Diff
1diff --git a/AGENTS.md b/AGENTS.md
2index f9f2fd9f34c35d6f4cb29256f659ce8c3f44b798..30ee8f8a9516588aab9777aa8f422dcc10d383a1 100644
3--- a/AGENTS.md
4+++ b/AGENTS.md
5@@ -6,7 +6,7 @@ This package provides a policy plugin for Pi. It combines host-specific precheck
6
7 ## Layout
8
9-- `src/core/` — shared Bash parsing, glob resolution, rules, deterministic checks, pipeline, reviewer, llama.cpp provider, cache, audit, normalization, and configuration.
10+- `src/core/` — shared Bash parsing, glob resolution, deterministic checks, pipeline, reviewer, llama.cpp provider, cache, audit, normalization, and configuration.
11 - `src/pi/` — Pi extension, static permissions, UI, and session Bash overrides.
12 - `test/core/`, `test/pi/` — unit and extension tests.
13
14@@ -28,14 +28,14 @@ Test only policy decisions: static permissions, deterministic rules, and LLM dec
15
16 ## Rules
17
18-`src/core/rules.ts` contains allowed commands and the LLM policy prompt. `src/core/deterministic.ts` applies policy to structured Bash.
19+`src/core/deterministic.ts` contains allowed commands and applies policy to structured Bash. `src/core/review.ts` contains the LLM policy prompt. `src/core/normalize.ts` contains `POLICY_VERSION`.
20
21 When changing deterministic patterns or matching behavior:
22
23 - Keep hard-allow rules anchored and strict.
24 - Keep config-allow rules protected from shell control syntax.
25 - Add or update tests.
26-- Bump `POLICY_VERSION` in `src/core/rules.ts` only immediately before committing rule changes, to invalidate cached LLM decisions.
27+- Bump `POLICY_VERSION` in `src/core/normalize.ts` only immediately before committing rule changes, to invalidate cached LLM decisions.
28
29 ## Commands
30