sacrifice grammar for brevity. Every comment MUST include an importance level prefix:
- **[CRITICAL]** — Bugs, security issues, data loss. Must fix.
- **[HIGH]** — Correctness, perf, or maintainability problems. Should fix.
- **[NIT]** — Style
evidence. Never copy a static provider count into product guidance.
- Verify product, plan, provider, security, and deployment claims against the
current code or an official source before publishing them
bullets. explain/teach -- only when user says "why" or "explain".
Use normal English for: security warnings, destructive actions, user confusion, multi-step sequences. Resume terse after.
## Memory routing
Session start: call
Authentication code is in `pkg/sqlcmd/azure_auth.go`
- Supports multiple authentication methods: DefaultAzureCredential, Password, Interactive, ManagedIdentity, ServicePrincipal
## Security Considerations
- Never commit secrets or credentials
- Use environment variables or secure credential stores for sensitive
guidelines are defined in [`AGENTS.md`](../AGENTS.md).
Additional references:
- REST API design: https://wso2.com/whitepapers/wso2-rest-apis-design-guidelines/
- Secure coding: https://security.docs.wso2.com/en/latest/security-guidelines/secure-engineering-guidelines/secure-coding-guidlines/general-recommendations-for-secure-coding/
- Documentation guidelines: [`docs/AGENTS.md`](../docs/AGENTS.md
Never minimal about:** input validation at trust boundaries, error handling
that prevents data loss, security, accessibility, anything explicitly requested.
Always on once installed. Deactivate: "stop chisle" / "normal mode
short form; `AGENTS.md` is
the source of truth.
## Priorities
Review for correctness, security, and backward compatibility, in that order. Focus on
architecture, logic bugs, and failure modes. Reason about
secrets.
- Provide actionable error messages (context via anyhow::Context), and map OS/IO errors precisely.
## Security & compliance
- No plaintext secrets, keys, or tokens in code or tests.
- Default to Rustls
modules with explicit paths: `Join-Path $PSScriptRoot` pattern.
- Use `-Force -DisableNameChecking` for re-imports.
## Security Patterns
### Secret Handling
- Mask secrets with `Write-Host "::add-mask::$secret"` before any output.
- Never
Standards
These standards apply to all Copilot interactions including code generation and PR review.
## Security
- Never hardcode secrets, tokens, API keys, or connection strings — use environment variables or a vault
integration cases (VARBINARY, UNIQUEIDENTIFIER, XML, DECIMAL, stored-proc params) before applying the optimization broadly.
## Security and credentials
- **Committed connection strings that contain `UID`/`PWD` must use `SERVER=localhost
clearly-labeled scaffolding
test and a TODO explaining the required wiring (project reference / InternalsVisibleTo).
## Security requirements (Microsoft SDL — always build in this spirit)
- **No injection.** Never build SQL, shell
selective. Only leave comments for issues that genuinely matter:
- Bugs, logic errors, or security concerns
- Unclear code that would benefit from refactoring for readability
- Violations of the critical coding conventions