inline comments for non-obvious logic.
- For multi-step operations, break into named steps.
## Security
- Never complete patterns that include hardcoded secrets, passwords, or API keys.
- Flag SQL string interpolation
invocation: true` on commands** — required marker,
do not remove.
**What TO flag:** code defects, security issues, broken tests, type
errors, and any new `.agent-src.uncondensed/` substring introduced
into `dist/agent-src/rules/` body content
changes.
- Make special note of any changes to dependencies.
- Comment on the security of the changes being made and offer suggestions for further securing the code.
## Repository Organization
- `.github/` - GitHub
Naming:** The external name for this project is **ACES** (Agent Capability Evaluation Suite). **SABER** (Security Agent Benchmarking and Evaluation Research) is the internal Microsoft codename. The Python package, CLI commands
either contract, update that specification before dependent guidance. An explicit user requirement or stricter security policy wins for the requested change.
## Repository Purpose and Layout
This repository curates reusable GitHub
brute-force about: input validation at trust boundaries, error handling that prevents data loss, security, accessibility, or user requirements. Never rewrite what you don't yet understand: trace the unit
include details like logical name, schema name<, display name, description, object type code etc.
# Security Guidelines
- Do not show any sensitive information like Secret, Client/Application Id, Password, or Tenant
MD5/SHA1/SHA256-pur. Pepper im Secret-Manager, Salt automatisch.
2. **Setzt der Code Session-Cookies?** → `HttpOnly`, `Secure`, `SameSite=Lax` (Default) oder `Strict` (Admin). Session-IDs aus `crypto.randomBytes(32)`, nicht JWT in Cookie
writing code; the agent pipeline runs automatically via git hooks (Claude Code).
---
## Principles
1. **Security by default** — never trust external input; sanitize all user-supplied data before use; never hardcode
example code and knowledge-base Markdown. Only flag issues that would cause runtime failures, security vulnerabilities, or silently wrong behavior. Do NOT comment on style, naming, minor inconsistencies, missing docs
updates `VERSION` constant, `pyproject.toml`, creates git commit and tag.
## Project-Specific Patterns
### 1. Sanitization & Security
All user inputs MUST be sanitized via `sanitize_name()` which:
- Removes special characters except
dedicated Claude AI Panel. All panel summaries use the primary fallback chain above.
---
## Security Guidelines
- **Never commit secrets** — use `.env.local` or Vercel/GitHub environment variables
- **Secret scan is mandatory** — this
templates, provider/runtime precedence, active project context, and update safety are indexed from `AGENTS.md`. Scoped security and validation instructions live in `.github/instructions/`. Copilot has no native Flow lifecycle hooks in this