| Dimension | Shared | Only in A | Only in B | Overlap |
|---|---|---|---|---|
| Sections | 0 | 42 | 15 | 0% |
| Commands | 0 | 11 | 0 | 0% |
| Section tags | 3 | 8 | 2 | 23% |
What each file covers
Sections
0 shared · 42 only in A · 15 only in B- − Megarepo - AI Setup Repository
- − Repository Overview
- − Current Repository State
- − Working Effectively
- − Initial Repository Exploration
- − Always start by understanding the current repository state
- − When Source Code is Added
- − Check for package.json first
- − If package.json exists, install dependencies
- − NEVER CANCEL: npm install typically takes 2-5 minutes. Set timeout to 10+ minutes.
- − Common build commands (verify these exist in package.json first)
- − NEVER CANCEL: Build may take 5-45 minutes depending on project size. Set timeout to 60+ minutes.
- − Common test commands
- − NEVER CANCEL: Tests may take 5-15 minutes. Set timeout to 30+ minutes.
- − Common development server
- − Check for linting configuration
- − Run linting if configured
- − Run formatting if configured
- − Run type checking if TypeScript
- − Repository Structure Expectations
- − Validation Requirements
- − Before Making Changes
- − After Making Changes
- − Common Commands Reference
- − Repository Information
- − View current files
- − Check git status
- − View repository structure
- − When Package.json Exists
- − View available scripts
- − Install dependencies
- − TIMEOUT: 10+ minutes
- − Common development commands (check package.json first)
- − File Locations and Navigation
- − Current Key Files
- − Expected Important Locations (when populated)
- − AI Development Guidelines
- − Troubleshooting
- − Repository Appears Empty
- − Build Failures
- − Development Server Issues
- − Critical Reminders
- + Security Guidelines
- + API Key and Credential Management
- + Environment Variable Patterns
- + Required AI service keys
- + Optional service configurations
- + Security Best Practices
- + AI Service Security
- + Input Validation
- + Output Sanitization
- + Rate Limiting and Usage Control
- + Data Privacy and Compliance
- + User Data Handling
- + AI Service Data Policies
- + Error Handling Security
- + Production Security Checklist
Commands
0 shared · 11 only in A · 0 only in B- − git status
- − npm install
- − npm run build
- − npm test
- − npm run dev
- − npm run lint
- − npm run format
- − npm run type-check
- − npm run start
- − npm run test
- − git branch -a
Section tags
3 shared · 8 only in A · 2 only in B- − build
- − test
- − lint-format
- − architecture
- − types
- − git-pr
- − dependencies
- − agent-behaviour
- + code-style
- + api
- setup
- security
- do-not
Line diff
HerringtonDarkholme/megarepo · .github/copilot-instructions.md
@@ −1 @@
1# Megarepo - AI Setup Repository
2
3**ALWAYS follow these instructions first and only fallback to additional search and context gathering if the information here is incomplete or found to be in error.**
4
5## Repository Overview
6
7Megarepo is currently a minimal repository template designed for AI-related projects. The repository contains basic setup files and is configured for Node.js/Next.js development based on the .gitignore patterns.
8
9## Current Repository State
10
11**IMPORTANT**: This repository is currently in a minimal state with only basic setup files:
12- README.md (basic project description)
13- LICENSE (MIT license)
14- .gitignore (configured for Node.js/Next.js projects)
15
16**DO NOT attempt to build, test, or run code** - there is no source code or build system present yet.
17
18## Working Effectively
19
20### Initial Repository Exploration
21```bash
22# Always start by understanding the current repository state
23ls -la
24git status
25find . -type f -name "*.json" -o -name "*.js" -o -name "*.ts" -o -name "*.md"
26```
27
28### When Source Code is Added
29
30The repository is pre-configured for Node.js/Next.js development. When source code is added, follow these patterns:
31
32#### Node.js/Next.js Project Setup
33```bash
34# Check for package.json first
35ls package.json
36
37# If package.json exists, install dependencies
38npm install
39# NEVER CANCEL: npm install typically takes 2-5 minutes. Set timeout to 10+ minutes.
40
41# Common build commands (verify these exist in package.json first)
42npm run build
43# NEVER CANCEL: Build may take 5-45 minutes depending on project size. Set timeout to 60+ minutes.
44
45# Common test commands
46npm test
47# NEVER CANCEL: Tests may take 5-15 minutes. Set timeout to 30+ minutes.
48
49# Common development server
50npm run dev
51```
52
53#### Pre-commit Validation
54When source code exists, always run these before committing:
55```bash
56# Check for linting configuration
57ls .eslintrc* eslint.config.* .prettierrc*
58
59# Run linting if configured
60npm run lint
61
62# Run formatting if configured
63npm run format
64
65# Run type checking if TypeScript
66npm run type-check
67```
68
69## Repository Structure Expectations
70
71Based on the .gitignore configuration, expect the following when the repository is populated:
72
73```
74.
75├── README.md # Project documentation
76├── LICENSE # MIT license
77├── .gitignore # Node.js/Next.js ignore patterns
78├── package.json # Node.js dependencies and scripts
79├── package-lock.json # Dependency lockfile
80├── next.config.js # Next.js configuration (if Next.js)
81├── tsconfig.json # TypeScript configuration (if TypeScript)
82├── .eslintrc.* # ESLint configuration
83├── .prettierrc # Prettier configuration
84├── src/ # Source code directory
85│ ├── pages/ # Next.js pages (if Next.js)
86│ ├── components/ # React components
87│ └── utils/ # Utility functions
88├── public/ # Static assets
89├── .next/ # Next.js build output (ignored)
90├── build/ # Build output (ignored)
91└── node_modules/ # Dependencies (ignored)
92```
93
94## Validation Requirements
95
96### Before Making Changes
971. **Always check current repository state first**:
98 ```bash
99 git status
100 ls -la
101 cat package.json # Only if it exists
102 ```
103
1042. **Verify build system exists before attempting builds**:
105 ```bash
106 # Check for package.json before running npm commands
107 test -f package.json && echo "Node.js project detected" || echo "No package.json found"
108 ```
109
110### After Making Changes
1111. **When source code is present, always validate**:
112 ```bash
113 # Install dependencies if package.json exists
114 test -f package.json && npm install
115
116 # Build if build script exists
117 test -f package.json && npm run build
118
119 # Test if test script exists
120 test -f package.json && npm test
121
122 # Lint if lint script exists
123 test -f package.json && npm run lint
124 ```
125
1262. **Manual validation scenarios when application exists**:
127 - Start the development server and verify it loads
128 - Test basic functionality by navigating through the application
129 - Verify any API endpoints respond correctly
130 - Check console for errors
131
132## Common Commands Reference
133
134### Repository Information
135```bash
136# View current files
137ls -la
138
139# Check git status
140git status
141
142# View repository structure
143tree . -a -I 'node_modules|.git' # If tree is available (use -a to show hidden files)
144find . -type f -not -path "./.git/*" -not -path "./node_modules/*" | sort
145```
146
147### When Package.json Exists
148```bash
149# View available scripts
150cat package.json | grep -A 20 '"scripts"'
151
152# Install dependencies
153npm install
154# TIMEOUT: 10+ minutes
155
156# Common development commands (check package.json first)
157npm run dev # Development server
158npm run build # Production build
159npm run start # Start production server
160npm run test # Run tests
161npm run lint # Run linter
162npm run format # Format code
163```
164
165## File Locations and Navigation
166
167### Current Key Files
168- `/README.md` - Project overview and setup instructions
169- `/LICENSE` - MIT license terms
170- `/.gitignore` - Git ignore patterns (Node.js/Next.js focused)
171
172### Expected Important Locations (when populated)
173- `/src/` - Main source code directory
174- `/src/pages/` - Next.js pages (if Next.js project)
175- `/src/components/` - React components
176- `/public/` - Static assets and files
177- `/package.json` - Project configuration and dependencies
178- `/next.config.js` - Next.js configuration
179- `/tsconfig.json` - TypeScript configuration
180
181## AI Development Guidelines
182
183Since this is an AI setup repository:
184
1851. **Always verify AI-related dependencies** when they are added:
186 ```bash
187 # Common AI packages to look for
188 grep -E "(openai|langchain|tensorflow|pytorch|huggingface)" package.json
189 ```
190
1912. **Environment variables for AI services**:
192 ```bash
193 # Check for environment configuration
194 ls .env* || echo "No environment files found"
195 ```
196
1973. **API key management**:
198 - Never commit API keys
199 - Always use environment variables
200 - Check .env.example for required variables
201
202## Troubleshooting
203
204### Repository Appears Empty
205- This is expected in the current state
206- Check git branch: `git branch -a`
207- Look for other branches that might contain code
208
209### Build Failures
210- First verify package.json exists: `ls package.json`
211- Clear dependencies and reinstall: `rm -rf node_modules package-lock.json && npm install`
212- Check Node.js version compatibility in package.json
213
214### Development Server Issues
215- Verify port availability (typically 3000 for Next.js)
216- Check for environment variable requirements
217- Review console output for specific error messages
218
219## Critical Reminders
220
221- **NEVER CANCEL builds or long-running commands** - they may take 45+ minutes
222- **ALWAYS validate commands work** before assuming functionality exists
223- **CHECK for package.json** before running npm commands
224- **SET APPROPRIATE TIMEOUTS** - builds: 60+ minutes, tests: 30+ minutes
225- **VERIFY repository state** before attempting any operations
HerringtonDarkholme/megarepo · .clinerules/04-security.md
@@ +1 @@
1# Security Guidelines
2
3## API Key and Credential Management
4**CRITICAL**: Never commit sensitive data to version control.
5
6### Environment Variable Patterns
7```bash
8# Required AI service keys
9OPENAI_API_KEY=sk-...
10ANTHROPIC_API_KEY=sk-ant-...
11HUGGINGFACE_API_KEY=hf_...
12
13# Optional service configurations
14AI_MODEL_TEMPERATURE=0.7
15AI_MAX_TOKENS=2048
16AI_RATE_LIMIT_PER_HOUR=100
17```
18
19### Security Best Practices
20- Use `.env.local` for development secrets (never commit)
21- Create `.env.example` with dummy values to document required variables
22- Implement API key rotation strategies for production deployments
23- Use secure key management services (AWS Secrets Manager, Azure Key Vault, etc.)
24- Validate API keys on application startup and fail fast if missing
25
26## AI Service Security
27
28### Input Validation
29Always validate and sanitize inputs to AI services:
30```javascript
31// Validate prompt length and content
32function validatePrompt(prompt) {
33 if (!prompt || typeof prompt !== 'string') {
34 throw new Error('Invalid prompt: must be a non-empty string');
35 }
36
37 if (prompt.length > 10000) {
38 throw new Error('Prompt too long: maximum 10,000 characters');
39 }
40
41 // Remove potential injection attacks
42 const sanitized = prompt.replace(/[<>]/g, '');
43 return sanitized;
44}
45```
46
47### Output Sanitization
48Sanitize AI service responses before displaying to users:
49```javascript
50// Sanitize AI responses for display
51function sanitizeAIResponse(response) {
52 // Remove potential script injections
53 return response
54 .replace(/<script\b[^<]*(?:(?!<\/script>)<[^<]*)*<\/script>/gi, '')
55 .replace(/javascript:/gi, '')
56 .trim();
57}
58```
59
60### Rate Limiting and Usage Control
61Implement safeguards against API abuse:
62```javascript
63// Example rate limiting implementation
64const rateLimiter = new Map();
65
66function checkRateLimit(userId, maxRequests = 10, windowMs = 60000) {
67 const now = Date.now();
68 const userRequests = rateLimiter.get(userId) || [];
69
70 // Remove old requests outside the window
71 const validRequests = userRequests.filter(time => now - time < windowMs);
72
73 if (validRequests.length >= maxRequests) {
74 throw new Error('Rate limit exceeded');
75 }
76
77 validRequests.push(now);
78 rateLimiter.set(userId, validRequests);
79}
80```
81
82## Data Privacy and Compliance
83
84### User Data Handling
85- Never log sensitive user inputs or AI responses
86- Implement data retention policies for AI interactions
87- Consider GDPR and other privacy regulations
88- Provide user controls for data deletion
89
90### AI Service Data Policies
91- Understand data usage policies of each AI provider
92- Implement opt-out mechanisms for data training
93- Consider on-premise or private cloud AI solutions for sensitive data
94- Document data flow and processing for compliance audits
95
96## Error Handling Security
97Avoid exposing sensitive information in error messages:
98```javascript
99// Secure error handling
100try {
101 const response = await aiService.complete(prompt);
102 return response;
103} catch (error) {
104 // Log detailed error internally
105 console.error('AI service error:', error);
106
107 // Return generic error to user
108 throw new Error('AI service temporarily unavailable');
109}
110```
111
112## Production Security Checklist
113- [ ] All API keys stored in secure environment variables
114- [ ] Input validation implemented for all AI service calls
115- [ ] Output sanitization applied to AI responses
116- [ ] Rate limiting configured for API endpoints
117- [ ] Error messages don't expose sensitive information
118- [ ] Data retention policies documented and implemented
119- [ ] Security headers configured for web applications
120- [ ] HTTPS enforced for all AI service communications
@@ −1 +1 @@
1−# Megarepo - AI Setup Repository
1+# Security Guidelines
22
3−**ALWAYS follow these instructions first and only fallback to additional search and context gathering if the information here is incomplete or found to be in error.**
3+## API Key and Credential Management
4+**CRITICAL**: Never commit sensitive data to version control.
45
5−## Repository Overview
6−
7−Megarepo is currently a minimal repository template designed for AI-related projects. The repository contains basic setup files and is configured for Node.js/Next.js development based on the .gitignore patterns.
8−
9−## Current Repository State
10−
11−**IMPORTANT**: This repository is currently in a minimal state with only basic setup files:
12−- README.md (basic project description)
13−- LICENSE (MIT license)
14−- .gitignore (configured for Node.js/Next.js projects)
15−
16−**DO NOT attempt to build, test, or run code** - there is no source code or build system present yet.
17−
18−## Working Effectively
19−
20−### Initial Repository Exploration
6+### Environment Variable Patterns
217 ```bash
22−# Always start by understanding the current repository state
23−ls -la
24−git status
25−find . -type f -name "*.json" -o -name "*.js" -o -name "*.ts" -o -name "*.md"
8+# Required AI service keys
9+OPENAI_API_KEY=sk-...
10+ANTHROPIC_API_KEY=sk-ant-...
11+HUGGINGFACE_API_KEY=hf_...
12+
13+# Optional service configurations
14+AI_MODEL_TEMPERATURE=0.7
15+AI_MAX_TOKENS=2048
16+AI_RATE_LIMIT_PER_HOUR=100
2617 ```
2718
28−### When Source Code is Added
19+### Security Best Practices
20+- Use `.env.local` for development secrets (never commit)
21+- Create `.env.example` with dummy values to document required variables
22+- Implement API key rotation strategies for production deployments
23+- Use secure key management services (AWS Secrets Manager, Azure Key Vault, etc.)
24+- Validate API keys on application startup and fail fast if missing
2925
30−The repository is pre-configured for Node.js/Next.js development. When source code is added, follow these patterns:
26+## AI Service Security
3127
32−#### Node.js/Next.js Project Setup
33−```bash
34−# Check for package.json first
35−ls package.json
36−
37−# If package.json exists, install dependencies
38−npm install
39−# NEVER CANCEL: npm install typically takes 2-5 minutes. Set timeout to 10+ minutes.
40−
41−# Common build commands (verify these exist in package.json first)
42−npm run build
43−# NEVER CANCEL: Build may take 5-45 minutes depending on project size. Set timeout to 60+ minutes.
44−
45−# Common test commands
46−npm test
47−# NEVER CANCEL: Tests may take 5-15 minutes. Set timeout to 30+ minutes.
48−
49−# Common development server
50−npm run dev
28+### Input Validation
29+Always validate and sanitize inputs to AI services:
30+```javascript
31+// Validate prompt length and content
32+function validatePrompt(prompt) {
33+ if (!prompt || typeof prompt !== 'string') {
34+ throw new Error('Invalid prompt: must be a non-empty string');
35+ }
36+
37+ if (prompt.length > 10000) {
38+ throw new Error('Prompt too long: maximum 10,000 characters');
39+ }
40+
41+ // Remove potential injection attacks
42+ const sanitized = prompt.replace(/[<>]/g, '');
43+ return sanitized;
44+}
5145 ```
5246
53−#### Pre-commit Validation
54−When source code exists, always run these before committing:
55−```bash
56−# Check for linting configuration
57−ls .eslintrc* eslint.config.* .prettierrc*
58−
59−# Run linting if configured
60−npm run lint
61−
62−# Run formatting if configured
63−npm run format
64−
65−# Run type checking if TypeScript
66−npm run type-check
47+### Output Sanitization
48+Sanitize AI service responses before displaying to users:
49+```javascript
50+// Sanitize AI responses for display
51+function sanitizeAIResponse(response) {
52+ // Remove potential script injections
53+ return response
54+ .replace(/<script\b[^<]*(?:(?!<\/script>)<[^<]*)*<\/script>/gi, '')
55+ .replace(/javascript:/gi, '')
56+ .trim();
57+}
6758 ```
6859
69−## Repository Structure Expectations
60+### Rate Limiting and Usage Control
61+Implement safeguards against API abuse:
62+```javascript
63+// Example rate limiting implementation
64+const rateLimiter = new Map();
7065
71−Based on the .gitignore configuration, expect the following when the repository is populated:
72−
66+function checkRateLimit(userId, maxRequests = 10, windowMs = 60000) {
67+ const now = Date.now();
68+ const userRequests = rateLimiter.get(userId) || [];
69+
70+ // Remove old requests outside the window
71+ const validRequests = userRequests.filter(time => now - time < windowMs);
72+
73+ if (validRequests.length >= maxRequests) {
74+ throw new Error('Rate limit exceeded');
75+ }
76+
77+ validRequests.push(now);
78+ rateLimiter.set(userId, validRequests);
79+}
7380 ```
74−.
75−├── README.md # Project documentation
76−├── LICENSE # MIT license
77−├── .gitignore # Node.js/Next.js ignore patterns
78−├── package.json # Node.js dependencies and scripts
79−├── package-lock.json # Dependency lockfile
80−├── next.config.js # Next.js configuration (if Next.js)
81−├── tsconfig.json # TypeScript configuration (if TypeScript)
82−├── .eslintrc.* # ESLint configuration
83−├── .prettierrc # Prettier configuration
84−├── src/ # Source code directory
85−│ ├── pages/ # Next.js pages (if Next.js)
86−│ ├── components/ # React components
87−│ └── utils/ # Utility functions
88−├── public/ # Static assets
89−├── .next/ # Next.js build output (ignored)
90−├── build/ # Build output (ignored)
91−└── node_modules/ # Dependencies (ignored)
92−```
9381
94−## Validation Requirements
82+## Data Privacy and Compliance
9583
96−### Before Making Changes
97−1. **Always check current repository state first**:
98− ```bash
99− git status
100− ls -la
101− cat package.json # Only if it exists
102− ```
84+### User Data Handling
85+- Never log sensitive user inputs or AI responses
86+- Implement data retention policies for AI interactions
87+- Consider GDPR and other privacy regulations
88+- Provide user controls for data deletion
10389
104−2. **Verify build system exists before attempting builds**:
105− ```bash
106− # Check for package.json before running npm commands
107− test -f package.json && echo "Node.js project detected" || echo "No package.json found"
108− ```
90+### AI Service Data Policies
91+- Understand data usage policies of each AI provider
92+- Implement opt-out mechanisms for data training
93+- Consider on-premise or private cloud AI solutions for sensitive data
94+- Document data flow and processing for compliance audits
10995
110−### After Making Changes
111−1. **When source code is present, always validate**:
112− ```bash
113− # Install dependencies if package.json exists
114− test -f package.json && npm install
115−
116− # Build if build script exists
117− test -f package.json && npm run build
118−
119− # Test if test script exists
120− test -f package.json && npm test
121−
122− # Lint if lint script exists
123− test -f package.json && npm run lint
124− ```
125−
126−2. **Manual validation scenarios when application exists**:
127− - Start the development server and verify it loads
128− - Test basic functionality by navigating through the application
129− - Verify any API endpoints respond correctly
130− - Check console for errors
131−
132−## Common Commands Reference
133−
134−### Repository Information
135−```bash
136−# View current files
137−ls -la
138−
139−# Check git status
140−git status
141−
142−# View repository structure
143−tree . -a -I 'node_modules|.git' # If tree is available (use -a to show hidden files)
144−find . -type f -not -path "./.git/*" -not -path "./node_modules/*" | sort
96+## Error Handling Security
97+Avoid exposing sensitive information in error messages:
98+```javascript
99+// Secure error handling
100+try {
101+ const response = await aiService.complete(prompt);
102+ return response;
103+} catch (error) {
104+ // Log detailed error internally
105+ console.error('AI service error:', error);
106+
107+ // Return generic error to user
108+ throw new Error('AI service temporarily unavailable');
109+}
145110 ```
146111
147−### When Package.json Exists
148−```bash
149−# View available scripts
150−cat package.json | grep -A 20 '"scripts"'
151−
152−# Install dependencies
153−npm install
154−# TIMEOUT: 10+ minutes
155−
156−# Common development commands (check package.json first)
157−npm run dev # Development server
158−npm run build # Production build
159−npm run start # Start production server
160−npm run test # Run tests
161−npm run lint # Run linter
162−npm run format # Format code
163−```
164−
165−## File Locations and Navigation
166−
167−### Current Key Files
168−- `/README.md` - Project overview and setup instructions
169−- `/LICENSE` - MIT license terms
170−- `/.gitignore` - Git ignore patterns (Node.js/Next.js focused)
171−
172−### Expected Important Locations (when populated)
173−- `/src/` - Main source code directory
174−- `/src/pages/` - Next.js pages (if Next.js project)
175−- `/src/components/` - React components
176−- `/public/` - Static assets and files
177−- `/package.json` - Project configuration and dependencies
178−- `/next.config.js` - Next.js configuration
179−- `/tsconfig.json` - TypeScript configuration
180−
181−## AI Development Guidelines
182−
183−Since this is an AI setup repository:
184−
185−1. **Always verify AI-related dependencies** when they are added:
186− ```bash
187− # Common AI packages to look for
188− grep -E "(openai|langchain|tensorflow|pytorch|huggingface)" package.json
189− ```
190−
191−2. **Environment variables for AI services**:
192− ```bash
193− # Check for environment configuration
194− ls .env* || echo "No environment files found"
195− ```
196−
197−3. **API key management**:
198− - Never commit API keys
199− - Always use environment variables
200− - Check .env.example for required variables
201−
202−## Troubleshooting
203−
204−### Repository Appears Empty
205−- This is expected in the current state
206−- Check git branch: `git branch -a`
207−- Look for other branches that might contain code
208−
209−### Build Failures
210−- First verify package.json exists: `ls package.json`
211−- Clear dependencies and reinstall: `rm -rf node_modules package-lock.json && npm install`
212−- Check Node.js version compatibility in package.json
213−
214−### Development Server Issues
215−- Verify port availability (typically 3000 for Next.js)
216−- Check for environment variable requirements
217−- Review console output for specific error messages
218−
219−## Critical Reminders
220−
221−- **NEVER CANCEL builds or long-running commands** - they may take 45+ minutes
222−- **ALWAYS validate commands work** before assuming functionality exists
223−- **CHECK for package.json** before running npm commands
224−- **SET APPROPRIATE TIMEOUTS** - builds: 60+ minutes, tests: 30+ minutes
225−- **VERIFY repository state** before attempting any operations
112+## Production Security Checklist
113+- [ ] All API keys stored in secure environment variables
114+- [ ] Input validation implemented for all AI service calls
115+- [ ] Output sanitization applied to AI responses
116+- [ ] Rate limiting configured for API endpoints
117+- [ ] Error messages don't expose sensitive information
118+- [ ] Data retention policies documented and implemented
119+- [ ] Security headers configured for web applications
120+- [ ] HTTPS enforced for all AI service communications
