给编程智能体加一份 ask first 清单,而不只是 never 清单
原文标题:Give your coding agent an "ask first" list, not just a "never" list
作者提出智能体配置不应只有允许和禁止两档,而应增加 ask first 中间档,用于推送远端、非本地数据库的 schema 迁移、安装新依赖、修改 CI 或部署配置这类需要先停下说明命令的操作。
当前语言的正文正在等待翻译,暂时显示原文。
Most agent configs have two modes: things the agent may do, and things it must never do. Real work needs a third bucket: ask first.
A flat deny-list is too blunt. Ban git push outright and the agent can't finish a branch you actually wanted pushed. Allow it silently and one bad loop rewrites shared history. The middle bucket fixes that.
A three-bucket layout for AGENTS.md
## Never
- Invent secrets, API keys, or env var values
- Force-push or rewrite shared history
- Delete data outside the working tree
## Ask first (stop and describe the command)
- Any push to a remote
- Schema migrations against a non-local database
- Installing a new dependency
- Changing CI or deploy config
## Fine without asking
- Edit files in the working tree
- Run the test suite and linters
- Read logs and local docs
Keep each bucket under ten lines. When a line needs a paragraph of explanation, move it into a scoped Cursor rule (.cursor/rules/*.mdc) that only loads for the matching paths.
Why it works
- The agent fails closed on irreversible actions without stalling on everyday ones.
- Reviews get shorter: anything surprising should have triggered an "ask first" stop, so you know where to look.
- New teammates read the same three lists and learn the house rules in a minute.
Vildanden's free Agent Config sample ships with this split for a Next.js-leaning repo:
来源:DEV Community · Cursor · dev.to