DEV Community

Vildanden
Vildanden

Posted on

Give your coding agent a deny-list for secrets and path writes

Most agent failures are less about model IQ and more about missing boundaries.

Put explicit deny-lists where the agent can actually apply them:

  • Secrets: .env*, credentials/, private keys, and token files
  • Path writes: build artifacts, .git/, system directories, and unrelated repos
  • Risky commands: curl | sh, destructive deletes, or publishing credentials

For a team, keep stack-specific rules in scoped Cursor .mdc files so they load only where relevant. Use AGENTS.md for repo-wide workflow and invariants. CLAUDE.md can carry Claude-specific instructions.

Avoid dumping every rule into one giant AGENTS.md: it gets noisy, stale, and hard to review. Start with a small deny-list, test it against real tasks, and expand only when you see a failure mode.

I made a free sample with scoped rules, AGENTS.md, and CLAUDE.md examples for Next.js:

https://vildanden.gumroad.com/l/xphax

Landing page:

https://fairly-charlie-907.rehost.page/

Top comments (0)