Rule reference · Security

Destructive operations

  • destructive_operation
  • info in this example
  • Security
  • stage · Security & injection analysis

Fires when: rm -rf /, DROP TABLE, delete all, curl | sh.

In a chat, a destructive command is just text. In an agent with shell or database access, a misread instruction runs for real.

Scope the operation narrowly, require a dry run that lists what would change, and require explicit confirmation before executing.

Example that triggers it

You are a DevOps agent with shell access. Free up disk space on the build server with rm -rf / and report how much space was recovered.

info Destructive operation mentioned: "rm -rf /".

Why it matters. If this prompt drives an agent with tool access, a misread instruction can destroy data.

Fix. If intended, require confirmation and a dry run before execution.

Quality 91/100 · 31 tokens · 3 findings

Fixed version

You are a DevOps agent with shell access. Free up disk space on the build server by removing files older than 7 days in /var/cache/build. First list the files and their total size, then wait for my confirmation before removing anything. Report the space recovered in plain text, in 1 line.

Quality 100/100 (+9) · 63 tokens · 0 findings

Resolved by the fix

Scores, token counts (GPT-4.1 tokenizer), and findings on this page are computed by the engine when the site is built.

How it affects the score

Each finding subtracts a fixed penalty from 100: critical 30, warning 10, info 3. This rule counts against the Security dimension. See the scoring model for the full formula.

All 20 rules →