Chaos testing: Run `python3 scripts/chaos/chaos-test-clients.py` to validate behavior across all 9 MCP client types.
## Security and Internal Routes
- Keep SSRF protections and domain sanitization paths intact.
- Public traffic must
Azure Verified Modules](https://aka.ms/avm). Application and AI scenarios must identify the additional security, identity, reliability, and compliance work required before production use.
---
## 🏗️ Repository Structure
```
azure-scenario-hub/
├── .github
after the clear part is done. This is
not optional — safety beats token savings:
- Security warnings
- Irreversible action confirmations (delete, drop, force-push, overwrite, deploy)
- Multi-step sequences where fragment
import type { MyType } from './types.js'`
- File URLs: `fileURLToPath(import.meta.url)` and `dirname()`
### Path & Permission Handling
- **Security**: Use `isPathAllowed(path, allowedRoots)` from `src/utils/permission-checker.ts` before file operations
- **Async FS**: Always use `fs.promises
lint is allowed).
- **Error handling**: `anyhow::Result` for application errors, `thiserror` for typed errors.
- **Security**: Path components (org, repo, overlay names) are validated against traversal attacks. Repository URLs must
MODULE_##_###` format
- **Include What You Use (IWYU)**: Build pipeline includes header dependency validation
- **CodeQL**: Security analysis through c-build-tools pipeline integration
- **Cross-Platform**: Validation on both Windows and Linux
threshold
- Only leave a comment when you find a plausible behavioral defect, operational risk, security issue, data consistency issue, or maintainability issue with clear production impact.
- Prefer no comment over
user already has.
Code blocks, file paths, commands, error messages: always written in full.
Security warnings and destructive action confirmations: use full clarity
going to stderr is a bug, not a style nit.
### 2. Token storage security
`token_store.py` persists OAuth tokens at `~/.config/mcp-stdio/tokens.json`
(with legacy `~/.mcp-stdio/` migration on read):
- The store directory
github/skills/code-review/SKILL.md` in its
read-only review mode. Read `AGENTS.md` and the referenced product, architecture,
security, and evaluation contracts. Review the exact PR head against its actual
target branch, including draft
Prefer simple conditionals over nested ternary operators
- Group related code together and separate concerns
### Security
- Add `rel="noopener"` when using `target="_blank"` on links
- Avoid `dangerouslySetInnerHTML` unless absolutely necessary
right".
## On disagreement
Name the concrete cost of being wrong (data loss, security, silent failure, money).
Then stop. One clear reason beats three hedged ones.
## Receipts
When you finish