Files
composiohq__composio/ts/AGENTS.md
T
Alberto Schiabel 022ecf6176 docs(agents): require zod and effect/Schema at data boundaries (#3969)
This PR:

- codifies the schema-parsing convention in agent guidance: parse
untyped/external data once at the boundary with zod (`z.infer`
downstream) in the docs site and SDK packages, and with `effect/Schema`
in the CLI
- bans hand-rolled structural guards (`'x' in obj` / `typeof` chains),
`as`-casts of parsed JSON, and fake validators such as `z.custom(() =>
true)`
- updates `docs/AGENTS.md`, `ts/AGENTS.md`,
`ts/packages/core/AGENTS.md`, and the existing trust-boundary rule in
`ts/packages/cli/AGENTS.md`

## Context

Follow-up to the review feedback that led to the #3958 split (#3966 /
#3967 / #3968): the docs type-safety work initially shipped a suite of
conditional structural utility helpers instead of zod schemas. This
records the convention so agents and contributors reach for schemas by
default.
2026-07-28 18:44:01 +05:30

1.6 KiB

AGENTS.md

TypeScript workspace guidance for AI agents.

Scope

ts/ contains the TypeScript SDK packages, examples, CLI, and runtime E2E tests.

Skill Routing

  • Use typescript-sdk for @composio/core, shared TypeScript package behavior, generated SDK surfaces, and modifiers.
  • Use typescript-providers for packages under ts/packages/providers/.
  • Use typescript-testing for Vitest, typecheck, package builds, examples, or runtime E2E test selection.
  • Use cli-command or cli-e2e for ts/packages/cli/ and ts/e2e-tests/cli/.
  • Use cli-release for first-party CLI beta builds, stable promotion, release verification, or recovery.

Commands

Run from the repository root:

pnpm build:packages
pnpm typecheck
pnpm lint:packages
pnpm test
pnpm test:e2e:node
pnpm test:e2e:deno
pnpm test:e2e:cloudflare
pnpm test:e2e:cli

Rules

  • Do not edit ts/vendor/; those submodules are read-only references.
  • Keep generated outputs owned by their generator.
  • Add changesets only for changes to published TypeScript packages.
  • Never add changesets for @composio/cli or @composio/cli-local-tools while .changeset/config.json ignores them; record CLI notes in ts/packages/cli/CHANGELOG.md instead.
  • Prefer focused package tests before broad workspace tests.
  • Parse untyped or external data (API payloads, JSON, unknown) at the boundary with schemas and let inferred types flow downstream: zod in SDK packages (@composio/core, providers, shared packages), effect/Schema in ts/packages/cli/. Never hand-roll structural guards ('x' in obj / typeof chains) or cast parsed JSON with as.