AGENTS.md
+16 −2
https://raw.githubusercontent.com/yschimke/compose-preview-server/HEAD/AGENTS.md
− - **Reviewers, human or bot: verify before reporting an attribution finding.** It is the− Report only what the scanner exits 1 on, and quote its output. `Yuri Schimke <yuri@schimke.ee>` is+ - **Human reviewers: verify before reporting an attribution finding.** Automated reviewers do+ not report attribution at all; see [Review guidelines](#review-guidelines). It is the+ `<head>` must be the pull request's head commit as GitHub reports it: a commit made in a review+ checkout, for example by reapplying the diff, carries the reviewer's identity, and that is how+ every false report so far arose. Report only what the scanner exits 1 on, and quote its output. `Yuri Schimke <yuri@schimke.ee>` is+ ## Review guidelines+ - **Do not report commit author, committer or `Co-authored-by:` findings.** Your review sandbox+ applies the pull request as a new commit under your own identity (`Codex <codex@openai.com>`),+ so any identity you read from a local `git log` is yours, not the author's. Every such finding+ on these repositories has named a commit that exists only in the sandbox. Attribution is a+ human and CI concern; leave it out of reviews entirely. This overrides the human reviewer+ guidance on attribution elsewhere in this file.+ - The UI-builder design-guideline rules, prompt and picture plan are compose-ui-builder's+ (`docs/guidelines/android-design-guidelines.json`, embedded in `ui-builder-export` as+ `DesignGuidelineRuleSet.Bundled`). Nothing is vendored here: change them upstream, and they arrive+ with the next `composeai-ui-builder` bump.