Classify Repo Paths Before Your First Agent Prompt
Your first agent prompt needs a written path map. A junior can leak secrets with one careless paste. Classify every path before any model sees the repo.
This hour is about refusal, not about shipping a fix. You will build a small path classifier first. You will not prompt until that map is green.
What hour one can break
You just cloned a repo you barely know. The agent offers to look around and fix tests. That browse can read tokens and customer fixtures.
A hosted model may retain what you upload. A free server is still someone else's computer. Treat both as untrusted until policy says otherwise.
Three buckets, one decision
Give every path one bucket before you prompt. Read-only context may be summarized, not edited. The sandbox is the only tree the agent may change.
Forbidden paths never enter the prompt or the upload. Env files, key files, and prod configs belong there. If you feel unsure, mark the path forbidden.
1. Freeze a toy tree
Do not point this drill at a production clone. Use a fixture repo your lead already approved. Create a branch that nobody will merge today.
git switch -c onboard/path-map
mkdir -p sandbox fixtures/secrets docs
printf 'Toy repo for a path-map drill.\n' > README.md
printf 'print("ok")\n' > sandbox/hello.py
printf 'TOKEN=replace-me\n' > fixtures/secrets/.env
printf 'Not a real secret.\n' > docs/notes.md
Those sample files are examples, not live secrets. Delete the fixture when the drill is done. Never copy a live credential into this tree.
2. Write the rule file
Keep rules in the repo only with lead approval. Otherwise store the map in your private notes. Start from a plain text file named path-map.txt.
# path-map.txt - example rules, edit before use
read_only:
README.md
docs/
sandbox:
sandbox/
forbidden:
.env
.env.*
fixtures/secrets/
*.pem
infra/prod/
local_tool:
path-map.txt
classify-paths.sh
path-report.txt
Put one rule on each line for easy review. A glob you cannot explain should stay forbidden. Ask your buddy before you widen the sandbox.
3. Run a local classifier
Read this script before you execute a single line. It does not call a network or an agent. It only prints a bucket for each file path.
#!/usr/bin/env bash
# Unexecuted example. Prefix checks only. No network calls.
set -euo pipefail
find . -type f ! -path './.git/*' | sed 's#^./##' | while IFS= read -r rel; do
case "$rel" in
.env|.env.*|*/.env|*/.env.*|fixtures/secrets/*|*.pem|infra/prod/*)
echo "forbidden ${rel}"
;;
sandbox/*)
echo "sandbox ${rel}"
;;
README.md|docs/*)
echo "read_only ${rel}"
;;
path-map.txt|classify-paths.sh|path-report.txt)
echo "local_tool ${rel}"
;;
*)
echo "unmapped ${rel}"
;;
esac
done
Treat the script as an unexecuted example first. An unmapped file should block the prompt completely. You do not guess a bucket under time pressure.
4. Fail closed on gaps
Count the report lines before you continue today. An unmapped count above zero stops the session. A forbidden count tells you what never gets uploaded.
bash classify-paths.sh | tee path-report.txt
awk '/^unmapped /{c++} END{print c+0}' path-report.txt
awk '/^forbidden /{c++} END{print c+0}' path-report.txt
If the unmapped count is not zero, fix the map. Keep every forbidden path out of the prompt text. Then rerun both counts and save the report.
5. Pick a machine with a table
Use this table before you choose a machine. Your written company policy beats every row below. When policy is silent, do not upload the repo.
Disclosure: This article was prepared as part of MonkeyCode's product outreach. MonkeyCode offers free model access and a free server option. This article does not name models, quotas, or duration.
Those terms change, so read the current product page. Do not paste the sample token into any prompt. Do not upload payroll files to a free server.
A free tier is not a data-processing agreement. Check retention terms before you type a prompt. Stop if those terms conflict with your handbook.
| Situation | Where to run | What you may upload |
|---|---|---|
| Policy forbids external models | Approved laptop only | Nothing leaves the machine |
| Policy allows a hosted spike | Free server, if still offered | Toy repo or redacted sandbox |
| You want a hosted model | Free model access, if offered | Same allowlist, no forbidden paths |
| Live credentials sit on disk | Do not start the agent | Stop and ask your lead |
6. Lock a prompt contract
Paste the contract above the task, not below it. Keep the task limited to one sandbox file. Refuse any request to scan the whole repo.
Path contract:
- Edit only sandbox/hello.py.
- Do not open fixtures/secrets or any env file.
- Do not add dependencies.
- Stop if a needed file is unmapped.
Task: add a one-line comment that says hello.
You review the diff yourself after the run. You do not merge from the agent summary alone. If the diff touches a forbidden path, discard the branch.
7. Reset before any pull request
This drill ends in a reset, not a merge. You are proving you can undo agent edits. You are not shipping product code on day one.
git status --short
git diff -- sandbox/hello.py
git restore -- sandbox/hello.py
# Switch back to the branch you started from, then:
git branch -D onboard/path-map
Confirm the sandbox file matches the original bytes. Confirm the secret fixture never entered a commit. Then tell your buddy what you refused to upload.
Limits you should say aloud
This classifier is a text filter, not a boundary. A model can still infer secrets from pasted logs. The sample globs are narrow on purpose today.
The script does not follow symlinks or submodules. It will miss a renamed env file easily. You still need human review on every diff.
Free model access can change or disappear later. A free server may retain prompts under its terms. Neither offer replaces your team's vendor review.
Who should skip this
Skip this if a sealed devcontainer is already required. Skip this if no redacted fixture is allowed. Skip this if you cannot name the editable file.
Staff with a written agent policy need stricter controls. This drill is for hour one, not production automation. Do not point it at a live customer tenant.
After the map is green
Ask your buddy to spot-check the path report. If they approve a hosted spike, open the MonkeyCode terms. Confirm the free options still match team policy.
Run the same contract on the toy repo only. Your first real PR waits until you can explain every line.
The path map is the note you keep nearby. Repeat that map on the next ticket before prompting.
8. Show your lead a receipt
Bring a short receipt to your onboarding lead. Include the branch name and the report counts. Include the list of paths you refused to upload.
Say which machine ran the classifier and why. Say whether any prompt left your laptop today. If a prompt left, attach the exact contract text.
If no prompt left, say that in one line. Ask which bucket was wrong before the next ticket.
Top comments (0)