text chat. Browser crash → auto-restart session. All errors are non-fatal and logged.
### Security Rules
- Never log PII (usernames, messages) in production — use `[REDACTED]`
- Sanitize all `page.evaluate` inputs
file. The brief will be submitted to external AIs — this is a non-negotiable security rule.
- **Two licenses coexist**: Apache 2.0 for code (skill, scripts, wrappers — `LICENSE-CODE
Automatic tagging of patched images with `-patched` suffix
- **Vulnerability Reporting**: Integration with Trivy for security scanning
## Key Functions and Components
- `NewServer()`: Creates MCP server instance with registered tools
- `Run()`: Starts
must begin with one of the following tags.
| Tag | Criteria | Comment Required |
|-----|----------|-----------------|
| `[MUST]` | Bugs, security vulnerabilities, data loss risk, runtime errors | **Always required** |
| `[SHOULD]` | Code quality issues, maintainability problems, performance
Project Codebase Guide for AI Agents
## 📋 Quick Links for Compliance & Security
When analyzing Project for security or compliance, refer to:
- **RGS Compliance**: [`.agents/skills/compliance-rgs/SKILL.md`](.agents/skills/compliance-rgs/SKILL.md) — 8-phase implementation framework with quick
written HashiCorp Sentinel policies for AWS Terraform that enforce ISO/IEC 27001:2013 Annex A security controls. The policies are consumed by HCP Terraform and Terraform Enterprise to validate infrastructure
responsible for
Thesmos is a deterministic governance engine — a fixed rule set covering security, auth, database, API, and framework-specific issues, checked the same way on every
Consulting Kit
## Agent Delegation Model
- **agent-dople**: Responsible for maintaining server integrity, security, and stability, and for running each server (`business-intelligence-mcp`, `api-integration-hub`, `content-automation
Copilot Code Review Instructions
Review this repository as a security-sensitive CLI plugin that delegates
read-only code review work from Codex to Claude Code.
- Prioritize correctness, security, release safety
just what's technically wrong today.
### SECURITYMODE
When I say SECURITYMODE, review as a security engineer doing a threat-focused audit. Look specifically for injection risks, auth/authz gaps, unsafe deserialization
Coding Instructions for GoBE Backend
## Project Overview
**GoBE** is a modular and secure HTTP backend server built with Go and Gin framework. The project emphasizes zero-configuration security, interface segregation
create temporary directories for intermediate processing, use `mktemp -d` to ensure a unique and secure temporary directory. For example:
```bash
temp_dir=$(mktemp -d)
# Use $temp_dir for your temporary