Skip to content

Add security guidelines to AGENTS.md#5146

Merged
fisx merged 4 commits intodevelopfrom
fisx/agents-md
Mar 23, 2026
Merged

Add security guidelines to AGENTS.md#5146
fisx merged 4 commits intodevelopfrom
fisx/agents-md

Conversation

@fisx
Copy link
Contributor

@fisx fisx commented Mar 23, 2026

source: https://wearezeta.atlassian.net/wiki/spaces/SC/pages/2064515093/PSA+Guidance+on+AI-assisted+Coding

Checklist

  • Add a new entry in an appropriate subdirectory of changelog.d
  • Read and follow the PR guidelines

@fisx fisx requested a review from a team as a code owner March 23, 2026 08:45
@fisx fisx requested a review from Copilot March 23, 2026 08:46
@zebot zebot added the ok-to-test Approved for running tests in CI, overrides not-ok-to-test if both labels exist label Mar 23, 2026
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR extends AGENTS.md with a new “Security Guidelines” section intended to steer AI agents (and prompt authors) toward safer, more explicit, and testable code generation practices within the wire-server monorepo context.

Changes:

  • Added a new top-level “Security Guidelines” section with 12 prescriptive rules for secure AI-assisted coding.
  • Included example prompts and anti-patterns to guide how requests to agents should be phrased.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

fisx and others added 3 commits March 23, 2026 10:31
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Copy link
Contributor

@supersven supersven left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm wondering if this is really helpful or just wishful thinking. (I've got no idea if agents will really adhere to this.) However, as this is required by @wireapp/security , you get a 👍

@fisx fisx merged commit 5b42332 into develop Mar 23, 2026
7 of 10 checks passed
@fisx fisx deleted the fisx/agents-md branch March 23, 2026 10:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ok-to-test Approved for running tests in CI, overrides not-ok-to-test if both labels exist

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants