The toolkit is the product. Daniel's complete workstation is one profile of the same components, so the groups below are separate.
Start at the project README. CONTRIBUTING.md states the change policy, and SECURITY.md states the security policy and the trust boundaries.
| Document | What it covers |
|---|---|
| components.md | The component contract, the installer, the profiles, and the public/local state boundary |
| platforms.md | The capability contract, the platform adapters, and what each support tier claims |
| environments.md | The development environment module, and the environments that exist today |
| not-tracked.md | What stays outside Git, and where each excluded thing lives instead |
| secrets.md | The credential policy, and the secret scanner that enforces it |
| agent-skills.md | The third-party skill packs, curated profiles, conflict rules, and installer commands |
| Agent skill setup | The issue tracker, triage labels, and domain docs used by the engineering skills |
| Document | Command |
|---|---|
| agentq.md | agentq, the GitHub backlog coordinator |
| ../packaging/agentq/README.md | The standalone agentq package and its agentbox dependency contract |
| sandcastle.md | agentbox, the unattended agent sandbox and its import boundary |
| agent-sandbox-profiles.md | agent-sandbox, the sandbox profiles, and how a repository selects one |
| repo-labels.md | repo-labels, the exact-sync GitHub label tool |
| repo-meta.md | repo-meta, the exact-sync GitHub About metadata and repository settings tool |
| python-dev.md | The python-dev environment and its toolchain |
| rust-dev.md | The rust-dev environment and its toolchain |
| dotnet-dev.md | The dotnet-dev environment and its toolchain |
| godot-dev.md | The godot-dev environment, the Godot engine and C# |
| windows-vm.md | winbox, the Windows virtual machine an agent drives over SSH |
devbox has no separate reference yet. The router is described in
architecture.md, and its environments in
environments.md.
These describe the complete personal workstation on Bazzite. Read them when you converge that machine, or when you want the reasoning behind a default. A reader who installs one component does not need them.
| Document | What it covers |
|---|---|
| architecture.md | The current machine: the host and container layers, the router, the agent configuration, and the trust boundary |
| recovery.md | The whole-machine path, from a fresh Bazzite installation to a verified workstation |
| bootstrap.md | The host and environment bootstrap scripts, and the libraries they share with the component installer |
| Document | What it covers |
|---|---|
| public-release-audit.md | The public-readiness audit, its findings, the GO decision, and the publication-gate command that re-checks it |
| naming.md | The repository-name evaluation, the decision, and what reopens it |