed:

  • commit_signature: One or more commits are not signed.

  • commit_sign_off: One or more commits are missing or have an invalid Signed-off-by trailer.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@AGENTS.md`:
- Line 188: Update the AGENTS.md OWASP management-command catalog to include
owasp-aggregate-member-contributions, matching the command referenced by the
Data pipeline and preserving consistency so sync-data can be reproduced
manually.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 1db0a0f9-2195-4571-9e8b-b25da8f6c747

📥 Commits

Reviewing files that changed from the base of the PR and between 6cfbeb8 and a756e5f.

📒 Files selected for processing (1)
  • AGENTS.md

Comment thread AGENTS.md
@github-actions

Copy link
Copy Markdown

Contribution validation failed:

  • commit_signature: One or more commits are not signed.

  • commit_sign_off: One or more commits are missing or have an invalid Signed-off-by trailer.

@github-actions

Copy link
Copy Markdown

Contribution validation failed:

  • commit_sign_off: One or more commits are missing or have an invalid Signed-off-by trailer.

coderabbitai[bot]
coderabbitai Bot previously approved these changes Jul 30, 2026
@github-actions

Copy link
Copy Markdown

Contribution validation failed:

cubic-dev-ai[bot]
cubic-dev-ai Bot previously approved these changes Jul 30, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 1 file (changes from recent commits).

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@github-actions

Copy link
Copy Markdown

Contribution validation failed:

coderabbitai[bot]
coderabbitai Bot previously approved these changes Jul 30, 2026
cubic-dev-ai[bot]
cubic-dev-ai Bot previously approved these changes Jul 30, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 1 file (changes from recent commits).

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

Signed-off-by: Khushal Malhotra <redmi5a3217@gmail.com>
Signed-off-by: Khushal Malhotra <redmi5a3217@gmail.com>
Signed-off-by: Khushal Malhotra <redmi5a3217@gmail.com>
…alog

Signed-off-by: Khushal Malhotra <redmi5a3217@gmail.com>
Signed-off-by: Khushal Malhotra <redmi5a3217@gmail.com>
Comment thread AGENTS.md Outdated
```bash
cd backend
poetry install
poetry run pytest tests/unit/apps/<app>/ -xvs

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this is enough for running the tests. Please see how the backend tests is run in GH actions

Signed-off-by: Khushal Malhotra <redmi5a3217@gmail.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@AGENTS.md`:
- Around line 241-244: Update the command sequence in AGENTS.md so sourcing
.env.unit-tests and enabling automatic export occur only inside a subshell that
runs pytest. Execute the migrate and runserver commands afterward from the
parent shell without the unit-test environment variables inherited.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 37a42395-1f59-45a2-a101-ee80a7c6e049

📥 Commits

Reviewing files that changed from the base of the PR and between a869bd0 and 2f003c8.

📒 Files selected for processing (1)
  • AGENTS.md

Comment thread AGENTS.md

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 1 file (changes from recent commits).

Confidence score: 3/5

  • In AGENTS.md, exporting .env.unit-tests with set -a causes DJANGO_CONFIGURATION=Test to leak into later migrate and runserver commands, so developers may run migrations or start the app against test settings and get incorrect behavior or data-targeting mistakes—scope the env var to just the test command (or explicitly unset/reset it before non-test commands).
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="AGENTS.md">

<violation number="1" location="AGENTS.md:241">
P1: Test environment variables leak into `migrate` and `runserver`. After `set -a && source .env.unit-tests`, `DJANGO_CONFIGURATION=Test` persists for subsequent commands: `migrate` and `runserver` will use Test settings (LocMemCache, empty DB_HOST/DB_NAME) instead of Local. Either run pytest in a subshell, or document that only `pytest` needs those vars.</violation>
</file>

Tip: Review your code locally with the cubic CLI to iterate faster.

Re-trigger cubic

Comment thread AGENTS.md
```bash
cd backend
poetry install
set -a && source .env.unit-tests && set +a

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: Test environment variables leak into migrate and runserver. After set -a && source .env.unit-tests, DJANGO_CONFIGURATION=Test persists for subsequent commands: migrate and runserver will use Test settings (LocMemCache, empty DB_HOST/DB_NAME) instead of Local. Either run pytest in a subshell, or document that only pytest needs those vars.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At AGENTS.md, line 241:

<comment>Test environment variables leak into `migrate` and `runserver`. After `set -a && source .env.unit-tests`, `DJANGO_CONFIGURATION=Test` persists for subsequent commands: `migrate` and `runserver` will use Test settings (LocMemCache, empty DB_HOST/DB_NAME) instead of Local. Either run pytest in a subshell, or document that only `pytest` needs those vars.</comment>

<file context>
@@ -238,7 +238,8 @@ The canonical path is Docker. For quick iteration you can run tools directly:
 cd backend
 poetry install
-poetry run pytest tests/unit/apps/<app>/ -xvs
+set -a && source .env.unit-tests && set +a
+poetry run pytest tests/unit
 poetry run python manage.py migrate
</file context>

Signed-off-by: Khushal Malhotra <redmi5a3217@gmail.com>

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 1 file (changes from recent commits).

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Requires human review: Auto-approval blocked by 1 unresolved issue from previous reviews.

Re-trigger cubic

Signed-off-by: Khushal Malhotra <redmi5a3217@gmail.com>
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jul 31, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 1 file (changes from recent commits).

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Requires human review: Auto-approval blocked by 1 unresolved issue from previous reviews.

Re-trigger cubic

Signed-off-by: Khushal Malhotra <redmi5a3217@gmail.com>

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

0 issues found across 1 file (changes from recent commits).

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Requires human review: Auto-approval blocked by 1 unresolved issue from previous reviews.

Re-trigger cubic

Signed-off-by: Khushal Malhotra <redmi5a3217@gmail.com>
@sonarqubecloud

Copy link
Copy Markdown

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

2 issues found across 1 file (changes from recent commits).

Confidence score: 3/5

  • In AGENTS.md, the e2e sequence appears to run poetry run python manage.py migrate from e2e/ after changing directories, which can fail because manage.py and the Poetry project live under backend/; this makes the documented workflow break for anyone following it — update the steps to cd ../backend (or use explicit paths) before migrate commands.
  • In AGENTS.md, using poetry install --only fuzz can omit main dependencies and leave the environment incomplete, causing later commands/tests to fail in non-obvious ways — switch to poetry install --with fuzz so fuzz deps are added without dropping core packages.
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="AGENTS.md">

<violation number="1" location="AGENTS.md:324">
P1: The e2e test steps have a directory navigation bug. After step 1 leaves the working directory in `e2e/`, step 2 runs `poetry run python manage.py migrate` from `e2e/` — but `manage.py` and the Poetry project are in `backend/`. Similarly step 3 runs `pnpm run dev` from `e2e/` instead of `frontend/`. Prefix each step's command with `cd ../backend`, `cd ../frontend`, or `cd ..` as appropriate so each command runs from the correct directory.</violation>

<violation number="2" location="AGENTS.md:343">
P2: `poetry install --only fuzz` installs only the fuzz group and excludes main dependencies. Use `poetry install --with fuzz` instead — it adds the fuzz group while preserving main deps. `--with` is safer and more conventional, especially since a prior `poetry install` from the e2e section would already have main deps installed.</violation>
</file>

Tip: Review your code locally with the cubic CLI to iterate faster.

Re-trigger cubic

Comment thread AGENTS.md

# 2. Start a backend: source backend/.env.e2e-tests (point DJANGO_DB_HOST and
# DJANGO_REDIS_HOST at localhost), run migrations, then:
poetry run python manage.py migrate

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: The e2e test steps have a directory navigation bug. After step 1 leaves the working directory in e2e/, step 2 runs poetry run python manage.py migrate from e2e/ — but manage.py and the Poetry project are in backend/. Similarly step 3 runs pnpm run dev from e2e/ instead of frontend/. Prefix each step's command with cd ../backend, cd ../frontend, or cd .. as appropriate so each command runs from the correct directory.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At AGENTS.md, line 324:

<comment>The e2e test steps have a directory navigation bug. After step 1 leaves the working directory in `e2e/`, step 2 runs `poetry run python manage.py migrate` from `e2e/` — but `manage.py` and the Poetry project are in `backend/`. Similarly step 3 runs `pnpm run dev` from `e2e/` instead of `frontend/`. Prefix each step's command with `cd ../backend`, `cd ../frontend`, or `cd ..` as appropriate so each command runs from the correct directory.</comment>

<file context>
@@ -301,18 +301,73 @@ hooks need `terraform`/`tflint`/`terraform-docs` binaries; `SKIP` those when
+
+# 2. Start a backend: source backend/.env.e2e-tests (point DJANGO_DB_HOST and
+#    DJANGO_REDIS_HOST at localhost), run migrations, then:
+poetry run python manage.py migrate
+poetry run gunicorn wsgi:application --bind 0.0.0.0:9000
+
</file context>

Comment thread AGENTS.md
# 1. Start the stack as above (backend/.env.fuzz-tests, gunicorn on :9500).
# 2. Install the fuzz extra and run the Schemathesis tests:
cd backend
poetry install --only fuzz

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: poetry install --only fuzz installs only the fuzz group and excludes main dependencies. Use poetry install --with fuzz instead — it adds the fuzz group while preserving main deps. --with is safer and more conventional, especially since a prior poetry install from the e2e section would already have main deps installed.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At AGENTS.md, line 343:

<comment>`poetry install --only fuzz` installs only the fuzz group and excludes main dependencies. Use `poetry install --with fuzz` instead — it adds the fuzz group while preserving main deps. `--with` is safer and more conventional, especially since a prior `poetry install` from the e2e section would already have main deps installed.</comment>

<file context>
@@ -301,18 +301,73 @@ hooks need `terraform`/`tflint`/`terraform-docs` binaries; `SKIP` those when
+# 1. Start the stack as above (backend/.env.fuzz-tests, gunicorn on :9500).
+# 2. Install the fuzz extra and run the Schemathesis tests:
+cd backend
+poetry install --only fuzz
+BASE_URL=http://localhost:9500 REST_URL=http://localhost:9500/api/v0 \
+CSRF_TOKEN=$(curl -fsSL "$BASE_URL/csrf" | jq -r '.csrftoken') \
</file context>
Suggested change
poetry install --only fuzz
poetry install --with fuzz

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docs Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add AGENTS.md

2 participants