## Environment - No passwordless root. There is no stored root password — if something needs `sudo`, ask me and I will run it or type the password myself. - Ask before installing system packages. Project-local dependencies are fine. - This is a personal workstation, not a sandbox: treat destructive or outward-facing actions as needing confirmation, and prefer reversible steps. - Dev servers may bind localhost; nothing needs to be reachable from the LAN unless I say so.