--- name: code-agent-contract description: Checklist of the platform contract every FindAgent CODE agent must meet (six entry tools, findagent.json v1.2, skills[] and example_prompts, default-deny egress, credential slots as declarations, autobuild safety for Node and Python, display-only MCP UI panel) plus the submit-flow traps already hit. Use when building, reviewing or debugging a code agent that will not build, serves no tools, or never unlocks Submit. --- # Code agent contract ## Contract 1. **Six entry tools**, all declared in `findagent.json` `skills[]` AND answered: `plan_inputs`, `open_form`, `run_form`, `run_full`, `list_capabilities`, `discover_intent`. A missing required argument answers `needs_input` naming the slot. The platform draws the form panel from the first three. 2. **`findagent.json` v1.2** at the repo root (a DXT `manifest.json` alone is read through an inferred contract that drops credential hosts): `schema_version "1.2"`, `kind "code-bundle"`, `name`, `entrypoint {path}`, `runtime {kind, version}` (node 22/24, python 3.13; Node 20 is not offered), `mcp {mode, command, args}`, `allowed_hosts[]` (top level in v1.2), `skills[]` (at most 40; id/name/description per tool, description at most 500 characters because the served tool list cuts there; each tool's typed `input_schema`), `example_prompts[]` (1-5), `serve` (`hosted` and/or `local`), `ui {path}`. 3. **Egress is default-deny.** `allowed_hosts` lists every host the code calls and nothing else. A host the caller chooses cannot be declared: take content as input instead. 4. **Credentials are declarations** (`credential_slots`: ref, label, `allowed_hosts` or `install_host`, `required`). A required slot not yet attached makes the gateway offer only `setup_credentials`, and a run with a required slot the buyer never saved is refused before the sandbox starts, for every tool; `required: false` keeps a tool usable without it. 5. **Autobuild**: the Node sandbox installs with npm (`npm ci` only for a committed `package-lock.json` / `npm-shrinkwrap.json`; `pnpm-lock.yaml` and `yarn.lock` are NOT read), so pin exact versions in `package.json`, use `npm run