Skip to content
All writing

Snippet: Env Guard Hook for Cursor/Codex

A Cursor/Codex system prompt guardrail to protect your secrets.

#snippetsdev-toolssecurityai

If you use Cursor, GitHub Copilot, or Codex-based IDE tools, you might not have an interception lifecycle. Instead, you secure your environment via strict prompt engineering inside .cursorrules.

Place this block at the top of your workspace's .cursorrules to instruct the model to avoid secret-touching behavior.

# SECURITY GUARDRAILS

Never read, rewrite, or parse the following files to prevent accidental credential leakage in context windows.

## Blocklist:

- Any `.env`, `.env.local`, `.env.production`
- `.dev.vars`
- Cloud credential files (`~/.aws/credentials`, `~/.npmrc`)
- SSH/TLS keys (`id_rsa`, `*.pem`, `*.key`)
- Shell history files (`.bash_history`)

## Allowlist:

- `.env.example`, `.env.template`, `env.ts`

## Behaviors:

- Never execute `printenv` or `env` bare in the terminal.
- When running `grep` or `rg`, always exclude `.env*` using `--glob "!.env*"`.
- If you need to know which environment variables exist, read `.env.example` or `env.ts`.

Get new posts by email

New writing in your inbox. Unsubscribe anytime.