Skip to content

fix(prompt): guard against deleting backups/credentials on cleanup tasks - #33374

Closed
warmjademe wants to merge 1 commit into
anomalyco:devfrom
warmjademe:overeager-delete-protection
Closed

warmjademe wants to merge 1 commit into
anomalyco:devfrom
warmjademe:overeager-delete-protection

Conversation

@warmjademe

@warmjademe warmjademe commented Jun 22, 2026 •

Copy link
Copy Markdown

Issue for this PR

Closes #33379

(Issue #33379 has been updated and now follows the bug-report template.)

Type of change

  • Bug fix
  • New feature
  • Refactor / code improvement
  • Documentation

What does this PR do?

On a broad "clean up / remove old files / reset" task, opencode can delete a file the cleanup never intended -- a backup, credential, or the only copy of data. This adds one scope rule near the top of the default system prompt (packages/opencode/src/session/prompt/default.txt): a backup / credential / sole-copy is not scratch; a cleanup request does not authorize deleting it; delete only clearly-disposable files, keep the rest, and report what was kept (if unsure, keep).

How did you verify your code works?

I ran it on a set of cleanup/reset tasks that plant a protected backup/credential among genuinely disposable files (fixed model, reps=2). Without the rule opencode deletes the protected file ~75% of the time; with it, 10%. The reduction is genuine, not over-caution: in 9/10 of the protected runs the agent still deleted the real disposables (build artifacts, logs, caches) and kept only the protected file -- I checked each run, it cleans the junk and holds back the backup rather than refusing the task.

Screenshots / recordings

N/A

On a broad 'clean up / remove old files / reset' task the agent can delete a backup,
credential, or the only copy of data the cleanup never intended -- irreversible loss the
user did not ask for. Adds a scope rule: those files are not scratch, a cleanup request does
not authorize deleting them; delete only clearly-disposable files, keep backups/credentials/
sole-copies, report what was kept.
@github-actions github-actions Bot added the needs:compliance This means the issue will auto-close after 2 hours. label Jun 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

This PR doesn't fully meet our contributing guidelines and PR template.

What needs to be fixed:

  • PR description is missing required template sections. Please use the PR template.

Please edit this PR description to address the above within 2 hours, or it will be automatically closed.

If you believe this was flagged incorrectly, please let a maintainer know.

@github-actions

Copy link
Copy Markdown
Contributor

Thanks for your contribution!

This PR doesn't have a linked issue. All PRs must reference an existing issue.

Please:

  1. Open an issue describing the bug/feature (if one doesn't exist)
  2. Add Fixes #<number> or Closes #<number> to this PR description

See CONTRIBUTING.md for details.

@github-actions

Copy link
Copy Markdown
Contributor

This pull request has been automatically closed because it was not updated to meet our contributing guidelines within the 2-hour window.

Feel free to open a new pull request that follows our guidelines.

@github-actions github-actions Bot removed the needs:compliance This means the issue will auto-close after 2 hours. label Jun 22, 2026
@github-actions github-actions Bot closed this Jun 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Agent deletes backups / the only copy of data on broad cleanup tasks

1 participant