No data exfiltration
Refuses to send workspace contents (files, env vars, secrets) to external hosts. For agents with network access on sensitive data.
id policy/no-data-exfiltrationv1.0.0by convergent-systems-key
Rule
Do not POST / PUT / PATCH workspace file contents to external hosts. Do not include environment variable values in network requests. Do not summarize internal data into a payload bound for a third-party service. If a task requires external sharing, escalate with the exact data to be shared and the destination.
- Boundary type
role-refusal- Refuses
- Do not POST / PUT / PATCH workspace file contents to external hosts.
- Do not include environment variable values in network requests.
- Do not summarize internal data into a payload bound for a third-party service.
- If a task requires external sharing, escalate with the exact data to be shared and the destination.
- Escalates to
agent-atoms://atoms/persona/devops-engineer
Used by
- agent/runbook-executor — Runbook Executor
- agent/safe-by-default — Safe-by-Default Agent Template
Author convergent-systems-key. Source convergent-systems-co/agent-atoms (original ↗). License Apache-2.0. Re-typed from role-boundary by scripts/migrate-policy-tool.py.