memory bank", refresh `activeContext.md` & `progress.md`
- 🏗️ For new features, create spec first in `memory-bank/`
## 🔒 Security & Code Quality
- 🔐 Never commit API keys, `.env`, or credentials
- ✅ Run `npm run lint
handling.
- SSH credential provisioning with auto-detect (Key Vault MSI or local workspace files).
### Security
- Least privilege: non-root Docker user (`appuser:1000`).
- No plaintext secrets: Azure Key Vault integration
actual content
- **Data classification:** All contract data is Confidential. Treat accordingly.
### Security
- Input validation on all user queries (max 2000 chars, sanitize)
- No raw string interpolation in Cypher queries
state`: Poll and wait until an entity reaches a specific spatial condition.
# Cryptographic Vault & Security (webcrypt-mcp)
This project provides native `webcrypt-mcp` tooling for zero-dependency
Copilot Instructions
Prefer minimal, tested, secure changes that follow the project docs and task files.
## Maintenance Note
This file is hand-maintained. `ackit generate` does not regenerate it. Update
state`: Poll and wait until an entity reaches a specific spatial condition.
# Cryptographic Vault & Security (webcrypt-mcp)
This project provides native `webcrypt-mcp` tooling for zero-dependency
needs_replan` — Architecture mismatch or missing dependency; delegate to Planner for targeted replan.
- `escalate` — Security vulnerability, data integrity risk, or unresolvable blocker; stop and await human approval.
- `model_unavailable
changed behavior, or tests weakened to pass
- concurrency, lifecycle, cancellation, or shared-state hazards
- security-sensitive input, output, storage, logging, and permissions
Avoid language-specific rules in this file unless
param above arrives from a URL a stranger may have edited, and two real security bugs have already come from treating them as trusted. Validate at the boundary in `parseURLParams