minor for enhancements, patch for fixes). Also update `.claude/rules/`, `.github/docs/copilot-reference.md`, and user-facing docs.
---
## Security
- **SQL**: always parameterized queries (`$1`, `$2`), never string interpolation
- **HTML sanitization**: use `htmlToText()` from `server/src/lib/death-sources/html-utils.ts
brig|swiss-kraken
Stop: "stop PirateBao" or "normal mode"
Auto-Clarity: drop PirateBao for security warnings, irreversible actions, user confused. Resume after.
Boundaries: code/commits/PRs written normal
formal full results.
Keep only the minimum protection required by a current security, data-loss, result-integrity, irreversible-action, or explicit requirement. Gates, hashes, Registries, audits, locks, migrations, fallbacks
tool, `msrc_search`, that queries the public MSRC CVRF v3 API (Microsoft Patch Tuesday security updates), enriched with FIRST.org EPSS scores and the CISA KEV catalog. No API keys anywhere
Authentication & Production Mode
- **Frontend**: Microsoft Entra ID via MSAL; access gated by Entra ID security groups configured through environment variables (no hardcoded group IDs).
- **Backend**: JWT bearer tokens validated against
Apps deployment; on Linux use pwsh deploy-to-azure.ps1 -BuildFirst [-DisableSage|-DeployToPreview].
## Security
- Only SELECT and WITH queries are permitted through CCFDatabase.executeQuery; never relax this constraint.
- Never store
readiness claims. Scope them by audience, environment, workload, and rollback posture, and report correctness, security, performance, operability, compatibility, and documentation evidence separately.
- For codec changes, start with `cargo test
vendor files or webfont assets for site behavior changes.
- Preserve the Microsoft contribution, trademark, security-reporting, and code-of-conduct language in the repository root documents.
## Track Changes
Always update
repository's standards
- Test coverage---are new paths tested and existing tests still passing?
- Security and dependency hygiene
## Review Workflow
- All code is authored and committed as `nathanjohnpayne`.
- Review under
GitHub Copilot Instructions - OWASP ASVS 5.0 Secure Coding Standards
You are an AI programming assistant that helps developers write secure code following OWASP Application Security Verification Standard (ASVS) 5.0 requirements