tool's implementation differs from upstream, flag it as HIGH priority.**
## Code Review Guidelines
### Security
- All path parameters MUST use `encodePath()` from `src/utils/encode-path.ts`
- No hardcoded credentials or tokens
- Session cookies
Kars — Copilot Instructions
## What is Kars?
A secure AI agent runtime on Azure AKS. OpenClaw agents run in isolated K8s sandbox pods with E2E encrypted inter-agent communication (Signal Protocol
Copilot Secure Defaults for Java, Node.js, C#, and Python Projects
These instructions guide GitHub Copilot to suggest secure, intentional code patterns for Java, Node.js, C#, and Python development — especially
workflow and build commands
- Coding conventions and critical rules
- Guidelines for adding new features
- Security best practices
**Quick Reference - Critical Rules:**
- 🛑 **NEVER** use `console.log` - ALWAYS use `logger` from `src/outputLogger.ts
state`: Poll and wait until an entity reaches a specific spatial condition.
# Cryptographic Vault & Security (webcrypt-mcp)
This project provides native `webcrypt-mcp` tooling for zero-dependency
identify the reverted commit or PR; otherwise, flag a critical issue.
## Security Review (Mandatory for all PR reviews)
When reviewing a PR, these checks are **always blocking** — regardless
proper event subscription before triggering changes
5. Verify storage initialization in test environments
## Security Notes
- Never store sensitive data in todo items
- Validate input schemas strictly in language model tools
architecture summary
- Tests live under `tests/` and are organized by category (unit-, integration-, performance-, security-, validation-, mock-, interop-). See the `tests/` tree in `README.md`.
- Page Objects are in `tests/pages/` (example
never licenses
dropping a stage, a trust-boundary validation, data-loss prevention, security,
or accessibility. Non-trivial logic leaves one minimal runnable check behind.
## Stage Pipeline
Walk stages from
correct pages and sections
```markdown
For more information, see [Installation guide](/docs/install/README.md).
Refer to [Security settings](/docs/security/configuration.md#authentication) for details.
```
#### Link to specific sections
- **Use anchor links**: Link to specific
Human maintainer approval is the final commit boundary.
- Do not independently approve or merge security-sensitive,
governance-sensitive, release-sensitive, credential, external-effect, or
public-claim changes.
- Do not infer
land under one of the subsections: `Added`, `Changed`, `Fixed`, `Removed` (BREAKING), `Quality` (test/coverage/CI infra), `Security`. Pick the one closest to user impact, not internal scope.
- Format: a bullet opening with