diff --git a/agent/extensions/pi-automode/config.json b/agent/extensions/pi-automode/config.json index 35f9ac9..177e36e 100644 --- a/agent/extensions/pi-automode/config.json +++ b/agent/extensions/pi-automode/config.json @@ -7,14 +7,15 @@ ], "allow": [ "$defaults", - "Using standard credentials with their intended configured providers is allowed only when secret values remain hidden from the agent, command arguments, and command output. Secret injection through op run is allowed under this condition, but never with --no-masking." + "Using standard credentials with their intended configured providers is allowed only when secret values remain hidden from the agent, command arguments, and command output. Secret injection through op run is allowed under this condition, but never with --no-masking.", + "Updating agent memory systems like hindsight or other agent-owned context documents." ], "protectedPaths": [ "$defaults" ], "soft_deny": [ "$defaults", - "Block every operation that changes state in an external or remote system unless the latest user instruction directly identifies the target and requests that exact state change. This includes cloud services, APIs, databases, infrastructure, clusters, ticketing and collaboration systems, communications, CI/CD, package registries, and remote hosts. The built-in allowance for pushing the current non-default working branch or a new task branch remains permitted.", + "Block every operation that changes state in an external or remote system (except agent memory systems like hindsight) unless the latest user instruction directly identifies the target and requests that exact state change. This includes cloud services, APIs, databases, infrastructure, clusters, ticketing and collaboration systems, communications, CI/CD, package registries, and remote hosts. The built-in allowance for pushing the current non-default working branch or a new task branch remains permitted.", "Block package publication unless the user explicitly identifies the package, version, registry, and asks to publish it.", "Block destructive database statements, including DROP DATABASE and DROP TABLE, unless the user explicitly identifies the target database or table and confirms the destructive action.", "Block Terraform or OpenTofu apply and destroy unless the user explicitly identifies the environment and approves the exact infrastructure change after reviewing a plan.",