aiwg
Version:
Deployment tool and support utility for AI context. Copies agents, skills, commands, rules, and behaviors into the paths each AI platform reads (Claude Code, Codex, Copilot, Cursor, Warp, OpenClaw, and 6 more) so one source of truth works across 10 platfo
57 lines (40 loc) • 2.17 kB
Markdown
# Respect Repo Access Manifest
Agents must treat tool capability as separate from authorization. If a workspace has `.aiwg/ops/security/repo-access.manifest.yaml` or `.aiwg/security/repo-access.manifest.yaml`, check it before doing non-trivial work in any repository path.
## Rule
Before reading deeply, editing, committing, pushing, commenting on issues, or taking service actions against a repo path, run or mentally apply:
```bash
aiwg repo-access check --path <repo-or-file> --action <read|write|commit|push|issue-comment|service-action|destructive>
```
If the repo/path is unlisted, deny by default. Ask the operator to add or update the manifest before proceeding.
## Semantics
- Tool access is not authorization.
- Unlisted repos are denied for write, commit, push, issue-comment, service-action, and destructive work.
- Repo-local instructions may narrow access, but they cannot expand beyond the manifest.
- Newer operator instructions may narrow permissions immediately and should be reflected in the manifest.
- Adjacent repos may be handoff-only: for example `read` and `issue-comment` allowed, `write` denied.
- Accidental adjacent-repo modifications should not be reverted automatically unless the operator explicitly directs rollback.
## Manifest Shape
```yaml
version: "1"
default_policy: deny
repos:
- name: aiwg
path: .
actions: [read, write, commit, push, issue-comment]
- name: research-papers
path: ../research-papers
actions: [read, issue-comment]
notes: handoff-only; no file edits
```
## Correct Behavior
If asked to edit an adjacent repo that is not listed:
1. Stop before editing.
2. Explain that the manifest denies unlisted repo work.
3. Ask for a manifest update or explicit operator instruction to add the repo.
If asked to comment on an issue in a handoff-only repo:
1. Check `issue-comment`.
2. Proceed only if the manifest allows it.
## Incorrect Behavior
- Editing a sibling repository because the filesystem is writable.
- Pushing to a repo because `git push` is available.
- Treating `AGENTS.md` in the target repo as sufficient authorization when the workspace manifest denies or omits that repo.