2026-06-22 21:44:32 +02:00
# Binect-JS — Agent Instructions
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
## Repo Identity
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
**Purpose:** JavaScript/TypeScript wrapper (@binect/js ) for the Binect REST API to send PDF documents as physical mail via Deutsche Post, plus a browser-based Explorer. Thin, transparent, zero-runtime-dependency SDK. Governance in INTENT.md / SCOPE.md.
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
**Domain:** communication
**Repo slug:** binect-js
**Topic ID:** `36c7421b-c537-4723-bf75-42a3ebc6a1dc`
**Workplan prefix:** `BINECT-WP-`
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
---
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
## State Hub Integration
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
The Custodian State Hub tracks work across all domains. Interact via HTTP REST —
there is no MCP server for Codex agents.
| Context | URL |
|---------|-----|
| Local workstation | `http://127.0.0.1:8000` |
| Remote via tunnel | `http://127.0.0.1:18000` |
### Orient at session start
2026-01-14 23:16:38 +01:00
```bash
2026-06-22 21:44:32 +02:00
# Offline brief — works without hub connection
cat .custodian-brief.md
# Active workstreams for this domain
curl -s "http://127.0.0.1:8000/workstreams/?topic_id=36c7421b-c537-4723-bf75-42a3ebc6a1dc& status=active" \
| python3 -m json.tool
# Check inbox
curl -s "http://127.0.0.1:8000/messages/?to_agent=binect-js& unread_only=true" \
| python3 -m json.tool
2026-01-14 23:16:38 +01:00
```
2026-06-22 21:44:32 +02:00
Mark a message read:
```bash
curl -s -X PATCH "http://127.0.0.1:8000/messages/< id > /read" \
-H "Content-Type: application/json" -d '{}'
2026-01-14 23:16:38 +01:00
```
2026-06-22 21:44:32 +02:00
### Log progress (required at session close)
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
```bash
curl -s -X POST http://127.0.0.1:8000/progress/ \
-H "Content-Type: application/json" \
-d '{
"summary": "what was done",
"event_type": "note",
"author": "codex",
"workstream_id": "< uuid > ",
"task_id": "< uuid > "
}'
```
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
Omit `workstream_id` / `task_id` when not applicable.
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
### Update task status
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
```bash
curl -s -X PATCH "http://127.0.0.1:8000/tasks/< task_id > " \
-H "Content-Type: application/json" \
-d '{"status": "progress"}'
# values: wait | todo | progress | done | cancel
```
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
### Flag a task for human review
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
```bash
curl -s -X PATCH "http://127.0.0.1:8000/tasks/< task_id > " \
-H "Content-Type: application/json" \
-d '{"needs_human": true, "intervention_note": "reason"}'
2026-01-14 23:16:38 +01:00
```
2026-06-22 21:44:32 +02:00
---
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
## Session Protocol
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
**Start:**
1. `cat .custodian-brief.md` — domain goal and open workstreams (offline-safe)
2. Check inbox: `GET /messages/?to_agent=binect-js&unread_only=true` ; mark read
3. Scan workplans: `ls workplans/` — note `status: ready` , `active` , or `blocked` files and open tasks
4. Check human-needed tasks: `GET /tasks/?needs_human=true`
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
**During work:**
- Update task statuses in workplan files as tasks progress
- Record significant decisions via `POST /decisions/`
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
**Close:**
1. Update workplan file task statuses to reflect progress
2. Log: `POST /progress/` with a summary of what changed
3. Note for the custodian operator: after workplan file changes, run from
`~/state-hub` :
```bash
make fix-consistency REPO=binect-js
```
This syncs task status from files into the hub DB.
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
---
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
## Credential and access routing
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
**Audience:** Codex, Claude Code, Grok, and custodian agents that call **llm-connect**
for inference. Run this check **before** requesting secrets, API keys, SSH access,
login tokens, or database passwords — in any repo, not only `ops-warden` .
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
ops-warden **issues SSH certificates only** (`warden sign` , `cert_command` ). Every
other credential need belongs to another subsystem. **Do not** message
`ops-warden` on State Hub expecting a secret value; the reply is a pointer, not a key.
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
### Lookup (do this first)
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
```bash
warden route find "< describe your need > " --json
warden route show < catalog-id > --json
2026-01-14 23:16:38 +01:00
```
2026-06-22 21:44:32 +02:00
Requires the `warden` CLI from `~/ops-warden` (`uv tool install .` or `uv run warden` ).
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
| Agent runtime | How to orient |
| --- | --- |
| **Codex / Grok** (shell, HTTP State Hub) | `warden route` commands above; inbox `to_agent=binect-js` is for coordination, not secret vending |
| **Claude Code** (MCP when available) | `get_domain_summary("custodian")` for workstreams; **still** use `warden route` for credential ownership |
| **llm-connect** (inference service) | Never put secret retrieval in prompts; route custody to OpenBao/operator paths surfaced by `warden route` |
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
### Quick routing table
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
| I need… | Owner | ops-warden executes? |
| --- | --- | --- |
| SSH cert (`adm` /`agt` /`atm` ) | ops-warden | **Yes** — `warden sign` |
| API key, DB password, provider token | OpenBao (`railiance-platform` ) | No — route only |
| Login / OIDC / MFA | key-cape / Keycloak | No — route only |
| Authorization decision | flex-auth | No — route only |
| activity-core → issue-core emission | activity-core + issue-core | No — `warden route show activity-core-issue-sink` |
| SSH tunnel | ops-bridge (+ `cert_command` from warden) | No — route only |
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
### Anti-patterns (do not do these)
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
- `POST /messages/` to `ops-warden` asking for `ISSUE_CORE_API_KEY` , `OPENROUTER_API_KEY` , etc.
- Inventing `warden secret` , `warden login` , `warden bao` , `warden tunnel` — they do not exist
- Pasting secrets into Git, State Hub, workplans, logs, or chat
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
### Other capabilities (reuse-surface)
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
Non-credential capabilities are usually discovered through **reuse-surface** federation
(`reuse-surface` registry / `capability.*` indexes). Credential routing is inlined in
every repo's agent instructions because it is high-frequency, high-risk, and easy to
get wrong.
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
**Canon:** `~/ops-warden/wiki/CredentialRouting.md` · catalog `~/ops-warden/registry/routing/catalog.yaml`
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
<!-- REPO - AGENTS - EXTENSIONS -->
<!-- Append repo - specific agent instructions below this marker.
The state-hub template sync preserves content after this line. -->
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
---
## Workplan Convention (ADR-001)
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
Work items originate as files in this repo — not in the hub. The hub is a
read/cache/index layer that rebuilds from files.
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
**File location:** `workplans/BINECT-WP-NNNN-<slug>.md`
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
**Archived location:** finished workplans may move to
`workplans/archived/YYMMDD-BINECT-WP-NNNN-<slug>.md` . The `YYMMDD` prefix is
the completion/archive date; the frontmatter `id` does not change.
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
**Ad Hoc Tasks:** small opportunistic fixes discovered during a session use
`workplans/ADHOC-YYYY-MM-DD.md` with task ids `ADHOC-YYYY-MM-DD-T01` , etc. Use
this only for low-risk work completed directly; create a normal workplan for
anything needing analysis, design, approval, dependencies, or multiple phases.
**Frontmatter:**
```yaml
---
id: BINECT-WP-NNNN
type: workplan
title: "..."
domain: communication
repo: binect-js
status: proposed | ready | active | blocked | backlog | finished | archived
owner: codex
topic_slug: ...
created: "YYYY-MM-DD"
updated: "YYYY-MM-DD"
state_hub_workstream_id: "< uuid > " # written by fix-consistency — do not edit
---
2026-01-14 23:16:38 +01:00
```
2026-06-22 21:44:32 +02:00
Use `proposed` for a new draft, `ready` after review against current repo
state, and `finished` after implementation. `stalled` and `needs_review` are
derived health labels, not frontmatter statuses.
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
**Task block format** (one per `##` section):
2026-01-14 23:16:38 +01:00
```
2026-06-22 21:44:32 +02:00
## Task Title
` ` `task
id: BINECT-WP-NNNN-T01
status: wait | todo | progress | done | cancel
priority: high | medium | low
state_hub_task_id: "< uuid > " # written by fix-consistency — do not edit
` ` `
Task description text.
```
Status progression: `todo` → `progress` → `done` ; use `wait` for waiting/blocked work and `cancel` for stopped work.
2026-01-14 23:16:38 +01:00
2026-06-22 21:44:32 +02:00
To create a new workplan:
1. Write the file following the format above
2. Notify the custodian operator to run `make fix-consistency REPO=binect-js`
(or send a message to the hub agent via `POST /messages/` )