For agents, on top of README.md, which they read first.
Notes for agents
Never run --remote without the user asking. It reads the deployed database with the deploy's credentials; the token stays inside the deploy's wrangler wrapper, and this tool must never read, print or pass it.
--remote is read-only by construction. It runs d1 list and d1 execute with SELECTs only, on a temporary copy of worker/. Don't reuse tools/deploy/resources.mjs's provision here: it creates a database that is missing.
Only validated literals reach the SQL. wrangler d1 execute takes no bound parameters, so the song id and hash are checked against their patterns before they are quoted in (literal). Keep every new input on that path.
The code hash must match the page's. currentHash hashes songCode(song.js, title), the same code the page plays and the recorder hashes. Change how the page builds a song's code only in website/src/jev/songCode.mjs.