frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Tell HN: Cursor agent force-pushed despite explicit "ask for permission" rules

6•xinbenlv•4h ago
I've been using Cursor with Claude as my coding assistant. I set up explicit workspace rules stating that the agent must ask for my approval before executing any git operations (git commit, git add, git push, etc.).

Today, I asked it to run gt restack (Graphite CLI) and resolve conflicts. The agent resolved the submodule conflict correctly, but then proceeded to run git push --force-with-lease --no-verify without asking for permission - directly violating my rules.

The agent's defense was reasonable ("force push is expected after a rebase"), but that's exactly why I want to be asked first. The whole point of the rule is to maintain human oversight on destructive operations.

I'm curious:

Has anyone else experienced AI agents ignoring explicit safety rules? How are you handling guardrails for potentially destructive operations? Is there a more reliable way to enforce these boundaries?

The irony is that the agent acknowledged the rule violation in its apology, which means it "knew" the rule existed but chose to proceed anyway. This feels like a trust issue that could have much worse consequences in other scenarios.

Comments

slau•3h ago
A few months ago, I switched to exclusively using an SSH key stored on my Yubikey token. I also recently switched to my default git config signing all commits with my SSH key. The way it’s setup means I have to touch my token every time I try to commit or push.

I typically commit everything myself—I’m still quite early in my adoption of coding agents. One of my first experience with OpenCode (which made me stop using it instantly) was when it tried to commit and force push a change after I simply asked it to look into a potential bug.

Claude Code seems to have better safeguards against this. However, I wonder how come we don’t generally run these things inside docker containers with only the current dir volume mounted or something to prevent spurious FS modifications.

I’m entirely with you that we need better ways to filter what commands these things are allowed to run. Specifically, a CLAUDE.md or “do not do this under any circumstance” as part of the prompt is a futile undertaking.

hombre_fatal•2h ago
Prompt instructions are never sufficient for this. The tool call itself needs to be gated.

With Claude Code, tools like Bash(“git *”) always ask for permission unless you’ve allowed it.

Figure out the Cursor equivalent of that.

ThePowerOfFuet•2h ago
It continues to surprise me that people continue to be surprised by this.
yellow_lead•1h ago
> The irony is that the agent acknowledged the rule violation in its apology, which means it "knew"

No, the AI never "knew" anything! :)

Testing AI orchestrated cyber attacks in practice

https://blog.fraktal.fi/testing-ai-orchestrated-attacks-in-practice-12f8fb03191e
1•tmakkonen•4m ago•0 comments

Downloading a Podcast to Create an Audiobook

https://kevinboone.me/clh_podcast_to_audiobook.html
1•LaSombra•5m ago•0 comments

Why I Don't Have Fun With Claude Code

https://brennan.io/2026/01/23/claude-code/
3•ingve•6m ago•0 comments

Why digital signatures break on structured healthcare data

https://formidable.care/articles/understanding-the-identity-integrity-gap-in-digital-signing
1•vincentxplore•8m ago•0 comments

Roleplayers

1•shoman3003•8m ago•0 comments

Faster Loading for GitHub Issues

https://github.blog/changelog/2026-01-22-faster-loading-for-github-issues/
2•ramon156•11m ago•0 comments

Web-SQLite-JS allows for the persistence of relational data on web clients [video]

https://www.youtube.com/watch?v=ZHYDv4GPprU
1•wuchuheng•14m ago•0 comments

Ask HN: Which paid apps and services do you use?

1•chistev•19m ago•0 comments

SnapHabit : Extreme habit accountability with AI and friend groups

https://snap-habit.com/
1•apollos•19m ago•0 comments

E-scooter sharing company Bird has raised $20M

https://micromobility.io/news/birds-parent-company-third-lane-mobility-raises-20m
1•prabinjoel•21m ago•2 comments

AI-Powered CSPM Tools Are Transforming Cloud Compliance

https://digimagazine.co.uk/how-ai-powered-cspm-tools-are-transforming-cloud-compliance/
1•cybleinc•24m ago•0 comments

Does AI-Assisted Coding Deliver? A Study of Cursor on Software Projects

https://arxiv.org/abs/2511.04427
2•iLoveOncall•24m ago•0 comments

Ghostty's AI Policy

https://github.com/ghostty-org/ghostty/blob/main/AI_POLICY.md
4•mefengl•27m ago•1 comments

A crowdsourced repository for optimization constants?

https://terrytao.wordpress.com/2026/01/22/a-crowdsourced-repository-for-optimization-constants/
1•jjgreen•29m ago•0 comments

Dcli: Declarative Package Management for Arch Linux (Inspired by NixOS)

https://gitlab.com/theblackdon/dcli
1•signa11•36m ago•0 comments

The new rules of the road for agentic commerce

https://www.mastercard.com/us/en/news-and-trends/stories/2026/agentic-commerce-rules-of-the-road....
1•saikatsg•37m ago•0 comments

Copilot SDK in Technical Preview

https://github.com/orgs/community/discussions/184872
1•edent•38m ago•0 comments

Google is ending full-web search for niche search engines

https://programmablesearchengine.googleblog.com/
52•01jonny01•40m ago•22 comments

Voice Layer for AI Agents Built with Rust, Pluggable to All Agentic Frameworks

https://github.com/SaynaAI/sayna
1•tigranbs•40m ago•0 comments

Raiden Warned About AI Censorship [video]

https://www.youtube.com/watch?v=-gGLvg0n-uY
1•DeathArrow•44m ago•0 comments

Show HN: Thalo – A "programming" language for structured knowledge

https://github.com/rejot-dev/thalo
3•WilcoKruijer•48m ago•0 comments

From Tomorrow Back to Yesterday: A Tale of Two Web Architectures – Yang [video]

https://www.youtube.com/watch?v=8W6Lr1hRgXo
1•adityaathalye•49m ago•0 comments

The State of Modern AI Text to Speech Systems for Screen Reader Users

https://stuff.interfree.ca/2026/01/05/ai-tts-for-screenreaders.html
1•tuukkao•53m ago•0 comments

Apple is burying the Time Capsule, but how to replace it?

https://sixcolors.com/post/2026/01/apple-is-burying-the-time-capsule-but-how-to-replace-it/
4•tosh•55m ago•1 comments

What time you should arrive at cinema to avoid adverts

https://news.sky.com/story/what-time-you-should-actually-arrive-at-cinema-to-avoid-adverts-13149863
1•austinallegro•55m ago•0 comments

Subject of Unique Interest: Mary Freeman Heuston Lewis and William Dean Howells

https://commonplace.online/article/a-subject-of-unique-interest/
1•bryanrasmussen•56m ago•1 comments

DeepSeek's mHC: Stabilizing Training Divergence from 3,000x to 1.6x

2•Research_Brief•57m ago•0 comments

How to Think About Self-Attention Intuitively

https://www.henrydashwood.com/posts/attention-intuition
1•HenryDashwood•1h ago•0 comments

Nvidia PersonaPlex: natural conversation AI

https://research.nvidia.com/labs/adlr/personaplex/
1•ricardobeat•1h ago•0 comments

Doing Gigabit Ethernet over My British Phone Wires

https://thehftguy.com/2026/01/22/doing-gigabit-ethernet-over-my-british-phone-wires/
3•user5994461•1h ago•0 comments