011e35bbb1693be8dcba32b336a26bcd2dcdfd9d

Author
TheEdgeOfRage <git@theedgeofrage.com>
Committer
TheEdgeOfRage <git@theedgeofrage.com>
Date

Message

Pass user's AGENTS.md to prompt to inject own preferences

Diff

 1diff --git a/src/haiku.ts b/src/haiku.ts
 2index 7c77a5568d745761e15fafa50168a706508c67b8..8086c46fd31d044fae220631960ffde647194f9a 100644
 3--- a/src/haiku.ts
 4+++ b/src/haiku.ts
 5@@ -1,3 +1,6 @@
 6+import { readFile } from "node:fs/promises"
 7+import { homedir } from "node:os"
 8+import { join } from "node:path"
 9 import type { Decision } from "./types"
10 import { HAIKU_POLICY_PROMPT } from "./rules"
11 import { callClaude } from "./api"
12@@ -63,9 +66,16 @@ export async function callHaiku(
13   const perms = sessionPermissions ?? []
14   const permBlock = perms.length > 0 ? formatPermissionsForPrompt(perms) : ""
15 
16+  let agentsMdBlock = ""
17+  try {
18+    const content = await readFile(join(homedir(), ".config", "opencode", "AGENTS.md"), "utf-8")
19+    agentsMdBlock = `## User-defined policy (from AGENTS.md)\nThe user has provided the following instructions. When these conflict with the default examples below, the user-defined policy ALWAYS takes precedence.\n\n${content}`
20+  } catch {}
21+
22   const prompt = HAIKU_POLICY_PROMPT.replace("{tool_name}", toolType)
23     .replace("{tool_input_json}", JSON.stringify(toolInput, null, 2))
24     .replace("{permissions_block}", permBlock)
25+    .replace("{agents_md_block}", agentsMdBlock)
26 
27   try {
28     const raw = await callClaude([{ role: "user", content: prompt }])
29diff --git a/src/rules.ts b/src/rules.ts
30index 94544e671ce4ed3163cf46db29ec22fcbc0b0ae2..a66eeb4dc00e7ec87b72057aa65b22393ecef526 100644
31--- a/src/rules.ts
32+++ b/src/rules.ts
33@@ -101,6 +101,8 @@ export const HAIKU_POLICY_PROMPT = `You are a security policy advisor helping de
34 
35 Your job is to use good judgment - not follow rigid rules. Consider the intent, context, and potential consequences.
36 
37+{agents_md_block}
38+
39 ## Examples of SAFE operations (allow):
40 - Reading files, directories, logs: \`cat\`, \`ls\`, \`head\`, \`tail\`, \`grep\`
41 - Git operations that don't affect remote: \`git status\`, \`git diff\`, \`git commit\`, \`git add\`