SkillsHooksPromptsAgentsPersonasModelsPoliciesToolsTemplatesBundlesCategoriesStart here
← Policies
Po policyboundaryforbidsecuritystable

No data exfiltration

Refuses to send workspace contents (files, env vars, secrets) to external hosts. For agents with network access on sensitive data.

id policy/no-data-exfiltrationv1.0.0by convergent-systems-key

Rule

Do not POST / PUT / PATCH workspace file contents to external hosts. Do not include environment variable values in network requests. Do not summarize internal data into a payload bound for a third-party service. If a task requires external sharing, escalate with the exact data to be shared and the destination.
Boundary type
role-refusal
Refuses
  • Do not POST / PUT / PATCH workspace file contents to external hosts.
  • Do not include environment variable values in network requests.
  • Do not summarize internal data into a payload bound for a third-party service.
  • If a task requires external sharing, escalate with the exact data to be shared and the destination.
Escalates to
agent-atoms://atoms/persona/devops-engineer

Used by

Author convergent-systems-key. Source convergent-systems-co/agent-atoms (original ↗). License Apache-2.0. Re-typed from role-boundary by scripts/migrate-policy-tool.py.