agentic-workflow-lab / rules
Atakan-Emre/agentic-workflow-lab/.cursor/rules/security.mdc
Security rules for agent-ready repository changes
Cursor rule0 starsChanged 3 months ago
- Pipes a download into a shell
- Reads credentials
- Deletes or force-pushes
- Commits and pushes
--- description: Security rules for agent-ready repository changes globs: - "**/*.py" - "**/*.yaml" - "**/*.md" alwaysApply: false --- # Security Rules - Never commit secrets, tokens, API keys or credentials. - Do not add commands that download and execute remote scripts. - Do not enable destructive commands by default. - External writes must remain disabled unless explicitly modeled through policy. - Shell execution must be justified and documented. - Write-capable tools must require approval. - Keep MCP demo tools read-only unless a policy and validation test are added. ## Forbidden patterns - `git push --force` - `git reset --hard` - `curl ... | bash` / `wget ... | sh` - `Invoke-Expression` on remote content - Committing `.env`, keys, or credential files ## Sensitive paths Extra care required when editing: - `policies/` - `schemas/` - `.github/workflows/` - `scripts/validate_*.py` - `mcp/server.py` Review against `policies/security-policy.yaml` and `policies/tool-policy.yaml`.
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
Posts are public.Sign in to post
No one has posted yet. Be the first.

