{"repo":"Robotti-io/copilot-security-instructions","free":true,"listed":false,"github":"https://github.com/Robotti-io/copilot-security-instructions","clone":"git clone https://github.com/Robotti-io/copilot-security-instructions.git","description":"✨ A customizable copilot-instructions.md ruleset & prompts to guide GitHub Copilot toward secure coding defaults in Java, Node.js, C# and Python. Blocks risky patterns, teaches safe habits.","language":"JavaScript","stars":42,"topics":["appsec","copilot","rulesets","security","github-copilot","prompt-engineering","mcp","mcp-server","mcp-servers"],"license":"Apache-2.0","category":"mcp-servers","readme_excerpt":"🛡️ Copilot Security Instructions A comprehensive toolkit to guide GitHub Copilot toward secure coding practices . This project includes customizable instructions and security-focused prompts to help development teams identify and mitigate security risks effectively. Designed for security-conscious teams, this configuration ensures Copilot suggests safer code patterns, avoids common vulnerabilities, and reinforces best practices — all without disrupting your workflow. --- 🔐 What's Inside This project offers: - Secure-by-default guidance for all languages (e.g., input validation, secret handling, safe logging). - Language-specific secure patterns : - ☕ Java - 🟩 Node.js - 🟦 C# - 🐍 Python - \"Do Not Suggest\" lists to block risky Copilot completions (e.g., eval , inline SQL, insecure deserialization). - AI hallucination protections to prevent package spoofing, non-existent APIs, and misinformation risks. - Mentorship-style tips to help newer engineers build secure coding habits. - Custom agents & Agent Skills under agents/ and skills/ for repeatable AppSec workflows inside Copilot. - An installable GitHub Copilot CLI plugin under plugins/copilot-security for reusable AppSec agents and skills across projects. - An MCP server for seamless integration of these prompts into other projects. --- 🗂️ Prompt Catalogue Explore the available prompts and their intended use cases: These prompt files live under prompts/ in this repo and are intended to be copied into a consuming repository","default_branch":null,"files":null,"tree":[],"storefront":"/r/Robotti-io","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Robotti-io/copilot-security-instructions/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}