Skip to content

Build1 publisher2 min readPublished

A Claude Code permission rule now enforces the commit ban that 18 prompt files only requested

One developer running Claude Code on 80-plus microservices enforces a never-commit rule, once pasted into 18 prompt files, with a permission deny rule. An audit found the agent's settings file allowing the git commands those prompts banned in capitals.

The Engineer · Build desk

Illustration accompanying A Claude Code permission rule now enforces the commit ban that 18 prompt files only requested

What happened

  • One of the developer's own reference documents also held a ready-made git add && git commit snippet.
  • The main orchestrator prompt ran to 1,464 lines, all loaded at once, and one file said "DO NOT run" eight times.
  • The first fix was one rulebook with short IDs such as GIT-1 for never commit; the main instruction file fell from 370 lines to about 145.
  • Rules were then split into judgment calls, such as matching a service's existing code style, and invariants that must hold every time.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure A ban that exists only in prompt text can be contradicted by any settings entry or doc example the agent also reads, so those files need the same review the prompts get.
  • decision Before moving anything into permissions, a team has to sort its rules into invariants and judgment calls, because a style rule has no single command to deny.
  • cost Duplicated prohibitions are paid for on every turn, since the model re-reads them in place of the code it is supposed to be working on.

The post documents an audit, not an incident. "A couple of months in, I stopped trusting my own rules," the developer wrote [18]. The commit ban was the rule the author cared about most, because every diff was meant to be read before it became history, and it was the one that felt shaky [2]. The post does not report the agent committing against orders. It reports prompt text and configuration that disagreed, found by reading the configuration [3].

Until then, every failure got the same fix: another capitalised line in a prompt file. "MANDATORY. NEVER. A warning emoji, to be safe," the author wrote [19]. Copies drifted until "The model had to guess which copy was the real one" [7]. Emphasis stopped carrying any signal: "When everything is MANDATORY, nothing is" [21]. The author flags this pattern in other people's pull requests and wrote, "I would never have approved it" [20].

The rulebook is a dull refactor and a sound one. The main instruction file lost roughly 61% of its lines [1].

For the invariants, the author moved enforcement into Claude Code's permission system, and the command is now denied before it runs [10]. That takes the decision away from the model. "The model's opinion about it no longer matters," the author wrote [10]. The author's summary: "A prompt is a request. A deny rule is a wall" [11]. According to the author, the change in day-to-day behaviour was immediate [13].

The wall has a gap. A command wrapped inside another command can still slip past the matcher, so the written rule stays in place and the permission file gets checked from time to time [12]. For the result to carry over to another setup, the invariant has to be a command pattern the matcher can see in its wrapped forms too. Nothing else the agent reads, settings or examples, can allow it [4].

The support side was built on the same principle. Separate agents search logs, query MongoDB, run SQL and read metrics, and none of them can write anything [14]. Their first failure was a search problem. The log agent looked for the log text it imagined, found nothing and reported that "with complete confidence," until it was told to search the code for the real log string first [15]. Each solved incident becomes a runbook, and there are 29 [16]. The whole tech team now uses the system, along with new joiners and people who do not write code [17].

What to watch

  • Whether the author publishes the actual deny entries and the wrapped-command forms that got past the matcher.
  • Whether Claude Code's permission matcher is changed to catch commands nested inside other commands.
  • Whether the 1,464-line orchestrator prompt shrinks the way the main instruction file did after the rulebook split.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories