| # Agent guidance |
| |
| This file is read by automated agents (security scanners, code |
| analyzers, AI assistants) operating on this repository. It |
| points them at the human-authored references they should |
| consult before producing output. |
| |
| ## Security |
| |
| Security model: [SECURITY.md](./SECURITY.md), which links to |
| the canonical model document at |
| <https://tomcat.apache.org/security-model.html>. |
| |
| Agents that scan this repository should consult the linked |
| security model for the project's threat model, in-scope / |
| out-of-scope declarations, and known non-findings before |
| reporting issues. |