AI Summary: Defining prohibitions in
AGENTS.mdis the primary mechanism for constraining autonomous coding agents from making destructive codebase changes. High-impact negative rules must follow an operational four-part anatomy: naming the forbidden action, providing the technical justification, establishing the mandatory alternative, and defining the automated verification gate that blocks violations.
Why Vague Prohibitions Always Fail
When engineering teams write agent guidelines, they frequently include aspirational statements:
- "Be careful with database migrations."
- "Do not introduce security bugs."
- "Write efficient, clean code."
To a transformer model predicting next tokens, these statements provide zero actionable constraint. Without explicit boundaries, an autonomous agent attempting to solve an intermittent test timeout will gladly delete the test, increase socket timeouts to 300 seconds, or bypass authorization middleware to make an endpoint respond.
To effectively constrain an agent, prohibitions must be Operational and Falsifiable.
The 4-Part Anatomy of an Operational Prohibition
Every negative rule in AGENTS.md should adhere to this four-part structure:
1. FORBIDDEN ACTION ──► What specific syntax, command, or file is blocked?
2. ARCHITECTURAL REASON ──► Why was this prohibited (past production incidents)?
3. MANDATORY ALTERNATIVE ──► What must the agent do instead to achieve its goal?
4. ENFORCEMENT GATE ──► Which compiler or CI check catches violations?
Production Examples from Real-World Repositories
Case 1: Database Migration Safety
- Forbidden Action: Never run raw SQL
ALTER TABLE DROP COLUMNor drop existing foreign key constraints. - Architectural Reason: Live production traffic runs zero-downtime rolling deploys; dropping columns breaks running instances before new code finishes rolling out.
- Mandatory Alternative: Use the expand-and-contract pattern: deprecate the column in code, deploy the new reader, and drop the column in a subsequent release.
- Enforcement Gate: Validated by
pnpm prisma:checkin CI.
Case 2: Git Integrity & Branch Protection
- Forbidden Action: Never run
git push origin mainor executegit reset --hard/git clean -fd. - Architectural Reason: Overwrites developer working directory state and bypasses pull request review controls.
- Mandatory Alternative: Create a local feature branch (
round-N) and propose a review diff. - Enforcement Gate: GitHub branch protection rules require signed PRs and passing CI status checks.
Case 3: Dependency Hygiene
- Forbidden Action: Never modify
package.jsonorpnpm-lock.yamlto add new dependencies. - Architectural Reason: Prevents supply-chain bloat and hallucinated npm packages.
- Mandatory Alternative: Implement the feature using native language primitives or existing project utilities.
- Enforcement Gate: CI workflow runs with
--frozen-lockfile.
Defense in Depth: Prompts vs Physical Controls
Never treat prompt instructions as a cryptographic security boundary. A comprehensive defense-in-depth model pairs prompt guidance with physical system controls:
[Layer 1: AGENTS.md / CLAUDE.md] ──► Instructs agent on correct paths (Advisory)
│
▼
[Layer 2: Local Pre-Commit Hooks] ──► Intercepts dangerous git & shell commands (Local block)
│
▼
[Layer 3: GitHub CI & Branch Rules] ──► Enforces typechecking, tests, & PR approvals (Hard gate)
│
▼
[Layer 4: Server IAM & WAF Gates] ──► Restricts production deployment keys (Cryptographic)
Comparative Prohibition Matrix
| Ambiguous Guideline | Operational AGENTS.md Prohibition |
|---|---|
| "Don't print passwords." | "Never print environment variables or secrets to stdout. Redact all tokens in log statements using [REDACTED]." |
| "Keep components clean." | "Never import @/lib/db.server into client components. Keep database queries strictly in Server Actions or route handlers." |
| "Don't skip tests." | "Never add .skip() or comment out assertions. If a test fails, fix the code under src/ until assertions pass." |
| "Avoid big diffs." | "Never reformat untouched files or apply global prettier runs. Restrict edits strictly to lines required by the prompt." |
Related guidance
To design portable rules, read AGENTS.md Best Practices, study test enforcement in Testing Conventions for Agents, and learn context mapping in Codebase Context Strategies.
References
- The AGENTS.md Standard: Community specifications for machine-readable agent instructions and boundary rules.
- GitHub: Managing Branch Protection Rules: Physical repository enforcement for code changes.
Need to optimize your entire site for AI search visibility? Run a comprehensive audit with Geolify.ai.