code-review-for-pms** — Review AI-generated code from a PM perspective: spec compliance, security, UX issues. Use when reviewing code against product requirements.
- **debug-with-ai** — Guide PMs through
evidence, and exact Git state over summaries or stale documentation.
5. Preserve fail-closed security behavior unless an explicitly approved contract changes it.
6. Do not add domain or business
creating a new one.
- Exception: Proactively maintain this `.github/copilot-instructions.md` file (see “Meta instructions”).
## Security guidelines
Important: Security policy
- Assist with defensive security tasks only.
- Refuse to create, modify, or improve
here is incomplete or found to be incorrect.
## Project Overview
Kompli is a Linux security compliance engine derived from Azure OSConfig. The repository keeps the ComplianceEngine module and the direct
ultra.
- NO group generalizations (gender, race, sexuality, disability).
- Auto-clarity: drop persona for security warnings, destructive ops (DROP TABLE, force push, rm -rf), user confusion, legal/compliance. Resume after.
Stop: "stop
Copilot review instructions
Repo-wide guidance for automated code review. Prioritize correctness and
security over style. Be specific and actionable; cite the file and line.
## GitHub Actions — credential & secret safety
user approval after completing a logical boundary before moving to the next.
6. **Security Paranoia:** Always assume external inputs are malicious. Inherently apply Defensive Programming reflexes without needing
error handling that lets a real failure pass silently or crash — not stylistic preference.
- Security: injection, unsafe deserialization, authz gaps, secrets in code or logs, unvalidated untrusted input.
- Test coverage
Naming:** The external name for this project is **ACES** (Agent Capability Evaluation Suite). **SABER** (Security Agent Benchmarking and Evaluation Research) is the internal Microsoft codename. The Python package, CLI commands
signing entitlements. It provides both one-time scanning and real-time monitoring capabilities for security analysis and compliance verification. Now includes background daemon mode for continuous system monitoring.
## Current Architecture
decide. Project rules govern what the code looks like. Both apply.
**Precedence.** Security, privacy, and explicitly required behavior override rules 2, 3, and 5. None of those three is ever