Jest.
- Maintain high test coverage and test edge cases and error paths explicitly.
### Security & Privacy Guidelines
- Never hardcode API keys, access tokens, or secrets in source code.
- Always validate external
access to Datalust Seq OpenTelemetry data.
## Priority Rules
1. Follow `.github/instructions/seq-mcp-server.instructions.md` first.
2. Apply security guidance from `.github/instructions/security-and-owasp.instructions.md`.
3. Apply container guidance from `.github/instructions/containerization-docker-best-practices.instructions.md`.
If rules conflict, the more specific
split one concern
into many separate line comments.
- Prioritize what matters: correctness, security, permission scoping, and violations of the
architecture invariants in `docs/conventions.md`. Lead with these.
## What to avoid
commercial dependency, research it — maintenance and health (active maintainers, release cadence, adoption, bus factor), security and supply chain (known vulnerabilities, install scripts, provenance), license, and transitive footprint — and prefer
Coverage targets: New code >80%, legacy after refactor >60%
- Test ViewModels/Presenters, never Views/Forms directly
## Security
- ServicePointManager.SecurityProtocol = Tls12
- Parameterized queries / EF6 only — zero SQL string concatenation
- AntiForgeryToken on all state-changing
Copilot Instructions
The full Oracle PL/SQL development, optimization, security and diagnostics
standards for this repository live in **[AGENTS.md](../AGENTS.md)** — the single
source of truth, read natively by both GitHub Copilot
import SubprocessToolRunner
runner = SubprocessToolRunner()
if runner.is_available("shellcheck"):
result = runner.run("shellcheck", ["-"], code=script_code)
```
- Security: allowlist of known tools (`KNOWN_TOOLS` mapping), no `shell=True`
- Supported tools are language-scoped
auditing whether an existing test can actually fail → `test-engineer`
- Quality gate before merge, security review, and adversarially verifying a claim this session made about its own work → `code-reviewer
auditing whether an existing test can actually fail → `test-engineer`
- Quality gate before merge, security review, and adversarially verifying a claim this session made about its own work → `code-reviewer
lock and rewrites only the key it was given.
→ `.ai-badger/invariants/never-hand-edit-the-git-dir.md`
- **Use platform security APIs** — Always use the platform's built-in security and crypto APIs.
→ `.ai-badger/invariants/no-hand-rolled-crypto.md
lock and rewrites only the key it was given.
→ `.ai-badger/invariants/never-hand-edit-the-git-dir.md`
- **Use platform security APIs** — Always use the platform's built-in security and crypto APIs.
→ `.ai-badger/invariants/no-hand-rolled-crypto.md