Read original ↗
newsReddit r/devopsTrust 52 · CommunityPublished 4d agoLive · 3d ago

I don't trust AGENTS.md as a secret-redaction boundary

I am getting less comfortable with using repo instruction files as a safety boundary. They are useful for preferences: commands to run, folders to avoid, how to format the final answer. But if an agent can read config files or logs, I do not think "please redact secrets" in a markdown file is enough. In one small debug task, I asked the agent to inspect config safely, and I still felt nervous when it started summarizing values instead of

Why these links exist

Every edge carries a method, confidence, and the source snippet that justified it — so bad links are debuggable.

Covers

Related across the graph