DEV Community

Quinn Zhu
Quinn Zhu

Posted on

Classify Repo Paths Before Your First Agent Prompt

Classify Repo Paths Before Your First Agent Prompt

Your first agent prompt needs a written path map. A junior can leak secrets with one careless paste. Classify every path before any model sees the repo.

This hour is about refusal, not about shipping a fix. You will build a small path classifier first. You will not prompt until that map is green.

What hour one can break

You just cloned a repo you barely know. The agent offers to look around and fix tests. That browse can read tokens and customer fixtures.

A hosted model may retain what you upload. A free server is still someone else's computer. Treat both as untrusted until policy says otherwise.

Three buckets, one decision

Give every path one bucket before you prompt. Read-only context may be summarized, not edited. The sandbox is the only tree the agent may change.

Forbidden paths never enter the prompt or the upload. Env files, key files, and prod configs belong there. If you feel unsure, mark the path forbidden.

1. Freeze a toy tree

Do not point this drill at a production clone. Use a fixture repo your lead already approved. Create a branch that nobody will merge today.

git switch -c onboard/path-map
mkdir -p sandbox fixtures/secrets docs
printf 'Toy repo for a path-map drill.\n' > README.md
printf 'print("ok")\n' > sandbox/hello.py
printf 'TOKEN=replace-me\n' > fixtures/secrets/.env
printf 'Not a real secret.\n' > docs/notes.md
Enter fullscreen mode Exit fullscreen mode

Those sample files are examples, not live secrets. Delete the fixture when the drill is done. Never copy a live credential into this tree.

2. Write the rule file

Keep rules in the repo only with lead approval. Otherwise store the map in your private notes. Start from a plain text file named path-map.txt.

# path-map.txt - example rules, edit before use
read_only:
  README.md
  docs/
sandbox:
  sandbox/
forbidden:
  .env
  .env.*
  fixtures/secrets/
  *.pem
  infra/prod/
local_tool:
  path-map.txt
  classify-paths.sh
  path-report.txt
Enter fullscreen mode Exit fullscreen mode

Put one rule on each line for easy review. A glob you cannot explain should stay forbidden. Ask your buddy before you widen the sandbox.

3. Run a local classifier

Read this script before you execute a single line. It does not call a network or an agent. It only prints a bucket for each file path.

#!/usr/bin/env bash
# Unexecuted example. Prefix checks only. No network calls.
set -euo pipefail

find . -type f ! -path './.git/*' | sed 's#^./##' | while IFS= read -r rel; do
  case "$rel" in
    .env|.env.*|*/.env|*/.env.*|fixtures/secrets/*|*.pem|infra/prod/*)
      echo "forbidden ${rel}"
      ;;
    sandbox/*)
      echo "sandbox ${rel}"
      ;;
    README.md|docs/*)
      echo "read_only ${rel}"
      ;;
    path-map.txt|classify-paths.sh|path-report.txt)
      echo "local_tool ${rel}"
      ;;
    *)
      echo "unmapped ${rel}"
      ;;
  esac
done
Enter fullscreen mode Exit fullscreen mode

Treat the script as an unexecuted example first. An unmapped file should block the prompt completely. You do not guess a bucket under time pressure.

4. Fail closed on gaps

Count the report lines before you continue today. An unmapped count above zero stops the session. A forbidden count tells you what never gets uploaded.

bash classify-paths.sh | tee path-report.txt
awk '/^unmapped /{c++} END{print c+0}' path-report.txt
awk '/^forbidden /{c++} END{print c+0}' path-report.txt
Enter fullscreen mode Exit fullscreen mode

If the unmapped count is not zero, fix the map. Keep every forbidden path out of the prompt text. Then rerun both counts and save the report.

5. Pick a machine with a table

Use this table before you choose a machine. Your written company policy beats every row below. When policy is silent, do not upload the repo.

Disclosure: This article was prepared as part of MonkeyCode's product outreach. MonkeyCode offers free model access and a free server option. This article does not name models, quotas, or duration.

Those terms change, so read the current product page. Do not paste the sample token into any prompt. Do not upload payroll files to a free server.

A free tier is not a data-processing agreement. Check retention terms before you type a prompt. Stop if those terms conflict with your handbook.

Situation Where to run What you may upload
Policy forbids external models Approved laptop only Nothing leaves the machine
Policy allows a hosted spike Free server, if still offered Toy repo or redacted sandbox
You want a hosted model Free model access, if offered Same allowlist, no forbidden paths
Live credentials sit on disk Do not start the agent Stop and ask your lead

6. Lock a prompt contract

Paste the contract above the task, not below it. Keep the task limited to one sandbox file. Refuse any request to scan the whole repo.

Path contract:
- Edit only sandbox/hello.py.
- Do not open fixtures/secrets or any env file.
- Do not add dependencies.
- Stop if a needed file is unmapped.
Task: add a one-line comment that says hello.
Enter fullscreen mode Exit fullscreen mode

You review the diff yourself after the run. You do not merge from the agent summary alone. If the diff touches a forbidden path, discard the branch.

7. Reset before any pull request

This drill ends in a reset, not a merge. You are proving you can undo agent edits. You are not shipping product code on day one.

git status --short
git diff -- sandbox/hello.py
git restore -- sandbox/hello.py
# Switch back to the branch you started from, then:
git branch -D onboard/path-map
Enter fullscreen mode Exit fullscreen mode

Confirm the sandbox file matches the original bytes. Confirm the secret fixture never entered a commit. Then tell your buddy what you refused to upload.

Limits you should say aloud

This classifier is a text filter, not a boundary. A model can still infer secrets from pasted logs. The sample globs are narrow on purpose today.

The script does not follow symlinks or submodules. It will miss a renamed env file easily. You still need human review on every diff.

Free model access can change or disappear later. A free server may retain prompts under its terms. Neither offer replaces your team's vendor review.

Who should skip this

Skip this if a sealed devcontainer is already required. Skip this if no redacted fixture is allowed. Skip this if you cannot name the editable file.

Staff with a written agent policy need stricter controls. This drill is for hour one, not production automation. Do not point it at a live customer tenant.

After the map is green

Ask your buddy to spot-check the path report. If they approve a hosted spike, open the MonkeyCode terms. Confirm the free options still match team policy.

Run the same contract on the toy repo only. Your first real PR waits until you can explain every line.

The path map is the note you keep nearby. Repeat that map on the next ticket before prompting.

8. Show your lead a receipt

Bring a short receipt to your onboarding lead. Include the branch name and the report counts. Include the list of paths you refused to upload.

Say which machine ran the classifier and why. Say whether any prompt left your laptop today. If a prompt left, attach the exact contract text.

If no prompt left, say that in one line. Ask which bucket was wrong before the next ticket.

Top comments (0)