4237f03a834eb3c1b533bf2758ebc68dc67cb362
Quick orientation: layout, hard rules (native tools stay disabled, sanitize+wrap, no secrets, two trees in sync, firewall is part of the threat model, deer-flow is vendored), where things run on data-nuc, commit style, a one-page verification block, and the common NixOS / docker / pip footguns to avoid.
Description
Hardened DeerFlow deployment with prompt-injection-proof web search/fetch (SearX + sanitizer + content delimiters)
Languages
Python
68.3%
TypeScript
19.4%
HTML
4.8%
Shell
2.4%
CSS
2.2%
Other
2.9%