Essential cookies are active for security and service continuity. You can also enable optional analytics cookies.
Cookie summary:
Disclaimer summary: This is a research product/service offered without warranty, guarantee, or promise regarding availability, accuracy, performance, security, or any other aspect.

agent_v2.md
<!-- AI-native Delivery Experience - IntDEx. Provided under CC BY 4.0. https://IntDEx.org --># Agent InstructionsFor Product: XYZ Website## 0) MANDATORY PER-MESSAGE SCRIPT (read this before anything else)Two calls, every single chat message, no exceptions, in this exact order. Run both from the workspace root (relative paths below assume the terminal's current directory is the workspace root.Each gate script invocation MUST be run to completion (its own prompt returned) before issuing any further terminal command. Never issue a second gate/tool call while a prior one is still executing, even in a different logical step — the dual-model L1 (Level One Model) review/audit can take 10–40+ seconds per call.**FIRST action of the turn, before any planning/reading/editing:**```powershell -ExecutionPolicy Bypass -File ".pdm/ai_delivery_engine/per_message_deterministic_script.ps1" -Phase pre```Non-zero exit code = STOP. Do nothing else. Print the failing gate's output verbatim.**LAST action of the turn, immediately before ending the response, after all work is done:**```powershell -ExecutionPolicy Bypass -File ".pdm/ai_delivery_engine/per_message_deterministic_script.ps1" -Phase post -WorkItem "<work-item-name>" -UserMessage "<verbatim user message, spelling/grammar corrected>" -Summary "<one-line summary of what this message asked for>"```Non-zero exit code = the response is NOT complete; fix and re-run before closing.### Dual-model mode (when `dual_ai_llm.py` is present, i.e. `-DualAiLlm Yes` was used at init)Both calls above already invoke the Level One Model (L1) automatically (`Invoke-LlmComplianceCheck` inside the gate script) and print its output to the console. "L1" denotes tier/role (Level One), not a claim that this model is cheaper than the high-cost model (Copilot) - the operator may configure any model. When that output is present, you MUST NOT simply display/quote it and move on:- **Pre-phase**: read L1's compliance verdict and its improved/compliant restatement of the message before starting any planning, editing, or tool use for the turn. If L1 flags a concrete compliance concern, address it (or explicitly explain why not) before proceeding with the work.- **Post-phase**: read L1's audit of the Work Item's generated Intent/Prompt/Test artefacts. For each concrete, actionable finding (e.g. vague acceptance criteria, missing `verification_source`, missing HITL checkpoint), either implement the improvement immediately in this same turn, or explicitly tell the user why it was not applied. Never treat L1's post-audit as informational-only output to quote and discard.- If `dual_ai_llm.py` is absent, or a `DUAL-AI-LLM: SKIPPED`/`WARN` line appears instead of a verdict (e.g. missing API key, no python on PATH), there is nothing to assess — proceed as normal and do not block on it; this is always non-blocking/advisory only, per the gate script's own design.- **Task routing (deterministic, no LLM self-judgement)**: the pre-phase output includes a `TASK-ROUTING-GATE: CLASSIFICATION=SIMPLE|ADVANCED :: <reason>` line, decided purely by regex rules in `per_message_deterministic_script.ps1` (`Invoke-TaskRoutingClassification`). If `SIMPLE` and the `[L1 - TASK ROUTING]` block below it contains a `DRAFT`, apply that draft directly after a light sanity check instead of independently re-designing the change. If `ADVANCED`, or no draft was produced, implement the request yourself as normal. The classification rules (which patterns count as "simple" vs "always advanced") are edited directly in that one PowerShell function — no separate config file, no duplicated model name.## Product DescriptionYou are working on a new simple website to promote XYZ product.## 1) Architecture- Keep a lightweight monolithic structure.- Preserve current routing behavior and existing user flows.- Prefer incremental edits over rewrites.- Do not introduce breaking changes to public/admin/member functionality.- Keep backward compatibility with existing database data and schema migrations.## 2) Technology- Backend: PHP (procedural + helper-method style), server-rendered HTML.- Web server: Apache with rewrite/security rules.- Data: MySQL with safe migrations for existing installations.- Frontend: minimal JS, simple CSS, no heavy framework unless requested.- Keep dependencies minimal; prefer native PHP/Apache/MySQL features.## 3) Security (mandatory)- Enforce CSRF protection on all state-changing requests.- Validate and sanitize all input; escape all output.- Use prepared statements for all database queries.- Keep authentication/authorization checks strict for admin/member areas.- Prevent direct access to sensitive storage/config/log files.- Keep security headers and safe cookie/session behavior.- Avoid exposing secrets, tokens, internal paths, or sensitive PII in UI/logs.- Preserve or improve brute-force protection and abuse controls.## 4) Coding directives- Make the smallest safe change needed.- Keep existing coding style and naming conventions.- Do not remove existing protections while adding features.- If schema changes are needed, make them additive and migration-safe.- After edits, verify no new errors are introduced.## 5) Delivery process- The token `{v}` in a file name represents the version number; only the HIGHEST version file present should be considered.- For every chat message, load and follow `.pdm/ai_delivery_engine/ai_delivery_engine_manifest_v1.md` in full (Tier 1). It governs everything not already covered by section 0's script commands.## 6) Output expectations- Provide concise summaries of what changed and why, with file paths.- Highlight any risk or migration impact.- If a request is ambiguous, choose the safest non-breaking implementation first.Back to home
Comments
Sign in to add and view your comments and replies.