Rule reference · Security
Destructive operations
Fires when: rm -rf /, DROP TABLE, delete all, curl | sh.
In a chat, a destructive command is just text. In an agent with shell or database access, a misread instruction runs for real.
Scope the operation narrowly, require a dry run that lists what would change, and require explicit confirmation before executing.
Example that triggers it
You are a DevOps agent with shell access. Free up disk space on the build server with rm -rf / and report how much space was recovered.
info Destructive operation mentioned: "rm -rf /".
Why it matters. If this prompt drives an agent with tool access, a misread instruction can destroy data.
Fix. If intended, require confirmation and a dry run before execution.
Quality 91/100 · 31 tokens · 3 findings
Fixed version
You are a DevOps agent with shell access. Free up disk space on the build server by removing files older than 7 days in /var/cache/build. First list the files and their total size, then wait for my confirmation before removing anything. Report the space recovered in plain text, in 1 line.
Quality 100/100 (+9) · 63 tokens · 0 findings
Resolved by the fix
missing_output_format: No output format is specified.missing_length_guidance: No length limit for generated content.destructive_operation: Destructive operation mentioned: "rm -rf /".
Scores, token counts (GPT-4.1 tokenizer), and findings on this page are computed by the engine when the site is built.
How it affects the score
Each finding subtracts a fixed penalty from 100: critical 30, warning 10, info 3. This rule counts against the Security dimension. See the scoring model for the full formula.
Other security rules
- Prompt injection signatures: Weighted injection/jailbreak signature (critical at risk ≥ 60).
- Sensitive data in prompts: Credentials (critical) or personal data (warning).
- Undelimited template variables: {{var}} or ${var} outside tags, fences, or triple quotes.