current branch compared to main. Provide structured feedback on correctness, design, performance, security, and test coverage.
### /github - GitHub CLI Reference
Use the `gh` CLI to interact with GitHub. Always specify
policy languages via
`src/languages/`. It is used in **production at scale** where **correctness is
security-critical** — a bug in policy evaluation can mean `allow` when the
answer should be `deny
production without it doing something expensive, irreversible, or embarrassing."*
- **Secondary: governance / compliance / security stakeholders.** They rarely write code but need to audit agent behavior, approve risky actions, and produce evidence
examples for clarity
- Addresses thread safety with NSManagedObjectID
- Considers performance implications
5. **Security Considerations**
- Scripts should be reviewed for security implications
- External dependencies should be clearly documented
- No malicious patterns
architecture.md`, then realign tasks and implementation before continuing.
- If the user requests quality or security remediation, first fix the issues, rerun quality gate plus `super-dev release proof-pack
local)
- Clear feature list highlighting AI capabilities
- CI/CD pipeline setup guidance using azd commands
**Security Recommended Practices:**
- Use keyless authentication (Managed Identity preferred or Key Vault) instead of API keys
newest first)
- Each entry includes version number, date, and a bulleted list of changes
## Security
- Report vulnerabilities through MSRC (https://msrc.microsoft.com/create-report), never via public issues
- Never commit secrets, connection
over new abstractions; watch for missing effect cleanup and stale
closures over socket state.
- Security: the server runs locally by default but can bind to a non-loopback
address
size
- Copy only necessary files (use .dockerignore)
- Set PYTHONUNBUFFERED=1 for proper log streaming
### Security Practices
- Never hardcode secrets or credentials
- Support multiple authentication methods (managed identity, service principal
GitHub Copilot Repository Instructions
For packet capture, protocol analysis, network security monitoring, incident response, and troubleshooting tasks, prefer the canonical project skill in `skills/wireshark-traffic-analysis/`.
Use the skill to:
- start with
Trusted Research Environments on Azure. It enables authorized users to deploy and configure secure workspaces and researcher tooling without a dependency on IT teams.
Trusted Research Environments (TREs) enable organizations
servers and TypeScript utilities (`utils/`).
- `scripts/`: TypeScript and shell utility scripts for setup, security, and documentation.
- `.mcp.json`: Project-scoped MCP servers the CLI reads on startup (`microsoft-learn`, `oreilly-july20