instructions
This file applies to `.github/` and inherits the repository-wide rules in `/AGENTS.md`.
## Security boundary
Every workflow, ownership, branch-enforcement, release, or repository-automation
change requires explicit security review
provided by the current stack or a small local implementation.
- Dependency changes require explicit security review.
- Update `docs-site/` when dashboard behavior, setup, or configuration changes for users.
## Failure mode
Changes to release, packaging, dependency-installation, credential, or repository-automation scripts require explicit security review.
## Implementation rules
- Preserve Linux, macOS, and Windows behavior. Do not add shell-specific assumptions
relevant to that adapter.
- Authentication, OAuth, token, credential, management API, and CORS changes are security-boundary changes.
## Tests and validation
- Place focused regression coverage near the existing tests
devlog/`.
- Superseded or alternative reasoning belongs in `decisions/`, not in the doc body.
- Unreleased security findings belong in scratch space and nowhere in this repository. The rule in
the root
touches the plugin
SDK boundary, HCL2 template parsing, the command surface, CI/release workflows,
or security-relevant behavior.
- Proceed without another confirmation when the user explicitly asks to implement
retire an externally reachable plugin or compatibility contract.
- Preserve coverage for distinct protocol, platform, security, lifecycle, persistence, and compatibility failures. Consolidation must retain assertions that distinguish those failures. Small tests
FastMCP server
skill-seekers-mcp
# Or use the Python module
python -m skill_seekers.mcp.server_fastmcp
```
## Security Considerations
- **API Keys:** Never commit API keys to version control. Use environment variables
digests over the reuse scope and the token sequence.
They are a security boundary for cross-request reuse. Do not replace,
truncate, or use a non-cryptographic hash unless prefix
Agent surfaces.
- Prioritize findings that can cause data loss, project corruption, crashes, hangs, races, security or privacy exposure, incorrect edits, broken undo, or misleading success. Then consider performance, maintainability
specific credential (e.g., ManagedIdentityCredential) to avoid
// latency issues, unintended credential probing, and potential security risks from fallback mechanisms.
AIAgent agent = new AIProjectClient(new Uri(endpoint), new DefaultAzureCredential())
.AsAIAgent(model: model
bash
# Run with auto-discovery
devui ./agents
# Run with specific entities
devui --entities my_agent.py
```
## Security Posture
DevUI is a development-only sample app, not a production hosting surface. Authentication
factory methods instead
- No `Token` type in props
- `SecretValue` type for any password/secret/token properties
## Security Rules
- SHOULD prefer specific IAM actions over full-service wildcards (`s3:*`), but suffix wildcards
services and endpoints, detecting uptime/downtime |
| `auditbeat` | Gathers audit data from systems to track security events, user activities, and compliance requirements |
| `packetbeat` | Analyzes network traffic by capturing and inspecting packets
Install GitHub CLI: `brew install gh` (macOS) or visit https://cli.github.com for other platforms.
## Security & Configuration Tips
Store API keys and provider URLs in `.env` or your MCP client config
checker and effective budget come from main, not the PR. Keep default CODEOWNERS.
## Security and lifecycle correctness
- Never commit API keys, tokens, private keys, `.env` files, customer data, or other
release`](.claude/skills/release/SKILL.md) | Cutting a release: bump on `v2/main`, milestone merge, tag `origin/main`, publish | `/release` |
| [`security-advisory`](.claude/skills/security-advisory/SKILL.md) | A privately reported vulnerability end to end: the draft card, who owns
Keep it simple
Codex Security is a thin wrapper around Codex and its security plugin.
- Trust local tools and processes running as the current user.
- Treat repository contents, model output