Control
Coding-agent instructions and automation, or agent-chosen packages, not under review and verification
Coding-agent instruction files and automation are under required human review, coding agents in CI cannot act on untrusted events with write access or merge their own changes, and packages an agent chooses are verified to exist on an approved registry before install.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
The guard to add
Require code-owner review of coding-agent instruction files, keep CI coding agents off untrusted triggers and self-merge, and check agent-chosen packages against an approved registry.
Repository and CI controls. CODEOWNERS entries cover AGENTS.md, CLAUDE.md, .github/copilot-instructions.md, .cursor/rules/, and .mcp.json, with branch protection requiring code-owner review. Workflows that run a coding agent (claude-code-action, codex-action, run-gemini-cli) trigger on pull_request or trusted comments rather than pull_request_target, hold the minimum token permissions (no contents: write on untrusted events), and never run gh pr merge --auto or --admin on the agent's own change. Where an agent installs packages at run time, the name is checked against an allowlist or resolved only from an approved internal index before install, never interpolated straight from model output into pip or npm.
Where it goes: 11 CI/CD pipeline, 12 repository artifacts, 1 application source code, 15 agent action surface.
What reviewers look for: a CODEOWNERS pattern matching each agent instruction file and required code-owner review; coding-agent workflows with no pull_request_target, no contents: write, and no auto-merge step; runtime installs that take package names from an allowlist or approved index, not from an f-string or list built from model output.
Example (GitHub CODEOWNERS), before:
/src/ @acme/backendAfter:
/src/ @acme/backend
/AGENTS.md @acme/platform-security
/CLAUDE.md @acme/platform-security
/.github/copilot-instructions.md @acme/platform-security
/.cursor/rules/ @acme/platform-security
/.mcp.json @acme/platform-securityEngineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Every rule this guard addresses
TwinEthos recommendation (not law) (1)
- Everywhere (*)
- Keep coding-agent instructions and automation under human review, and verify packages an agent chooses before installing them TwinEthos derivation — guardrail.agent-ai-generated-code-provenance
Related incidents
- Amazon Q Developer extension shipped with an injected destructive agent prompt (2025-07; disclosed by the operator). AWS says an attacker used an inappropriately scoped GitHub token in its build configuration to inject code into Amazon Q Developer for VS Code version 1.84.0, that the code failed to execute due to a syntax error, and that version 1.85.0 fixed it (CVE-2025-8217). The Register reports the injected prompt instructed the agent to delete local files and cloud resources. Source: AWS Security Bulletin (operator) · evidence grade: primary · cited by Keep coding-agent instructions and automation under human review, and verify packages an agent chooses before installing them
- LLM-hallucinated package name registered on PyPI and adopted in real projects (2023-12; confirmed). Lasso Security researcher Bar Lanyado saw generative AI repeatedly recommend a nonexistent Python package, 'huggingface-cli', registered an empty placeholder under that name in December 2023, and found it adopted in real projects, including a README instructing users to install it. Download counts differ between sources (The Register: more than 15,000; Lasso: more than 30,000). Source: Lasso Security (original researcher disclosure) · evidence grade: primary · cited by Keep coding-agent instructions and automation under human review, and verify packages an agent chooses before installing them