Scope the tool, not the prompt. Permissions come from keys, not instructions
grep -rnP "[\x{200B}-\x{200F}\x{2060}\x{FEFF}]" .cursor/ . claude/ CLAUDE. md . mcp. json 2>/ dev/ nullcat . claude/ settings. json | grep -A20 '"allow"'
Get every Fix AI Slop Code episode
The code it wrote, the code it should have written and a check, for every episode
What is going on
"Do not deploy" in a prompt is a request. A token that cannot deploy is a rule. Any safety that lives in instruction text can be overridden by a later instruction, a poisoned rules file, or the model deciding the instruction did not apply this time.
Where it bit
A bare wrangler deploy from the worker folder redeployed the whole site, because wrangler walks up the tree and found the site's config first. Fixed by pinning -c wrangler.toml in the npm script, so the wrong command is no longer possible to type. The cron in 09 is the same lesson. Our operating rule is written as "keys, not prompts" for this reason.
The practice
Tool allowlists per agent role. Scoped, expiring tokens per agent. Deploy commands that fail without an explicit config path. Rules files and .mcp.json diffs reviewed as code, with a grep for zero-width characters, because poisoned rules are now a documented attack on four coding agents.
Get this check as a script you can run tonight

The coding agent never holds production credentials
An agent with a production database URL will sooner or later run a migration or a cleanup against it, so production secrets never enter its env
Keys go in headers, never in URLs
A URL is written to server logs, CDN logs, browser history and error trackers, so an API key in a query string is a key in five places
Backups the app cannot reach, and one restore you have actually done
A backup on the same account the app or an agent can delete from is not a backup, and a restore you have never run is a number you do not have
If this check came back with more than you expected, that is worth a conversation