Agents and checks · 17 of 20

Scope the tool, not the prompt. Permissions come from keys, not instructions

Hit in our code
Check it
grep -rnP "[\x{200B}-\x{200F}\x{2060}\x{FEFF}]" .cursor/ .claude/ CLAUDE.md .mcp.json 2>/dev/nullcat .claude/settings.json | grep -A20 '"allow"'
Free, no call

Get every Fix AI Slop Code episode

The code it wrote, the code it should have written and a check, for every episode

Free, straight to your inbox. No call, no pitch

What is going on

"Do not deploy" in a prompt is a request. A token that cannot deploy is a rule. Any safety that lives in instruction text can be overridden by a later instruction, a poisoned rules file, or the model deciding the instruction did not apply this time.

Where it bit

A bare wrangler deploy from the worker folder redeployed the whole site, because wrangler walks up the tree and found the site's config first. Fixed by pinning -c wrangler.toml in the npm script, so the wrong command is no longer possible to type. The cron in 09 is the same lesson. Our operating rule is written as "keys, not prompts" for this reason.

The practice

Tool allowlists per agent role. Scoped, expiring tokens per agent. Deploy commands that fail without an explicit config path. Rules files and .mcp.json diffs reviewed as code, with a grep for zero-width characters, because poisoned rules are now a documented attack on four coding agents.

Free, no call

Get this check as a script you can run tonight

Free, straight to your inbox. No call, no pitch

What to do with this

If this check came back with more than you expected, that is worth a conversation

Book a free 30-minute call