Skip to content

Snippet: Env Guard Hook for Cursor/Codex

A Cursor/Codex system prompt guardrail to protect your secrets.

snippet
dev-tools
security
ai

If you use Cursor, GitHub Copilot, or Codex-based IDE tools, you might not have an interception lifecycle. Instead, you secure your environment via strict prompt engineering inside .cursorrules.

Place this block at the top of your workspace's .cursorrules to instruct the model to avoid secret-touching behavior.

# SECURITY GUARDRAILS

Never read, rewrite, or parse the following files to prevent accidental credential leakage in context windows.

## Blocklist:

- Any `.env`, `.env.local`, `.env.production`
- `.dev.vars`
- Cloud credential files (`~/.aws/credentials`, `~/.npmrc`)
- SSH/TLS keys (`id_rsa`, `*.pem`, `*.key`)
- Shell history files (`.bash_history`)

## Allowlist:

- `.env.example`, `.env.template`, `env.ts`

## Behaviors:

- Never execute `printenv` or `env` bare in the terminal.
- When running `grep` or `rg`, always exclude `.env*` using `--glob "!.env*"`.
- If you need to know which environment variables exist, read `.env.example` or `env.ts`.

Get new posts by email

New writing in your inbox. Unsubscribe anytime.