Diff
1diff --git a/src/rules.ts b/src/rules.ts
2index ed15612087d71846762316a34f120d7e3792129b..4d714b044fbded167fd2d69e91ad355db432333e 100644
3--- a/src/rules.ts
4+++ b/src/rules.ts
5@@ -1,5 +1,5 @@
6 // Bump to invalidate all cached decisions when rules change.
7-export const POLICY_VERSION = 2;
8+export const POLICY_VERSION = 3;
9
10 // Trailing stderr redirections that are safe to strip before pattern matching.
11 // `2>&1` and `2>/dev/null` have no security implication but would otherwise
12@@ -116,7 +116,9 @@ export const HAIKU_POLICY_PROMPT = `You are a security policy advisor helping de
13 Your job is to use good judgment - not follow rigid rules. Consider the intent, context, and potential consequences.
14
15 ## Examples of SAFE operations (allow):
16-- Reading files, directories, logs within the project: \`cat\`, \`ls\`, \`head\`, \`tail\`, \`grep\`
17+- Reading files, directories, logs anywhere under the user's home directory or /tmp:
18+ \`cat ~/dev/proj/file.go\`, \`grep -n PATTERN /home/user/dev/other-repo/...\`, \`ls /tmp/...\`, \`head\`, \`tail\`
19+ Reading from another repo under \`~/dev/\` is normal multi-repo workflow — allow.
20 - Git operations that aren't destructive: \`git status\`, \`git diff\`, \`git commit\`, \`git add\`
21 - Git push to feature branches (not main/master): \`git push origin feature/my-branch\`
22 - Running tests: \`npm test\`, \`pytest\`, \`go test\`, \`make test\`
23@@ -126,8 +128,9 @@ Your job is to use good judgment - not follow rigid rules. Consider the intent,
24 - Creating files in project directories: \`mkdir src/components\`, \`touch README.md\`
25
26 ## Examples of RISKY operations (ask):
27-- Reading files outside of normal project boundaries: \`outside of /home or /tmp\`, \`~/.config\`, \`~/.local\`
28-- Reading potential secrets: \`.env\`
29+- Reading sensitive dotfile locations: \`~/.config/\`, \`~/.local/share/\`, \`~/.aws/\`, \`~/.ssh/\`, \`~/.gnupg/\`, \`~/.kube/\`, \`~/.netrc\`, \`~/.pgpass\`
30+- Reading potential secrets by name: \`.env\`, \`credentials*\`, \`id_rsa\`, \`*.pem\`, \`*.key\`
31+- Reading outside the user's home and /tmp: \`/etc/shadow\`, \`/var/log/...\`, \`/root/...\`
32 - Git pushing to main or force pushes: \`git push\`, \`git push --force\`
33 - Destructive git ops: \`git checkout --\`, \`git restore\`, \`git reset --hard\`, \`git clean -fd\`
34 - Anything that touches remote systems: AWS CLI, remote database operations, etc.