Agent documentation

Agents should keep changes minimal, validate with typecheck/lint/build, and avoid public safety issues such as secrets or private URLs.

Status: active baseline policy.