House Rules
Secrets Stay Secret
Agents can't write over your keys and environment files, and never repeat a secret back.
by PeregriniTrusted publisherversion 1 · 0 accounts running it
What it does
- Stops writes to files matching **/.env*.
- Stops writes to files matching **/*.pem.
- Stops writes to files matching **/*.key.
- Stops writes to files matching ~/.ssh/**.
- Stops writes to files matching ~/.aws/**.
- Tells every agent, when its session starts: "Never print, paste or send the value of a secret, key or token, even to your user. Name the file it is in instead."
Peregrini chose this publisher. It has not checked each rule. A book cannot vary the Mandate, and no instruction in it permits anything the Mandate reserves to your own permission lines. Its blocks are added to yours: where two books block different things, both apply. Where its instructions conflict with your own, the agent says so and asks.
The exact lines
no-write **/.env* no-write **/*.pem no-write **/*.key no-write ~/.ssh/** no-write ~/.aws/** instruction Never print, paste or send the value of a secret, key or token, even to your user. Name the file it is in instead.
Version fingerprint
65313c186ce771ac3023beb50817624a913b2041d1947506063ca5f163bf1baf
Versions
Version 1 · 28 September 2026
A starter book by Peregrini.
Added: no-write **/.env* · no-write **/*.pem · no-write **/*.key · no-write ~/.ssh/** · no-write ~/.aws/** · instruction Never print, paste or send the value of a secret, key or token, even to your user. Name the file it is in instead.