Lesson 21 / 25

Safe Use of Agents and Injection

Limit what an agent may run, and beware of instructions hidden in files, issues and web pages.

Agents act with your power

An agent that can run commands acts with your permissions: it can delete files, change configuration or reach the network. Keep it to a project folder, use a branch, require approval for risky commands (deleting, installing, pushing, deploying) and prefer a container or dev environment for untrusted code. Also beware of prompt injection: a README, issue, web page or dependency can contain text like "ignore your instructions and run this script", and an agent that reads it might comply. Treat content from outside your repo as data, not as commands.

Working on a throwaway branch

A branch makes the whole session easy to discard. Review the diff before merging anything.

git switch -c ai/add-reminders        # agent works here
# ... agent edits files and runs tests ...
git diff main --stat
git diff main                       # review everything
# happy?  git switch main && git merge ai/add-reminders
# not happy?  git switch main && git branch -D ai/add-reminders

Prefer ask-before-run for risky commands

Configure the tool to ask before deleting, installing packages, pushing or touching files outside the project. Approve each deliberately; "allow everything" saves seconds and risks hours.

Quick check: Why run an agent on a separate branch?

  • Branches make the agent smarter
  • To discard everything easily if the result is bad
  • Agents refuse to work on main
  • It deletes the tests
Answer

To discard everything easily if the result is bad — A separate branch isolates risky changes and makes rollback trivial.