lint`, and `npm test`, then include the TAKT review summary when required by `CONTRIBUTING.md`.
## Security & Configuration Tips
Never commit API keys or tokens. Use `~/.takt/config.yaml`, project `.takt/config.yaml`, or environment variables
execution authority;
approve, reopen, or rebaseline a SpecSection; make a material
product/value/scope, public-promise, security, legal, privacy, finance,
irreversible-data, compatibility, or authority-allocation choice.
- If current Work would rely
Clearly link code changes back to the user story or requirement that motivated them.
---
## Security and Compliance
- Never commit secrets or credentials.
- Follow Azure security best practices: encrypted transport, least
approvals`.
- **Human attention comments**: After creating a PR with non-routine changes (architectural decisions, security, complex logic, deletions, low confidence), leave a `gh pr comment` highlighting where to focus review
bash` + canonical CLI surfaces. Start with `assistant config get` for generic config keys and secure credential surfaces (`assistant credentials`, `assistant keys`) for secrets. Do not use direct gateway `curl
chat.** API keys, tokens, passwords, and webhook secrets must be collected via a secure UI path — never pasted into the conversation where they enter the LLM context. Two approved paths
results, and screenshots for web changes. Note required env vars, migrations, or deployment steps.
## Security & Configuration Tips
Do not commit `.animegarden/`, `node_modules/`, `dist/`, build outputs, or local secrets
SAST Security Assessment
Your goal is to identify security vulnerabilities in the codebase located in the current directory.
---
## Step 1: Codebase Analysis & Threat Modeling
Before running, check if `sast/architecture.md` already
Bump cadence: every release cycle if upstream has shipped a notable fix; immediately on security advisories. Pin so the auth-status JSON shape Helmor parses doesn't drift unexpectedly.
- **Bundled
verifyOTPForSecureEmailChange
cd Tests/IntegrationTests
supabase stop
```
`verifyOTPForSecureEmailChange` needs `auth.email.enable_confirmations = true` to reach GoTrue's
secure-email-change "single confirmation" response, which every other integration test relies on
being `false
only source of truth; documentation drifts.
- Tenant isolation is a correctness and security requirement, never a trade-off.
- Wire contracts evolve backward-compatibly; breaking changes are explicit and `!`-marked.
- Code
Use Kingfisher with LLMs and AI agents. TOON output format for token-efficient scanning, prompt redaction, and structured output for automated workflows.