internal/runner/`, also run `make e2e`.
5. Update `CHANGELOG.md` if the change is user-visible.
## Security considerations
- Credentials resolve in this priority order: CLI flag -> environment variable
-> `~/.skill-up/credentials.yaml`. Never
state until the result message arrives. This
matters most on machines running an endpoint security agent (e.g. CrowdStrike),
where every file open and process spawn carries a large fixed
they create real objects).
- The npm-bundled `esbuild` binary is blocked by Santa (endpoint security). Set `ESBUILD_BINARY_PATH` to the Homebrew-installed binary: `source scripts/prefer-system-esbuild.sh
times
- Memory usage matters for CI environments
- Network operations should be optimized and retryable
### Security Best Practices
- Handle authentication tokens securely
- Validate file paths to prevent directory traversal
- Consider impact
CI/CD Workflow Guidelines
## Security: Pin Actions by Commit Hash
**ALWAYS pin GitHub Actions to specific commit SHAs** instead of version tags for enhanced security. This prevents supply chain attacks where
project, append what agents need to execute
the beats there: commands & checks, hard invariants (security and
architecture rules), an environment quick reference, local test
infrastructure (stubs, fixtures), and anything that
when not applicable).
- All required checks (build, lint, robot) must be green before merge.
## Security & Configuration Tips
StackQL supports flexible configuration management, including authentication secrets and connection parameters, through environment
when changing exports or module dependencies.
- See `.github/workflows/ci.yml` for the complete CI sequence, including security-rule fixture tests and the real-PTY coordinator test. Ordinary test runs skip
defined in `toolsets.py`. A trust-boundary middleware (`security.py`) wraps every tool result in a security envelope to mitigate prompt injection via tool outputs.
The test suite has three layers:
- `tests/test_integrity.py
Gateway pattern through Azure API Management. It focuses on managing AI services APIs with security, reliability, performance, and cost controls. Labs use Jupyter notebooks with Python, Bicep templates, and Azure
privileges
on the backing table that ACTIVATION creates, so they are applied in the **`security` phase**, after
both the flow and the personas' roles exist — persona lookup there is **case
directory). Validator changes are not an exception; they must always ship with test coverage.
- **Secure process validation** — After changing Power Pages `child_process` usage, run `node scripts/validate-secure-process-execution.js` from the repository