security: keep caller AGENTS.md as subordinate repo notes, not rules
Fully hiding the caller's AGENTS.md dropped repo-specific operational knowledge agents need (e.g. homelab's migration mechanism: deleting a service requires a matching migrations/*.sh, else the old service keeps running in prod). Separate the two concerns: - Platform golden rules stay authoritative (scripts/agent-rules.md), un-overridable. - The caller's AGENTS.md / CLAUDE.md text is captured before quarantine and injected into the prompt as explicitly SUBORDINATE context — usable for repo mechanics, but unable to change behavior, grant permissions, or override the rules. - opencode.json / .opencode remain fully blocked (config + RCE), never re-injected. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
06df6320a1
commit
5601dfe8d6
+10
-2
@@ -29,8 +29,16 @@ workflow secrets):
|
||||
They are moved aside before opencode starts and restored after it exits, so the committed tree is
|
||||
unchanged. The authoritative configuration comes from `~/.config/opencode/` (written by
|
||||
`scripts/install-opencode.sh`), and the authoritative golden rules from `scripts/agent-rules.md`,
|
||||
injected into the agent prompt. A caller repo's own `AGENTS.md` is informational to humans only and is
|
||||
never followed as rules by the agent.
|
||||
injected into the agent prompt.
|
||||
|
||||
**`opencode.json` / `.opencode/` are fully blocked** — never re-introduced — because they can change
|
||||
config or execute code.
|
||||
|
||||
**`AGENTS.md` / `CLAUDE.md` are treated as repo notes, not rules.** A caller repo legitimately uses
|
||||
its `AGENTS.md` to document repo-specific mechanics (build/deploy/migration conventions) the agent
|
||||
needs. So its text is captured and injected into the prompt as explicitly **subordinate** context —
|
||||
useful for how the repo works, but unable to change agent behavior, grant permissions, or override
|
||||
the golden rules. It is never auto-loaded by opencode as top-level instructions.
|
||||
|
||||
**Consequence:** an agent cannot durably edit these quarantined files *during a run* — its changes to
|
||||
them are not persisted. Change them via a normal human PR instead.
|
||||
|
||||
Reference in New Issue
Block a user