# Agent instructions thought stream is spec-driven. Read `spec/README.md` and the owning spec before changing runtime behavior. Rules: - Preserve append-only event semantics. Corrections are new events. - Keep connectors read-only unless a separate action capability is explicitly specified and authorized. - Never put credentials, raw auth headers, session cookies, or private keys in events, traces, fixtures, logs, or tests. - Preserve source provenance and idempotency keys through every derived event. - Agent output is untrusted until it validates against its declared output contract. - Every run must reach a visible terminal receipt or a recoverable nonterminal state. - Prefer small adapters around shared normalization and cursor contracts. - Do not couple Charter to thought stream internals. Integrate through versioned event contracts. - Do not commit or add a remote unless Cameron explicitly requests it.