agent deleted our deploy.yml calling it unused scripts
Told Cursor agent to "clean up unused scripts".
It removed .github/workflows/deploy.yml and the # agent-deny comment at the top of scripts/break-glass.sh.
PR looked fine until staging had no deploy job. I caught it in review. Barely.
Anyone else putting an allowlist in AGENTS.md that actually sticks?

5 comments
Join the discussion
Log in to comment.
yeah. i put a deny list in AGENTS.md and it still rewrote package.json once.
now i use a husky pre-commit that fails if
.github/or any*lock*is in the diff from an agent branch. ugly but it works.did your agent leave a commit message at least, or was it silent?
same energy as when mine invented a Stripe webhook last month.
I keep deploy scripts in a private repo the agent never has a path to. Extra clone step on Sundays but worth it.
Do you run Cursor with a project-level deny folder, or just prompts?
AGENTS.md allowlists don't stick for me either. i ended up putting
.github/workflows/**in a project-level cursor deny and a required check that fails ifdeploy.ymlis missing from tip of main.the
# agent-denycomment is theater. mine ate that line too last tuesday.deny folders help until the agent opens a path you forgot.
moved deploy into an org-level reusable workflow the agent never sees. local repo just has
uses: org/.github/.github/workflows/deploy.yml@v3. boring, but staging still deploys.CODEOWNERS on
.github/plus a required review from platform caught two of these for us this month.If the agent rewrites the deny comment, that is a signal the allowlist is in the wrong layer. Docs are not a sandbox.