<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Aditya Goyal</title>
    <description>The latest articles on DEV Community by Aditya Goyal (@adityagoyal009).</description>
    <link>https://dev.to/adityagoyal009</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4151085%2F5b0244d7-5e20-4fe6-a232-e90b1a1d366e.png</url>
      <title>DEV Community: Aditya Goyal</title>
      <link>https://dev.to/adityagoyal009</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/adityagoyal009"/>
    <language>en</language>
    <item>
      <title>Why coding agents should work on a copy of your repo</title>
      <dc:creator>Aditya Goyal</dc:creator>
      <pubDate>Wed, 30 Sep 2026 01:53:19 +0000</pubDate>
      <link>https://dev.to/adityagoyal009/why-coding-agents-should-work-on-a-copy-of-your-repo-1l7e</link>
      <guid>https://dev.to/adityagoyal009/why-coding-agents-should-work-on-a-copy-of-your-repo-1l7e</guid>
      <description>&lt;p&gt;A coding agent should work on its own copy of your repository, on its own branch, so that nothing it does touches your working files until you have read the diff and merged it yourself. Git worktrees are the simplest way to do this: one repository, several separate working directories, each on a different branch.&lt;/p&gt;

&lt;p&gt;This guide explains what goes wrong without isolation, how worktrees work, the commands you need and the limits you should know about.&lt;/p&gt;

&lt;h2&gt;
  
  
  What goes wrong in a shared directory
&lt;/h2&gt;

&lt;p&gt;If an agent edits the same directory you are working in, several problems appear quickly.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Mixed changes.&lt;/strong&gt; Your half-finished work and the agent's edits end up in the same set of uncommitted changes. Telling them apart later is tedious and easy to get wrong.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Moving ground.&lt;/strong&gt; The agent changes a file while you are reading or editing it. Your editor, your running development server and your tests all see a project that keeps shifting.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Harder review.&lt;/strong&gt; There is no clean line between before and after, so there is no single diff that shows what the agent did.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Harder undo.&lt;/strong&gt; If the result is poor, you want to throw it away. In a shared directory, discarding the agent's changes risks discarding your own.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Collisions between agents.&lt;/strong&gt; Two agents in one directory overwrite each other's files and run tests against each other's unfinished work. See &lt;a href="https://prismlabs.solutions/blog-running-several-ai-coding-agents.html" rel="noopener noreferrer"&gt;running more than one AI coding agent&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Isolation solves all five with one idea. The agent's work lives somewhere else until you choose to bring it in.&lt;/p&gt;

&lt;h2&gt;
  
  
  What a git worktree is
&lt;/h2&gt;

&lt;p&gt;Normally a git repository has one working directory: the folder where the files of your current branch are checked out. A worktree is an additional working directory attached to the same repository. Each worktree has its own checked-out branch, its own files on disk and its own staging area. All of them share one underlying store of commits and history.&lt;/p&gt;

&lt;p&gt;That sharing is the advantage over making a second clone. There is no second copy of the history to download or keep in step. A commit made in one worktree is visible from the others straight away, because there is only one repository underneath. You can compare, cherry-pick or merge between them without pushing or pulling anything.&lt;/p&gt;

&lt;p&gt;Git applies one rule that helps here: the same branch cannot be checked out in two worktrees at once. Each agent is therefore on its own branch by construction.&lt;/p&gt;

&lt;h2&gt;
  
  
  The basic commands
&lt;/h2&gt;

&lt;p&gt;Create a worktree in a sibling folder, on a new branch:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git worktree add ../myproject-fix-login &lt;span class="nt"&gt;-b&lt;/span&gt; agent/fix-login
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;See what exists:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git worktree list
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Review the work from your main directory when the agent has finished:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight diff"&gt;&lt;code&gt;&lt;span class="p"&gt;git diff main...agent/fix-login
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Merge if you are satisfied, then tidy up:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git merge agent/fix-login
git worktree remove ../myproject-fix-login
git branch &lt;span class="nt"&gt;-d&lt;/span&gt; agent/fix-login
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If a worktree folder was deleted by hand, &lt;code&gt;git worktree prune&lt;/code&gt; clears the leftover record.&lt;/p&gt;

&lt;p&gt;Many agent tools now create and remove worktrees for you. It is still worth knowing what happens underneath, because at some point you will need to find a branch or clean up after a session that ended badly.&lt;/p&gt;

&lt;h2&gt;
  
  
  A simple workflow
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Create a worktree and branch for the task.&lt;/strong&gt; Name the branch after the task, and the agent if you use several.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Start the agent in that directory&lt;/strong&gt; with a bounded task and a clear finishing condition, such as a test that must pass.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Let it work freely there.&lt;/strong&gt; Because nothing counts until you merge, the agent does not need to ask before each edit. This removes most of the small permission prompts that people learn to click through, a problem described in &lt;a href="https://prismlabs.solutions/blog-human-in-the-loop-approvals.html" rel="noopener noreferrer"&gt;designing approvals people do not skip&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Review one diff.&lt;/strong&gt; Read it as you would a colleague's pull request. Run the checks.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Merge it yourself,&lt;/strong&gt; ask for changes, or delete the branch and lose nothing.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The important shift is that review happens once, at a natural boundary, with the full change in front of you.&lt;/p&gt;

&lt;h2&gt;
  
  
  Things that catch people out
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Files git does not track are not copied.&lt;/strong&gt; A new worktree contains only tracked files. Installed dependencies, build output and local settings files that git ignores will be missing. You will usually need to run your install step in each worktree, and provide any local configuration the project needs. Be careful about copying secrets into a directory an agent can read; give it test credentials where possible.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Disk space and install time.&lt;/strong&gt; History is shared, but each worktree has its own checked-out files and its own installed dependencies. For large projects this adds up. Remove worktrees when you have finished with them.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Shared machine resources.&lt;/strong&gt; Separate directories do not give you separate ports, databases or caches. Two worktrees running the same development server will collide on the port. Give each its own, or run one at a time.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Stale branches.&lt;/strong&gt; If the main branch moves on while an agent works, its branch falls behind. Bring it up to date before you review, so you are judging the change against the current code.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Submodules and unusual setups.&lt;/strong&gt; Projects that use git submodules or depend on absolute paths may need extra care. Test the process once by hand before relying on it.&lt;/p&gt;

&lt;h2&gt;
  
  
  A worktree is not a sandbox
&lt;/h2&gt;

&lt;p&gt;This point matters most. A worktree isolates the agent's changes from your working files. It does not restrict what the agent can do on your computer. An agent that can run shell commands can still read other folders, use the network and reach anything your user account can reach. It also shares the repository's configuration and hooks with your main checkout.&lt;/p&gt;

&lt;p&gt;For protection against a misbehaving agent or a malicious instruction hidden in something it reads, you need other measures as well: limited tools and permissions, approval for risky commands, and for stronger separation a container or virtual machine. See &lt;a href="https://prismlabs.solutions/blog-agent-skills-plugins-tool-servers.html" rel="noopener noreferrer"&gt;skills, plugins and tool servers explained&lt;/a&gt; for how an agent's reach is decided. Use worktrees to keep work organised and reviewable, and use permissions and sandboxes for safety.&lt;/p&gt;

&lt;p&gt;Equally, keep the step that leaves your machine under your own control. An agent can commit to its branch as often as it likes. Pushing to a shared remote, opening a pull request and merging are better kept as decisions a person makes.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Written by Aditya Goyal, AI-assisted. First published at &lt;a href="https://prismlabs.solutions/blog-coding-agents-isolated-worktrees.html" rel="noopener noreferrer"&gt;prismlabs.solutions&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>productivity</category>
      <category>security</category>
    </item>
    <item>
      <title>What actually gets sent to an AI provider when you ask?</title>
      <dc:creator>Aditya Goyal</dc:creator>
      <pubDate>Wed, 30 Sep 2026 01:52:48 +0000</pubDate>
      <link>https://dev.to/adityagoyal009/what-actually-gets-sent-to-an-ai-provider-when-you-ask-44e3</link>
      <guid>https://dev.to/adityagoyal009/what-actually-gets-sent-to-an-ai-provider-when-you-ask-44e3</guid>
      <description>&lt;p&gt;When you ask an AI model a question, the provider receives the whole request, not only the sentence you typed: hidden instructions, the earlier conversation, any attached files or retrieved passages, and descriptions of the tools the model may use. The model has no memory between requests, so everything it needs to know must be sent again each time.&lt;/p&gt;

&lt;p&gt;That second point surprises people. It is the key to understanding what leaves your device.&lt;/p&gt;

&lt;h2&gt;
  
  
  Models are stateless
&lt;/h2&gt;

&lt;p&gt;A large language model, as served over an API, does not remember your last message. Each request stands alone. The appearance of memory in a chat comes from the application, which resends the conversation so far along with your new message.&lt;/p&gt;

&lt;p&gt;So by the tenth message in a long chat, the request contains messages one to nine as well. If you pasted a long document in message two, that document is sent again with every later message in that conversation, unless the application trims or summarises the history. Some providers offer caching so that repeated content is cheaper and faster to process, but the content is still part of the request.&lt;/p&gt;

&lt;h2&gt;
  
  
  The parts of a typical request
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Part&lt;/th&gt;
&lt;th&gt;What it is&lt;/th&gt;
&lt;th&gt;Who wrote it&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;System prompt&lt;/td&gt;
&lt;td&gt;Standing instructions: role, rules, tone, format&lt;/td&gt;
&lt;td&gt;The application&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Conversation history&lt;/td&gt;
&lt;td&gt;Earlier messages and replies&lt;/td&gt;
&lt;td&gt;You and the model&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Your new message&lt;/td&gt;
&lt;td&gt;The question you just typed&lt;/td&gt;
&lt;td&gt;You&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Attachments&lt;/td&gt;
&lt;td&gt;Files, images, pasted text&lt;/td&gt;
&lt;td&gt;You&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Retrieved context&lt;/td&gt;
&lt;td&gt;Passages the application looked up for this question&lt;/td&gt;
&lt;td&gt;The application&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Tool definitions&lt;/td&gt;
&lt;td&gt;Names and descriptions of tools the model may call&lt;/td&gt;
&lt;td&gt;The application&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Tool results&lt;/td&gt;
&lt;td&gt;Output from tools called earlier in the task&lt;/td&gt;
&lt;td&gt;Your systems&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Parameters&lt;/td&gt;
&lt;td&gt;Model name, length limits and similar settings&lt;/td&gt;
&lt;td&gt;The application&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Alongside the content, the request carries the usual network details: an API key or session token that identifies the account, your IP address, and headers naming the client software.&lt;/p&gt;

&lt;h2&gt;
  
  
  Retrieved context: the part you do not see
&lt;/h2&gt;

&lt;p&gt;Many AI tools search your documents before asking the model. This pattern is called retrieval-augmented generation. The application finds passages that look relevant and places them in the request, so that the model can answer from them.&lt;/p&gt;

&lt;p&gt;This is useful, and it is also the easiest place for more to leave your device than you expected. You typed one line. The application may have added several pages from your files. A well-designed tool shows you what it attached. The guide on &lt;a href="https://prismlabs.solutions/blog-ai-answers-with-sources.html" rel="noopener noreferrer"&gt;AI answers with sources&lt;/a&gt; explains why this pattern is worth the trade.&lt;/p&gt;

&lt;h2&gt;
  
  
  Agents send more than chats
&lt;/h2&gt;

&lt;p&gt;An AI agent works in a loop. It asks the model what to do next, runs a tool, sends the result back, and repeats. Each tool result becomes part of the next request.&lt;/p&gt;

&lt;p&gt;For a coding agent, that means file contents, directory listings, command output, error messages and test logs all go to the provider as the task proceeds. If a command prints an environment variable that holds a password, that password is now in a prompt. If the agent reads a configuration file with credentials in it, the same applies.&lt;/p&gt;

&lt;p&gt;This is why the set of tools and files an agent can reach matters so much. The guide on &lt;a href="https://prismlabs.solutions/blog-agent-skills-plugins-tool-servers.html" rel="noopener noreferrer"&gt;skills, plugins and tool servers&lt;/a&gt; covers how those are granted.&lt;/p&gt;

&lt;h2&gt;
  
  
  What is usually not sent
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Files the application never read.&lt;/strong&gt; A model cannot browse your disk. It sees only what the application places in a request. The risk lies in how much the application is allowed to read, not in the model reaching out.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Your password for the provider.&lt;/strong&gt; A request carries a token or key, not the password itself.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Other applications' data.&lt;/strong&gt; Unless a tool or integration has been connected that fetches it.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Treat these as the normal case, not a guarantee. What a particular application reads and uploads in the background, such as indexing, telemetry and crash reports, is a question for that vendor.&lt;/p&gt;

&lt;h2&gt;
  
  
  What happens at the other end
&lt;/h2&gt;

&lt;p&gt;Once a request arrives, the provider processes it and returns a response. What happens afterwards depends on the provider, the plan and your settings. The points that commonly vary are:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;how long prompts and outputs are retained, and in which logs&lt;/li&gt;
&lt;li&gt;whether content may be used to train or improve models, and whether that is opt-in or opt-out&lt;/li&gt;
&lt;li&gt;whether staff or automated systems may review content, for example for abuse monitoring&lt;/li&gt;
&lt;li&gt;where the data is processed geographically&lt;/li&gt;
&lt;li&gt;which other companies process it on the provider's behalf&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Consumer plans and business or API plans from the same provider often have different terms. Do not rely on a summary written by someone else, including this one. Check the provider's current terms for the exact plan you use.&lt;/p&gt;

&lt;p&gt;There may also be an intermediary. If you use an AI feature inside another product, the request may pass through that product's servers before reaching the model provider. That adds a custodian. The guide on &lt;a href="https://prismlabs.solutions/blog-what-is-data-custody-in-ai.html" rel="noopener noreferrer"&gt;data custody in AI&lt;/a&gt; explains why each hop matters.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to keep requests small
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Start new conversations for new topics.&lt;/strong&gt; Old history stops being resent.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Paste the relevant section, not the whole document.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Remove what the model does not need.&lt;/strong&gt; Names, account numbers and identifiers can often be replaced with placeholders without harming the answer.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Keep secrets out of files and output an agent can read.&lt;/strong&gt; Use a proper secret store. See &lt;a href="https://prismlabs.solutions/blog-where-ai-keys-should-live.html" rel="noopener noreferrer"&gt;where your AI keys and logins should live&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Limit what agents can reach.&lt;/strong&gt; Give each one the folders and tools the job needs, no more.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Prefer tools that show you the request.&lt;/strong&gt; If you can see what was attached, you can correct it.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;None of this requires avoiding hosted models. It requires knowing that the unit of disclosure is the full request, and shaping that request with care.&lt;/p&gt;

&lt;p&gt;This is general information, not legal advice. If you handle personal or regulated data, check your obligations with your own adviser.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Written by Aditya Goyal, AI-assisted. First published at &lt;a href="https://prismlabs.solutions/blog-what-gets-sent-to-an-ai-provider.html" rel="noopener noreferrer"&gt;prismlabs.solutions&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>privacy</category>
      <category>security</category>
      <category>llm</category>
    </item>
  </channel>
</rss>
