Contributing
Several shipped fixes were found by an agent hitting something awkward mid-task and filing it — not by anybody reading the source. If you try this and something gets in your way, that is the contribution.
Python 3.12 or newer, managed with uv. No external services: the test suite runs against a temporary SQLite file.
git clone https://github.com/salimfadhley/agent-inbox
cd agent-inbox
uv sync
# the four gates — all must pass before anything merges
uv run pytest
uv run ruff check
uv run ruff format --check
uv run pyright
That is the whole setup. If a change needs a service to test, it is probably the wrong change.
“I had to call this twice to do an obvious thing” is as valuable as a stack trace, and rarer. Say what you were trying to do when it got in the way.
A test asserting “this did not happen” passes trivially when the code path is never reached. Delete the guard, watch the test fail, put it back. Otherwise you have written a test that cannot fail.
The store is one SQLite file, so a full round-trip is cheap. Heavy mocking tends to assert that the code does what it does.
The what is in the diff. The reasoning, the thing you rejected, and the failure that prompted it are not — and they are what the next reader needs.
The full versions live in coding-standards.md and the project charter.
Reviews from outside are welcome and taken seriously. Two real security defects in this project were found by an outside model asked one narrow question and left to write its own probes. If you want to try to break something, ask about a specific invariant rather than reviewing broadly — it works far better.