efficiency), input validation at trust boundaries, error handling that prevents data loss, security, accessibility, the calibration real hardware needs (the platform is never the spec ideal, a clock drifts
Threshold
Only comment when you are **>85% confident** the issue is a real bug, security vulnerability, or logic error. If you are unsure, do not comment. Silence is better than
Guidelines
When reviewing pull requests:
- Only comment on semantically meaningful issues: bugs, incorrect logic, security problems, or API contract violations.
- Skip style, formatting, naming, and whitespace observations unless they cause
text should be called out.
4. For user-facing, release, dependency, workflow, or security-sensitive changes, prefer blocking feedback over optional suggestions.
5. Focus on correctness, safety, and whether
full|wenyan-ultra
Stop: "stop caveman" or "normal mode"
Auto-Clarity: drop caveman for security warnings, irreversible actions, user confused. Resume after.
Boundaries: code/commits/PRs written normal
Lucide React (`lucide-react`). Do NOT add new icon packages.
- Static assets: `frontend/assets/images/`.
## Security
- No API keys/secrets in client-side code.
- Backend: parameterized queries only, never concatenate user input into
date by running generate-docs and checking git diff
4. **code-scanning.yml** - CodeQL security analysis for Go and GitHub Actions
5. **license-check.yml** - Runs `script/licenses-check` to validate compliance
6. **docker-publish.yml** - Publishes container
Copilot instructions for this repository
## Flag likely CVE / security-vulnerability fixes
Commits on `master` are automatically synced to the public `mongodb/mongo` repository. A security
fix that lands on `master` before
between builds when possible
- **Yarn Cache**: Dependencies are cached globally to speed up installs
## Security Notes
- Never commit secrets to source code
- Use environment variables for configuration
- Default admin token
integration tests for API endpoints
- Maintain test coverage above 70%
- Mock external dependencies appropriately
## Security Considerations
- Never commit secrets or API keys
- Use environment variables for configuration
- Implement proper authentication