src/index.ts`**: The main application entry point. It initializes the Express app, sets up middleware (security, logging), and instantiates the `MCPServer`.
- **`src/mcp/MCPServer.ts`**: The core of the application. It manages different transport
approved MCP servers (Go)
All applications deployed on NAIS platform with environment-specific configurations.
**Security architecture:** See [SECURITY.md](../../SECURITY.md) for trust zones, auth flow, and secret isolation.
---
# Nav Development Standards
every new component/logic
- Architecture: Next.js App Router, Server Actions, React Server Components when possible
- Security: Never commit secrets, use environment variables
### Python
- Type hints on all function signatures
- Formatting: Black
ClipboardItem({
'image/png': blob
})
]);
```
- Uses Clipboard API with `ClipboardItem`
- Requires HTTPS or localhost (browser security)
- Works in Chrome/Edge, Firefox
- Safari support limited (requires user permission)
3. **`handleTwitterShare()` - Open Twitter Intent**:
```typescript
build + MCPB upload on release
- **Testing**: Jest with `ts-jest`
## Priority Areas (Review These)
### Security
- Credentials must NEVER be logged, even at debug level — check `logger.debug()` calls for leaked
production pipelines. Your single
objective is to find every issue that could degrade correctness,
security, throughput, availability, observability, or maintainability
**before it hits production** — and to leave reviews that
line and follow conventional commits.
- New code never uses Math.random for anything security-adjacent: use
crypto.randomInt (SonarCloud S2245 gates the merge).
- Binaries invoked from scripts are resolved from fixed paths
/README.md) for full project context.
## Project Overview
NuGuard is an open-source AI application security CLI. It generates AI-focused SBOMs from source code, runs static security analysis, validates cognitive
Follow the principle of least privilege for permissions
- Implement optional permissions where possible
## Security and Privacy
- Implement Content Security Policy (CSP) in manifest.json
- Use HTTPS for all network requests
- Sanitize
repository root is the authoritative guide** for working in this
codebase: architecture, conventions, testing, security, configuration and the project's hard-won
rules. Read it before suggesting changes.
This file
implementing, reviewing, or auditing platform infrastructure as a system — where Kubernetes, GitOps, CI/CD, and security concerns intersect. Apply these patterns when generating or reviewing code across Kubernetes, Flux CD, Argo