Data Structures, Design patterns, Functional programming, Parallel programming
You focus on elegance, maintainability, readability, security, "clean code", and best practices.
You always write the minimum amount of code to accomplish
test data directories
- Include edge cases: nested archives, encrypted files, malformed content, zip bombs
## Security Considerations
- The library includes protections against ZipSlip, Quines, and Zip Bombs
- Always validate file paths
required contract — `ManagedBy` may
> still be emitted as an optional deploy-provenance marker.
### Security baseline + AVM mandate
Non-negotiable: HTTPS-only, TLS 1.2 minimum, no public blob, Managed Identity
over
caller
before editing. Never simplify away input validation, error handling
that prevents data loss, security, or accessibility. Non-trivial logic
leaves one runnable check behind. A repo overrides these wholesale
bullets. explain/teach -- only when user says "why" or "explain".
Use normal English for: security warnings, destructive actions, user confusion, multi-step sequences. Resume terse after.
## Memory routing
Session start: call
generating suggestions:
1. Prefer incremental, minimal diffs; preserve existing style and naming.
2. Surface security, correctness, and data integrity issues before micro-optimizations.
3. Encourage type safety (no `any` unless
review priorities.
- Prefer focused, file/line-specific findings over broad style suggestions.
- Treat correctness, security, missing tests, governance-bypass, and stale spec/backlog/SSoT metadata as higher priority than formatting.
- Do not duplicate
Balance all five pillars** - Consider Cost Optimization, Operational Excellence, Performance Efficiency, Reliability, and Security together
4. **Justify decisions** - Explain WHY a service or pattern was chosen, including tradeoffs
5. **Link
termination condition. No pointer capture in closures without snapshot/sync.
## 3. Workspace path safety (critical: security boundary)
- Containment of workspace paths under `workspace.root` after absolute normalization; no escape symlinks.
- Issue identifiers
files, **always run `bash scripts/validate-ai-index.sh`** to confirm line numbers still point to correct headings.
### Security-Critical: Timing-Safe Comparison
All crypto verification code **must** use timing-safe comparison functions. Never
Azure AI integrations (Azure OpenAI, Azure AI Search, etc.), follow official SDK and security guidelines
7. Use configuration via `appsettings.json` and dependency injection for new .NET code
8. Keep code
test` after every change
## Code Quality
- Review across five axes: correctness, readability, architecture, security, performance
- Every PR must pass: lint, type check, tests, build
- No secrets in code or version
Commit messages: Follow the `Commit messages` rule in `AGENTS.md` (Conventional Commits, ` ( ): `, lowercase imperative summary).
- Security: Never suggest or commit secrets, API keys, or other personal data. Private dotfiles are managed
anti-detector
Stop: "stop unslop" or "normal mode"
Auto-Clarity: drop unslop style for security warnings, irreversible actions, legal/medical/financial precision, user confused. Resume after.
Boundaries: code/commits/PRs written normal. Never invent
primary targets)
- **AI integration** is a core feature - be mindful of Ollama API calls
- **Security**: Handle shell command execution carefully to prevent injection
- **Performance**: Keep the UI responsive; use async
This repo contains instruction files for using and conducting security reviews, do not confuse this `copilot-instructions.md` from other copilot-instructions files existing in this workspace.
For every change
tasks and avoid manual interventions.
- Write modular, reusable CI/CD pipelines.
- Use containerized applications with secure registries.
- Manage secrets using Azure Key Vault or other secret management solutions.
- Build resilient systems
MSTest.
- Use Moq or NSubstitute for mocking dependencies.
- Implement integration tests for API endpoints.
## Security
- Use Authentication and Authorization middleware.
- Implement JWT authentication for stateless API authentication.
- Use HTTPS
processing with @Async for non-blocking operations.
- Implement proper database indexing and query optimization.
## Security
- Implement Spring Security for authentication and authorization.
- Use proper password encoding (e.g., BCrypt).
- Implement CORS