DEV Community

Vildanden
Vildanden

Posted on

Give your coding agent an "ask first" list, not just a "never" list

Most agent configs have two modes: things the agent may do, and things it must never do. Real work needs a third bucket: ask first.

A flat deny-list is too blunt. Ban git push outright and the agent can't finish a branch you actually wanted pushed. Allow it silently and one bad loop rewrites shared history. The middle bucket fixes that.

A three-bucket layout for AGENTS.md

## Never
- Invent secrets, API keys, or env var values
- Force-push or rewrite shared history
- Delete data outside the working tree

## Ask first (stop and describe the command)
- Any push to a remote
- Schema migrations against a non-local database
- Installing a new dependency
- Changing CI or deploy config

## Fine without asking
- Edit files in the working tree
- Run the test suite and linters
- Read logs and local docs
Enter fullscreen mode Exit fullscreen mode

Keep each bucket under ten lines. When a line needs a paragraph of explanation, move it into a scoped Cursor rule (.cursor/rules/*.mdc) that only loads for the matching paths.

Why it works

  • The agent fails closed on irreversible actions without stalling on everyday ones.
  • Reviews get shorter: anything surprising should have triggered an "ask first" stop, so you know where to look.
  • New teammates read the same three lists and learn the house rules in a minute.

Vildanden's free Agent Config sample ships with this split for a Next.js-leaning repo:

Brand: Vildanden / @vildandenai. The paid multi-stack pack is optional; start with the free files and keep only what earns its place.

Top comments (0)