Coding-agent glossary

44 terms, grouped by where they appear in DevFlow: 20 about the pipeline, 11 about models and cost, 8 about security and isolation, 4 about integrations and 1 about comparisons.

Pipeline and languages

  • Agent container

    An agent container is a throwaway Docker container that runs one call of a coding CLI; with DEVFLOW_AGENT_CONTAINER=on, DevFlow starts 1 per OpenCode invocation, with all Linux capabilities dropped.

  • Agent image

    An agent image is the Docker image that holds the toolchain for a coding agent and the build gates; DevFlow resolves it per repository in 3 steps, with a universal default.

  • Agentic delivery pipeline

    An agentic delivery pipeline hands a task through a fixed series of AI roles; in DevFlow that is planning, approval, a split into at most 8 subtasks, implementation, verification, a summary and a PR.

  • AGENTS.md

    AGENTS.md is a Markdown file in a repository that briefs AI tools on its conventions; DevFlow checks for it at step 2 of its pipeline and fails the task if it is missing.

  • AI coding agent

    An AI coding agent is a language model that reads a repository, runs tools and edits code by itself; DevFlow chains more than 20 such roles and stops any single run after 90 minutes.

  • Egress allowlist

    An egress allowlist is the list of network hosts an agent may connect to; for containerized runs, DevFlow enforces one in a proxy, with a per-run token that expires after 3 hours at the latest.

  • Git worktree

    A git worktree is an extra working directory that shares one repository; DevFlow creates 1 per task and keeps it for 168 hours, or 7 days, after the task is done.

  • Human in the loop

    Human in the loop means people approve key steps of an automated process; DevFlow keeps 2 such gates on every task, plan approval and mark-done, even with autopilot on.

  • Implementer

    The implementer is the role that edits code: it works through each of up to 8 subtasks inside the task's git worktree, with Bash, Read, Edit, Write and Glob as its 5 tools.

  • Landlock sandbox

    A Landlock sandbox uses the Linux kernel's Landlock module to limit which files a process can reach; DevFlow applies one to agent CLI runs, with write access in only 5 places.

  • Merge evidence report

    A merge evidence report is a structured record of the verification a task really went through, appended to every new DevFlow PR body under GitHub's 64 KB limit.

  • Plan approval

    Plan approval is the step where a person accepts, edits or rejects the AI proposal; in DevFlow no code is written and none of the up to 8 subtasks exists until it happens.

  • Planner

    The planner is the first AI role on a task: it reads the repository, asks clarifying questions in batches and writes a plan that you approve before any of up to 8 subtasks exist.

  • Container resource caps

    Container resource caps limit the memory, CPU and processes one container may use; DevFlow caps each test, build and agent container at 4 GB of memory, 4 CPUs and 512 processes by default.

  • Secrets encrypted at rest

    Secrets encrypted at rest are credentials stored in a database in encrypted form; DevFlow encrypts provider keys and GitHub tokens with AES-256-GCM under a 32-byte key.

  • Subtask

    A subtask is one unit of implementation cut from an approved plan; DevFlow's task creator produces at most 8 and rejects a larger split rather than truncate it.

  • Summarizer

    The summarizer writes the summary, PR description and changelog once verification ends, reading the whole branch diff when it is 512 KB or less.

  • Test commands

    Test commands are the build, lint and test lines stored for each repository; DevFlow's gates run nothing else, each in a non-root container capped at 4 CPUs by default.

  • Verification gate

    A verification gate is a check a change must pass before it moves on; DevFlow's gates run only the configured test commands, in containers capped at 4 CPUs and 4 GB.

  • Verifier

    The verifier checks implemented work: it runs only the repository's configured test commands and reviews the diff with an AI model, inlining branch diffs up to 512 KB.

Models and cost

  • Agent backend

    An agent backend is the command-line program that drives a model with tools inside a repository; DevFlow ships 2, OpenCode by default and Claude Code as an opt-in.

  • Agent invocation

    An agent invocation is one run of one pipeline role, such as the planner or the verifier; DevFlow gives each invocation its own process and a hard cap of 90 minutes.

  • Cache read share

    Cache read share is the part of a model's input served from the prompt cache; DevFlow's planned export pools it per model and role over a trailing 90-day window, from 0 to 1.

  • Cost per merged PR

    Cost per merged PR is the total agent spend of one task whose pull request was merged; DevFlow will publish the median per implementer model once 30 such tasks exist.

  • Median and p90

    The median is the value half of all runs fall below and p90 the value 90 percent fall below; DevFlow plans to publish both for spend per run, over a trailing 90-day window.

  • Model routing

    Model routing is choosing which model handles each step of an agent pipeline; DevFlow resolves it in 4 steps, from a per-task role override down to the workspace default.

  • Model tiers

    Model tiers are named slots, each holding a backend and a model, that agent roles draw from; DevFlow has 3 of them: fast, pro and max.

  • Prompt caching

    Prompt caching lets a model provider reuse an already processed prompt prefix instead of reading it again; DevFlow tracks it with 2 counters per run, cache reads and cache writes.

  • Reasoning effort

    Reasoning effort is a request setting that tells a thinking model how much to deliberate; DevFlow pins it to the maximum for 2 roles, planning and verification.

  • Monthly spend cap

    A monthly spend cap is a budget ceiling for agent runs; DevFlow checks it before every pipeline starts and applies a default of 100 USD to workspaces on managed inference.

  • Input and output tokens

    Input tokens are the text a model reads and output tokens the text it writes; DevFlow records both for every agent run, plus 2 cache counters kept apart from them.

Security and isolation

  • Security advisory IDs

    A security advisory ID is the stable name of one published vulnerability, such as a CVE or GHSA id; DevFlow keys each finding on it and plans to rank the top 10 per ecosystem.

  • cargo-audit

    cargo-audit checks the crates pinned in a Rust lockfile against the RustSec database; DevFlow runs it once per lockfile and turns each CVSS v3 vector into 1 of 5 severity buckets.

  • Dependency vulnerability scanning

    Dependency vulnerability scanning checks the package versions a project uses against published security advisories; DevFlow runs 6 scanners, one per ecosystem, chosen by the manifests a repository contains.

  • govulncheck

    govulncheck is the Go team's vulnerability checker for Go modules; DevFlow runs it on every changed repository with a root go.mod, bounded by a 300-second timeout.

  • osv-scanner

    osv-scanner matches dependency manifests against the open OSV vulnerability database; DevFlow uses it for Maven and Gradle projects, passing every pom.xml and Gradle lockfile in 1 call.

  • pip-audit

    pip-audit checks Python requirement files against published advisories; DevFlow passes it every requirements*.txt file it finds, in 1 call, and keeps one finding per package and advisory.

  • pnpm audit

    pnpm audit checks the resolved packages of a Node project against known security advisories; DevFlow runs it with --json when a package.json sits at the repository root, within a 300-second limit.

  • Vulnerability severity levels

    Severity levels rank how dangerous a vulnerability is; DevFlow normalizes every scanner's output to 5 buckets: critical, high, moderate, low and unknown.

Integrations

  • Attention item

    An attention item is an incoming signal, such as a new Sentry issue, waiting for triage; DevFlow polls for new issues every 2 minutes and can turn an analyzed item into a task in one click.

  • Bring your own key (BYOK)

    Bring your own key means AI agents bill your own provider account; DevFlow stores one key per workspace and provider, encrypted with AES-256-GCM, for 4 model providers.

  • Chat bridge

    A chat bridge connects a team chat to DevFlow so a mention can start a task and a thread reply can approve its plan; each workspace and author can send 15 events per minute.

  • MCP server

    An MCP server is a program that offers tools to AI agents through the Model Context Protocol; DevFlow runs one, the Figma server at version 0.13.2, for 2 agent roles.

Comparisons

  • Self-hosted

    Self-hosted means a platform runs on infrastructure you operate rather than a vendor's cloud.

FAQ

How are DevFlow glossary terms chosen?

Each DevFlow glossary entry names something you meet while running tasks in DevFlow: a pipeline role, a gate, a setting or an integration. Every glossary definition runs to at least 250 words and links three related entries.

Are DevFlow glossary definitions specific to DevFlow?

Each DevFlow glossary definition opens with the general meaning of the term, then says how DevFlow implements the term. The DevFlow details come from the product source code and its documentation, not from marketing copy.

How often are DevFlow glossary entries updated?

Each DevFlow glossary entry carries its own date, shown as the entry's last-modified date in the sitemap. A glossary entry is revised when the behaviour it describes changes in the code.