e751252916d5e04557532c57099e7aad9c4b3aae

Author
TheEdgeOfRage <git@theedgeofrage.com>
Committer
TheEdgeOfRage <git@theedgeofrage.com>
Date

Message

Update haiku prompt

Diff

 1diff --git a/src/rules.ts b/src/rules.ts
 2index ed5c34fafc296e15309ec53aadf99918f7aa4118..9b81c35837ec23c938e6ad8bd2bd40f59b5c51c8 100644
 3--- a/src/rules.ts
 4+++ b/src/rules.ts
 5@@ -82,7 +82,7 @@ export const CONFIG_ALLOW_PATTERNS: RegExp[] = [
 6 
 7   // Bun
 8   /^(?:TZ=\S+\s+)?bun\s/,
 9-]
10+];
11 
12 // Searched (not anchored) — obviously dangerous patterns that warrant user confirmation.
13 export const ASK_PATTERNS: RegExp[] = [
14@@ -104,23 +104,23 @@ Your job is to use good judgment - not follow rigid rules. Consider the intent,
15 {agents_md_block}
16 
17 ## Examples of SAFE operations (allow):
18-- Reading files, directories, logs: \`cat\`, \`ls\`, \`head\`, \`tail\`, \`grep\`
19-- Git operations that don't affect remote: \`git status\`, \`git diff\`, \`git commit\`, \`git add\`
20+- Reading files, directories, logs within the project: \`cat\`, \`ls\`, \`head\`, \`tail\`, \`grep\`
21+- Git operations that aren't destructive: \`git status\`, \`git diff\`, \`git commit\`, \`git add\`
22 - Git push to feature branches (not main/master): \`git push origin feature/my-branch\`
23 - Running tests: \`npm test\`, \`pytest\`, \`go test\`, \`make test\`
24 - Building projects: \`npm run build\`, \`cargo build\`, \`make build\`
25-- Installing dependencies: \`npm install\`, \`pip install\`, \`uv sync\`
26+- Installing dependencies: \`npm install\`, \`pip install\`, \`uv add\`
27 - Process inspection: \`ps\`, \`top\`, \`lsof\`
28 - Creating files in project directories: \`mkdir src/components\`, \`touch README.md\`
29-- **Database queries on dev/staging databases**: \`psql dev-db -c "SELECT ..."\`
30-- **AWS CLI read operations**: \`aws secretsmanager get-secret-value\`, \`aws s3 ls\`
31 
32 ## Examples of DANGEROUS operations (deny or ask):
33+- Reading files outside of project boundaries: \`outside of /home or /tmp\`, \`~/.config\`, \`~/.local\`
34 - Privilege escalation: \`sudo\`, \`su\`, \`doas\`
35 - Deleting system files: \`rm -rf /\`, \`rm -rf ~\`, \`rm -rf /etc\`
36-- Force pushing: \`git push --force\`, \`git push -f\`
37-- Destructive git ops: \`git reset --hard\`, \`git clean -fd\`
38+- Git pushing to main or force pushes: \`git push\`, \`git push --force\`
39+- Destructive git ops: \`git checkout --\`, \`git restore\`git reset --hard\`, \`git clean -fd\`
40 - Remote code execution: \`curl ... | bash\`, \`wget ... | sh\`
41+- Anything that touches remote systems: AWS CLI, remote database operations, etc.
42 - System operations: \`reboot\`, \`shutdown\`, \`dd\`, \`mkfs\`
43 - Changing permissions broadly: \`chmod 777\`, \`chown\`
44 - Writing to system locations: \`> /etc/hosts\`, \`tee /etc/passwd\`
45@@ -134,16 +134,16 @@ Your job is to use good judgment - not follow rigid rules. Consider the intent,
46    - Reversible mistakes are less concerning than irreversible ones.
47 
48 2. **Is this a normal development operation?**
49-   - Building, testing, committing, installing deps - these are routine → **allow**
50+   - Building, testing, committing - these are routine → **allow**
51    - System administration, permission changes, force pushes - these need care → **ask**
52 
53 3. **Does this look intentional and scoped?**
54    - \`rm -rf node_modules\` - clearly intentional, scoped to project → **allow**
55    - \`rm -rf /\` - catastrophic, likely a mistake → **deny**
56 
57-4. **Be decisive, not overly cautious**
58-   - If an operation is clearly safe (read-only, dev environment, normal workflow), choose **allow**
59-   - Only use "ask" when there's genuine ambiguity or risk
60+4. **Be decisive, but cautious**
61+   - If an operation is clearly safe (read-only, local environment, normal workflow), choose **allow**
62+   - Only use "ask" when there's ambiguity, risk or you are unsure about the target
63 
64 ## Your response:
65