codingbuddy copilot-instructions.md

A set of Copilot instructions for reviewing code, especially TypeScript code. It defines review priorities, security checks, and coding standards such as strict types and safe handling of missing values.

In plain words
What is it for?
Use it to review code for secrets, injection risks, input validation, dependency problems, TypeScript type safety, function complexity, tests, and performance.
Why use it?
It gives reviews a consistent way to separate merge-blocking problems from issues for discussion and optional suggestions.

Instructions file for GitHub Copilot

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/jeremydev87/codingbuddy/copilot-instructions
Clone the repo
git clone --depth 1 https://github.com/JeremyDev87/codingbuddy

Made for: GitHub Copilot.

Per session 512 This file is loaded in full into every session.
When invoked 512 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00512 $0.00512
Opus 5 $0.00256 $0.00256
Sonnet 5 $0.00102 $0.00102
Haiku 4.5 $0.00051 $0.00051

Measured 2d ago against content hash e46d0b9e21ec, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

codingbuddy copilot-instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/copilot-instructions.md · 63 lines

How it starts

The opening of the file, as written. The whole thing — 63 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Copilot Code Review Instructions

Review Priority Levels

  • 🔴 CRITICAL (Block merge): Security vulnerabilities, logic errors, breaking changes, data loss risks
  • 🟡 IMPORTANT (Requires discussion): Code quality issues, missing tests, performance bottlenecks, architectural deviations
  • 🟢 SUGGESTION (Non-blocking): Readability improvements, minor optimizations, best practice refinements

Security Review

  • Check for hardcoded secrets, API keys, or credentials
  • Look for SQL injection and XSS vulnerabilities
  • Verify proper input validation and sanitization
  • Check for command injection in shell executions
  • Ensure authentication/authorization is properly implemented
  • Verify dependencies don't have known vulnerabilities

TypeScript Standards

  • No any type usage — use unknown or specific types with strict mode
  • Prefer const over let, never use var
  • Use explicit return types for public functions
  • Ensure proper null/undefined handling with strict null checks
  • Prefer pure functions over impure ones (separate files for pure/impure)

Code Quality

  • Functions should follow Single Responsibility Principle (10-20 lines max)
  • No deeply nested code (max 3-4 levels)
  • No magic numbers — use named constants
  • Remove dead code and unused imports
  • DRY: No duplicated logic across files
  • Keep methods small and focused

Testing Standards

  • Core logic (entities, shared/utils, hooks) MUST have tests (TDD approach)
  • UI components (features, widgets) should have test-after coverage
  • Target 90%+ test coverage
  • No mocking — test real behavior with actual implementations
  • Use Arrange-Act-Assert pattern
  • Test edge cases and error paths

Architecture

  • Layer dependency: app → widgets → features → entities → shared
  • No circular dependencies between modules
  • Server Components as default, Client Components only when necessary
  • Pure/impure function separation (different files)

NestJS Patterns (MCP Server)

  • Follow NestJS module pattern (Module → Controller/Gateway → Service)
  • Use dependency injection properly
  • Validate DTOs with class-validator decorators
  • Handle errors with proper NestJS exception filters

Read the full file on GitHub · 63 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 63 lines · 512 tokens per session scan A e46d0b9e21ec

Subscribe to this mod's changes

codingbuddy copilot-instructions.md is an instructions file published in the GitHub repository JeremyDev87/codingbuddy (31 stars, last pushed 4mo ago), licensed MIT. It adds 512 tokens to every session, about $0.0026 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

MonkeyCode AGENTS.md

AGENTS.md instructions for chaitin/MonkeyCode, covering git 提交与推送规则, ohmydesign-tmp 例外, 启动 monkeycode debug app(开发与测试), 1. 编译 agent(必须用最新功能分支代码) and 2. 启动 debug app(ui-next 热加载).

chaitin/MonkeyCode · 863 tokens

claude-code-plugins AGENTS.md

Instructions for DropFan/claude-code-plugins, covering claude code plugins collection, repository structure, plugin management, development guidelines and adding a self-developed plugin.

DropFan/claude-code-plugins · 794 tokens

codeframe AGENTS.md

AGENTS.md instructions for frankbria/codeframe: The guidelines for this repo live in CLAUDE.md. Read that file.

frankbria/codeframe · 145 tokens

open-mercato CLAUDE.md

Instructions for open-mercato/open-mercato, a project described as: The AI-Engineering Foundation Framework for CRM/ERP and commerce: open-source TypeScript, with multi-tenancy, RBAC, events and domain modules already decided as conventions and specs, so Cursor, Claude Code and Codex build features instead of…

open-mercato/open-mercato · 5 tokens

claude-skills AGENTS.md

AGENTS.md instructions for heymegabyte/claude-skills, covering emdash skills — agent instructions, stack, usage, key files and for ai coding tools.

heymegabyte/claude-skills · 564 tokens

claude-skills copilot-instructions.md

Copilot instructions for heymegabyte/claude-skills, covering emdash skills for github copilot, stack and rules.

heymegabyte/claude-skills · 196 tokens