Diff
1diff --git a/dot_config/opencode/AGENTS.md b/dot_config/opencode/AGENTS.md
2index 8836498fbc09acca9165d3f7f80df8b62247a9ad..1dd0566b57ae15a6d15e9621bf96bbe789c14947 100644
3--- a/dot_config/opencode/AGENTS.md
4+++ b/dot_config/opencode/AGENTS.md
5@@ -20,10 +20,11 @@ When outputing text for human consumption (agent responses, comments, PR descrip
6 - Don't write tests for logs, metrics, or other observability behavior
7 - Zero comments by default. Only explain it if it is truly complex or unexpected behaviour
8
9-## Security
10+## Security and access
11
12 - Zero Trust. Least privilege. Never leak secrets.
13 - Do not under any circumstance read any secret files into context. Assume what is reasonably a secret (.env, auth token files, etc.)
14+- Do not search the entire home directory for something. If you don't know where something is, ask
15
16 ## State Mutation
17
18@@ -45,6 +46,6 @@ Specific footguns:
19
20 ## Remote access
21
22-Never mutate remote systems, like databases, Kubernetes, AWS, etc.
23+Never mutate remote cloud systems, like databases, Kubernetes, AWS, etc.
24 Services that are used for development (GitHub, Grafana, etc.) are fine to write to when prompted.
25-Full local docker access is also allowed
26+Full local docker read and write access is also allowed