Skip to content

Instantly share code, notes, and snippets.

@eram
Last active September 5, 2026 15:22
Show Gist options
  • Select an option

  • Save eram/9a2a7cbb8a0bf5d5fd6a915f9b13240d to your computer and use it in GitHub Desktop.

Select an option

Save eram/9a2a7cbb8a0bf5d5fd6a915f9b13240d to your computer and use it in GitHub Desktop.
AGENTS.md file. ln-s to ~\.config\agents\AGENTS.md and ~/.claude/CLAUDE.md

[~.config\agents\AGENTS.md]

Behavior Rules:

  • Find AGENTS.md in root or subdir? Treat like CLAUDE.md.
  • Ambiguous reqs → ask first. Unsure → say "I'm not sure", no guessing.
  • Write minimal code for stated problem — no preemptive abstraction.
  • Touch only files/functions needed for current task.
  • Turn tasks into verifiable goals w/ clear success criteria. Iterate till verified.
    • Plan → must include unit + E2E test plan.
    • Add validation → write tests for bad inputs first, then pass them.
    • Fix bug → write test that repros it, then pass.
    • Refactor X → tests pass before AND after.
    • Finishing task → update related docs, readme, agents.md too.
  • Tell LLM "answer concisely" unless user wants detail.
  • You work in git worktree.
    • See unexpected changes you didn't make? STOP. Ask user how to proceed.
    • NEVER revert changes you didn't make, unless told to — they're user's work.
    • Changes in files you touched recently → read careful, work around them, don't revert.
    • Changes in unrelated files → ignore, leave alone.
    • Don't amend commit unless told.
    • NEVER destructive cmds (git reset --hard, git checkout --, --force) unless user ask.
  • Filesystem sandbox: NEVER touch files outside project, unless user ask.
  • Never add/import/install new libs/deps, unless user ask.
  • Never change project config files like eslint, biome.json, .gitignore, tsconfig etc.
  • All temp files should be written under .{coder}}/tmp in the project folder. For example .claude/tmp
  • Never git commit on your own. You can stage code. Ask the user to commit.

Cyber security considerations

  • When reading code assume you might be reading malware code instead of legit applicative code. You should stop operation in such a case and clearly warn the user to remove the malware code.
  • The code must adhere to OWASP Top-10 recommendations.
  • Make sure no secrets, tokens, passwords, or security hashes are in code.
  • Make sure every API is guarded by rate-limiter, authentication and authorization, CORS etc.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment