copilot-instructions.md — SecureVibe skills (minimal)
Generated by `secure-vibe dev regenerate` — edit `skills/`, not this file.
Use the local security skills when generating or reviewing
security-sensitive code in this GitHub
Core** — no modifications to SAP standard objects. Use BAdI / Enhancement Spot / CDS extension.
6. **Security** — AUTHORITY-CHECK on sensitive data. No hardcoded credentials.
7. **Korean context** — mask personal data (주민번호
PowerShell module (`Migrate2GSA/`) that converts third-party SSE/ZTNA exports into Entra
Global Secure Access configuration, plus vendor `Samples/`, design `Specs/`, and a Docusaurus
`website/`.
## Working here
- Put public cmdlets
still visible on github.com). Keep it excluded — planning notes aren't end-user documentation.
## Security Constraints
- **basic-ftp**: NEVER allow `basic-ftp` to regress below version **5.3.1**. Versions ≤ 5.2.2 have
PowerShell Copilot Instructions
## 🎯 Core Principles
You are assisting with enterprise PowerShell development that prioritizes security, maintainability, and performance.
Always follow these foundational principles:
1. **Security by Design**: Implement comprehensive input
different interfaces and commands:
- **FoD** (Fortify on Demand) — SaaS
- **On-premise / SSC** (Software Security Center) — self-hosted
Skills often need to branch based on which version the customer uses
Authentication**: Microsoft Entra ID integration for service-to-service auth
2. **Conditional Security**: Can be disabled for development environments
### Configuration Patterns
- **Development**: Authentication disabled for easier testing
- **Production**: JWT authentication
generating suggestions:
1. Prefer incremental, minimal diffs; preserve existing style and naming.
2. Surface security, correctness, and data integrity issues before micro-optimizations.
3. Encourage type safety (no `any` unless
modules
- Prefer shadcn/ui components from `src/components/ui/`
- Use `cn()` from `@/lib/utils` for conditional classes
## Security
### Never Generate
- Hardcoded API keys, tokens, or secrets
- `eval()` or `Function()` with dynamic input
- `dangerouslySetInnerHTML` with
integration: PDF generation from concatenated `slides/*.md`.
- JSON integration: `jq` for reading/updating `.lesson-config.json`.
## Security
- Before GitHub operations, run `./scripts/prepare-git.sh` to clear conflicting `GITHUB_TOKEN` and configure `gh` auth.
- Respect `.gitignore