focus stop rather than
a nested button. Enforced by `AUTOSDE.yaml` (`errors-use-error-notice`).
- **Security: every `dangerouslySetInnerHTML` goes through DOMPurify** via
`md()` / `sanitize()` / `esc()` in `src/api/helpers.ts`. A bypass
helper
(`fn_user_org_ids()`/`fn_user_role_in_org()`), a mesma função SECURITY DEFINER que o RBAC de
aplicação usa. Schema versionado em `supabase/migrations/`; o que o self-host
safety requirements.
- Do not call a project production-ready without current maintenance, licensing,
security, and adoption evidence.
- Do not use an LLM or web-search API to generate resource descriptions
check` or targeted commands), linked issue, and screenshots/logs when UI or operator workflow changes.
## Security & Configuration Tips
- Never commit secrets. Copy from `.env.example` and keep real values in local
overthinking!)
- if you are in a worktree, configure required environment variables securely
## SECRETS
- Never commit `.env` files, API keys, tokens, cookies, etc.
- Keep browser/client code limited to public or anon
fixes), `harness-setup` (how a pasted image reaches the model in each harness), `security` (recovered-image privacy, permissions passed to engines, untrusted image content), `testing`, `commit`, `research-gemini-claude-skills
Note:** The web terminal functionality is provided by the separate `tuios-web` binary for security isolation. See `cmd/tuios-web/` and [docs/WEB.md](docs/WEB.md) for details.
## Essential Commands
### Build & Run
```bash
# Build from
local `vite-plus` dependency (`pnpm vp …`), and hooks resolve it from `node_modules/.bin`.
## SECURITY
- **NEVER commit** Figma tokens, npm tokens, or API keys
- `.env` files are gitignored
- `wrangler.jsonc` contains Cloudflare
These are set via `vrSection` and `vrTitle` props on `ComponentExample.astro` in the docs site.
## SECURITY NOTES
- **URL validation**: all Browser Rendering targets must be `https://` and match the explicit Kumo
best practices. You prioritize:
- Clear, readable code with good documentation
- Test-driven development approaches
- Security-first design patterns
- Performance optimization where appropriate
When working on any task, always consider
model usage should follow Microsoft's Responsible AI principles:
- Fairness, reliability, safety
- Privacy and security
- Inclusiveness, transparency, accountability
- Use Azure AI Content Safety for production applications
- See `/md/01.Introduction/01/01.AISafety.md`
### Translations
model usage should follow Microsoft's Responsible AI principles:
- Fairness, reliability, safety
- Privacy and security
- Inclusiveness, transparency, accountability
- Use Azure AI Content Safety for production applications
- See `/md/01.Introduction/01/01.AISafety.md`
### Translations
model usage suppose follow Microsoft's Responsible AI principles:
- Fairness, reliability, safety
- Privacy and security
- Inclusiveness, transparency, accountability
- Use Azure AI Content Safety for production applications
- See `/md/01.Introduction/01/01.AISafety.md`
### Translations
model usage should follow Microsoft's Responsible AI principles:
- Fairness, reliability, safety
- Privacy and security
- Inclusiveness, transparency, accountability
- Use Azure AI Content Safety for production applications
- See `/md/01.Introduction/01/01.AISafety.md`
### Translations