Thanks for helping. Small, focused PRs are easiest to review.
npm ci
npm run check # typecheck + tests + build
npx vitest run test/worker.test.ts # one fileNode 22.13+ (uses node:sqlite). No test sends a real message or needs Sendblue or Codex credentials.
src/domain/pure types and helperssrc/sendblue/transport: HTTP client, payload normalization, messaging portsrc/codex/the Codex SDK adapter, the managed instructions, the action envelope schemasrc/state/SQLite store (queue, threads, routines, metadata)src/ingest.ts,src/worker.ts,src/reconcile.ts,src/daemon.tsorchestrationsrc/http/,src/cli.ts,src/setup.ts,src/doctor.ts,src/service.tsedges
- Never commit credentials, real phone numbers, message content, SQLite files, logs, or downloaded media. Tests use
+1555…numbers. - Anything that changes what Codex is allowed to do, what the host validates, or who can reach the daemon needs a line in SECURITY.md and a test.
- Keep the managed instructions in
src/codex/prompt.tsgeneric. Personal tooling belongs in the operator's ownAGENTS.mdsection. - Add a CHANGELOG entry under Unreleased.