# webapp - Agent Ruleset

> **Skills**: on-demand rulesets live in [`../skills/`](../skills/); the full
> list is the SKILLS CATALOGUE in the [root AGENTS.md](../AGENTS.md). The table
> below is generated by `sync.sh` - never hand-edit it.

### Auto-invoke Skills

When performing these actions, ALWAYS invoke the corresponding skill FIRST:

| Action | Skill |
| ------ | ----- |
| Adding a built-in attack skill to the agent | `builtin-agent-skill` |
| Adding or integrating an LLM provider | `llm-provider-integration` |
| Changing or adding a project setting or default value | `project-settings-cascade` |
| Editing a Prisma @default, a Python settings default, or the /defaults endpoint | `project-settings-cascade` |
| Editing agent skill classification, phase injection, or the attack-skill UI | `builtin-agent-skill` |
| Editing model-id routing or provider credential handling | `llm-provider-integration` |

---

## CRITICAL RULES - NON-NEGOTIABLE

<!-- Add a rule only if an agent breaks it while working elsewhere AND cannot
     discover it from the file being edited. Component patterns belong in a
     scoped skill. See the root AGENTS.md for repo-wide rules. -->

---

## TECH STACK

Next.js 16 (App Router, Turbopack) · React 19 · TypeScript · Prisma 6 (Postgres) ·
custom CSS design-token system (`src/styles/{base,components,themes,tokens}`, no
Tailwind) · Vitest 4. Runs in the `webapp` container; build via Docker.

## PROJECT STRUCTURE

```
src/app/          App Router routes + API route handlers (src/app/api/**)
src/components/   React components
src/context/      React context providers        src/providers/  provider wrappers
src/hooks/        hooks (e.g. useAlertModal)      src/lib/        client/server utilities
src/types/        shared TS types                 src/middleware.ts  edge middleware
server_actions/   Next.js server actions          prisma/schema.prisma  data model
```

## COMMANDS

```bash
# All commands run against the webapp image or an `npm ci`'d webapp/ (never global node)
cd webapp
npm run test          # vitest run --no-file-parallelism (full parallelism OOMs the box)
npm run type-check    # tsc --noEmit
npm run lint          # next lint

# Prisma schema changes: db push, NOT migrate
docker compose exec webapp npx prisma db push
```

## QA CHECKLIST

- [ ] `npm run type-check` and `npm run lint` clean.
- [ ] `npm run test` green (with `--no-file-parallelism`).
- [ ] New or changed behaviour is covered by a test (see the `redamon-testing` skill for where + how).
- [ ] Prisma schema edited? Applied with `db push` (not `prisma migrate`) and client regenerated.
- [ ] UI prompts/alerts use the `useAlertModal` hook, never `window.alert` / `window.confirm`.
- [ ] Rebuilt the webapp image (prod) or relied on dev hot-reload as appropriate.
