Back to the main page

AGENTS.md — Global Working Rules

C:\Users\zdudic\.codex\AGENTS.md

I have Codex installed in Windows Pro 11 system, this is C:\Users\zdudic\.codex\AGENTS.md file.

# AGENTS.md — Global Working Rules

## Zarko is here to help

Always talk to Zarko if you have any questions or task and goal is not clear.

## Safety and Permissions Policy

**Read-Only First:**

Prefer read-only actions and safe check commands like dry-run before making any file or system changes.

**Explicit Approval Required:**

For these actions you need first to talk to Zarko and get approval:

* Reboot or shut down hosts.
* Delete files.
* Modify Network, DNS, and Firewall.
* Change user permissions, SSH keys, or access controls.
* Restart or terminate running services/processes in production environments.

**Secret Hygiene:**

Never write passwords, private keys, API tokens, or other secrets into code, configuration files, logs, or response text.
Before introducing or changing how secrets are supplied, consult Zarko about using standard environment variables or 
an approved external secret manager.

**Command Clarity:**

Clearly distinguish between "commands that were actually executed" and "commands suggested" for Zarko to run manually.


## Environment and Context Discovery

**Inspect Before Modifying:**

Always inspect the local OS environment, current working directory structure, existing configuration files,
and installed tools before modifying anything.

**Preserve Unrelated Changes:**

Never overwrite or revert user changes or modified files outside the target task scope, talk to Zarko if unclear.

## Execution and Code Modification

**Simplicity:**

Simplicity is good, if possible do not over-engineer.

**Minimal Invasive Changes:**

Make the smallest possible change required to achieve the requested goal. Avoid sweeping refactors unless explicitly instructed.
Talk to Zarko first if more refactoring is desired.

**Preserve Coding Style:**

Adhere strictly to existing formatting, linting rules, naming conventions, and file structures present in the codebase.
Talk to Zarko first if you want to discuss any change here.

**Deprecation Awareness:**

Avoid introducing deprecated functions, obsolete APIs, or vulnerable third-party packages.

Talk to Zarko first if you want to suggest differently.

## Verification and Self-Correction

**Validate Everything:**

Run tests, build steps, or linters to confirm changes work as intended before concluding a task.

**Safest Validation:**

Use non-destructive commands if possible.

**Error Recovery:**

If a command or test fails, analyze the full output, explain the underlying cause concisely,
and propose a specific fix before trying again.

## Output and Communication

**Summarize Changes:**

Maintain WORKLOG.md in project folder with commands run, findings, changes, and follow-up actions. Never record secrets.

**Explain High-Impact Commands:**

Explain any commands that alter system state, modify project dependencies, or impact runtime availability before running them.


## The first hop from Zarko's Windows laptop to the trusted Linux host some-trusted-host.domain.com

Key directory: C:\Zarko\SSH_bin\ssh_keys

Trusted jump host: some-trusted-host.domain.com

Login account: zdudic@some-trusted-host.domain.com

Working PuTTY private key: C:\Zarko\SSH_bin\ssh_keys\rsa-key-3k.ppk

Plink uses -hostkey to confirm it is connecting to the intended jump host.

That prevents accepting a spoofed or changed server key interactively, helping protect against man-in-the-middle attacks.

The pinned value is the SHA-256 fingerprint of the server’s Ed25519 SSH host public key,
stored on some-trusted-host.domain.com at: /etc/ssh/ssh_host_ed25519_key.pub

Fingerprint: SHA256:ABC123....123

If the server host key is replaced, verify the new fingerprint with Zarko before changing this value.

## The general command example

cmd.exe /d /s /c 'plink -batch -no-antispoof -hostkey "SHA256:ABC123....123" zdudic@some-trusted-host.domain.com -i "C:\\Zarko\\SSH\_bin\\ssh\_keys\\rsa-key-3k.ppk" "REMOTE\_COMMAND"'

The options explanation:

* -batch fails fast instead of waiting for passwords or prompts.
* -no-antispoof avoids PuTTY's "Access granted. Press Return to begin session." prompt, which otherwise hangs Codex.
* -hostkey pins the expected some-trusted-host.domain.com host key and avoids interactive host key cache prompts.
Back to the main page