ee35f4f4e099177c39dcdf509d13d8419728ef8f

Author
TheEdgeOfRage <git@theedgeofrage.com>
Committer
TheEdgeOfRage <git@theedgeofrage.com>
Date

Message

Remove adding user's global AGENTS.md into haiku context

Diff

 1diff --git a/src/cache.ts b/src/cache.ts
 2index 4d602ff1675f29f70e6fb87bc2e1ca4bfd180e33..e54bc3cabcae61a765bd6c2e65e7068162e89b40 100644
 3--- a/src/cache.ts
 4+++ b/src/cache.ts
 5@@ -25,7 +25,7 @@ export function setCacheFile(path: string) {
 6 type CacheEntry = {
 7   key: string
 8   ts: string
 9-  policy_version: string
10+  policy_version: number
11   tool_type: string
12   normalized: string
13   decision: Decision
14diff --git a/src/haiku.ts b/src/haiku.ts
15index 8086c46fd31d044fae220631960ffde647194f9a..7c77a5568d745761e15fafa50168a706508c67b8 100644
16--- a/src/haiku.ts
17+++ b/src/haiku.ts
18@@ -1,6 +1,3 @@
19-import { readFile } from "node:fs/promises"
20-import { homedir } from "node:os"
21-import { join } from "node:path"
22 import type { Decision } from "./types"
23 import { HAIKU_POLICY_PROMPT } from "./rules"
24 import { callClaude } from "./api"
25@@ -66,16 +63,9 @@ export async function callHaiku(
26   const perms = sessionPermissions ?? []
27   const permBlock = perms.length > 0 ? formatPermissionsForPrompt(perms) : ""
28 
29-  let agentsMdBlock = ""
30-  try {
31-    const content = await readFile(join(homedir(), ".config", "opencode", "AGENTS.md"), "utf-8")
32-    agentsMdBlock = `## User-defined policy (from AGENTS.md)\nThe user has provided the following instructions. When these conflict with the default examples below, the user-defined policy ALWAYS takes precedence.\n\n${content}`
33-  } catch {}
34-
35   const prompt = HAIKU_POLICY_PROMPT.replace("{tool_name}", toolType)
36     .replace("{tool_input_json}", JSON.stringify(toolInput, null, 2))
37     .replace("{permissions_block}", permBlock)
38-    .replace("{agents_md_block}", agentsMdBlock)
39 
40   try {
41     const raw = await callClaude([{ role: "user", content: prompt }])
42diff --git a/src/rules.ts b/src/rules.ts
43index 103606df62fafbf48b91fbe2ce6d96630fa0c1a6..a2349b814b4dc0fcc729c758e47a9c052548e627 100644
44--- a/src/rules.ts
45+++ b/src/rules.ts
46@@ -1,5 +1,5 @@
47 // Bump to invalidate all cached decisions when rules change.
48-export const POLICY_VERSION = "3.5.2";
49+export const POLICY_VERSION = 1;
50 
51 // Matched with test() on anchored patterns (equivalent to Python fullmatch).
52 // Purely a performance optimization — these would pass LLM review anyway.
53@@ -106,8 +106,6 @@ export const HAIKU_POLICY_PROMPT = `You are a security policy advisor helping de
54 
55 Your job is to use good judgment - not follow rigid rules. Consider the intent, context, and potential consequences.
56 
57-{agents_md_block}
58-
59 ## Examples of SAFE operations (allow):
60 - Reading files, directories, logs within the project: \`cat\`, \`ls\`, \`head\`, \`tail\`, \`grep\`
61 - Git operations that aren't destructive: \`git status\`, \`git diff\`, \`git commit\`, \`git add\`
62@@ -119,7 +117,8 @@ Your job is to use good judgment - not follow rigid rules. Consider the intent,
63 - Creating files in project directories: \`mkdir src/components\`, \`touch README.md\`
64 
65 ## Examples of RISKY operations (ask):
66-- Reading files outside of normal expected boundaries: \`outside of /home or /tmp\`, \`~/.config\`, \`~/.local\`
67+- Reading files outside of normal project boundaries: \`outside of /home or /tmp\`, \`~/.config\`, \`~/.local\`
68+- Reading potential secrets: \`.env\`
69 - Git pushing to main or force pushes: \`git push\`, \`git push --force\`
70 - Destructive git ops: \`git checkout --\`, \`git restore\`, \`git reset --hard\`, \`git clean -fd\`
71 - Anything that touches remote systems: AWS CLI, remote database operations, etc.