name` and `description`. The agent ID is derived from the filename (e.g., `security-reviewer.agent.md` → `security-reviewer`).
**Session linking:** Sessions are linked to custom agents by matching `agent_type` values extracted from
identity
- Web dashboard to visualize results
- CLI for running benchmarks in CI/CD
---
## 🚨 HARD RULES
### Security
- ❌ **NEVER** commit secrets, API keys, or tokens to code or config files
- ✅ Use `.env` files
verification
7. **Check unused dependencies**: Use `#cargo-machete` to identify unused dependencies
8. **Verify security compliance**: Use `#cargo-deny-check` to ensure security and licensing compliance
### 3. Dependency Management
- When
load into `$Global:PesterOfflineTests.SdnApiResources`.
**Running:** Build the module first (`.\build.ps1`), then `.\tests\offline\RunTests.ps1`
## Security Best Practices
- Never log credentials or secrets
- Use SecureString for password parameters
- Validate user input
dist/
npm run dev # Development server with tsx hot-reload
make ci # Full pipeline: security, lint, test, build
```
### Testing Strategy
```bash
npm test # All tests with Vitest
npm run test
compiled files stay under `dist/` only; never commit generated artifacts outside `dist/` or `documents`.
- **Security**: never commit secrets or credentials; validate all inputs; follow principle of least privilege.
## Commit Messages
should be used when the code defines a public API, involves I/O, networking, or security-sensitive behavior, or contains sufficiently complex logic to warrant explanation.
All docstrings must follow Google
Treat `.github/actions/**`, `.github/hooks/hooks.json`, `.goat-flow/hooks/deny-dangerous.sh`, `.goat-flow/hooks/deny-dangerous/**`, `.github/skills/**`, `.github/copilot-instructions.md`, and `.copilotignore` as security-sensitive runtime surfaces; verify after touching them. `.github/agents/` remains out of scope unless a concrete
YourCommandWizardContext.ts # Wizard state interface
├── PromptXStep.ts # User input steps
├── ExecuteStep.ts # Final execution
└── yourCommand.ts # Main orchestration
```
## Security
- Never log passwords, tokens, or connection strings
- Use VS Code's secure storage for credentials
code without concurrency-specialist review
5. Do NOT handle credentials or encryption without swift-security-specialist review
6. Do NOT submit to App Store without app-review-guardian review
default: `http://localhost:3000`)
- `GAMES_DB_PATH` - SQLite database location (default: `./games.db`)
## Security Considerations
- Never hardcode credentials or API keys
- Validate all user inputs in API routes
- Sanitize game
list NOW.
[7] TYPE SAFETY -- No any (TS). Full type hints (Python)
[8] SECURITY FIRST -- OWASP Top 10. Validate inputs. Protect secrets
[9] ZERO VERBOSITY -- Every token = payload. No filler
target branch, then summarize the changes under clear categories (Added, Changed, Fixed, Removed).
## Security
- **Sensitive Data**: Use `flutter_secure_storage` for tokens and secrets. NEVER use `SharedPreferences` or source code