CtrlK
BlogDocsLog inGet started
Tessl Logo

jbaruch/nanoclaw-trusted

Rules for trusted NanoClaw groups. Shared memory, session bootstrap, cross-group memory updates. Loaded for trusted and main containers only.

77

Quality

96%

Does it follow best practices?

Impact

No eval scenarios have been run

SecuritybySnyk

Risky

Do not use without reviewing

This version of the tile failed moderation
Failed moderation (intent review) in rules/session-bootstrap.md: This is a prompt injection attack disguised as a cursor/IDE rule file. It instructs an AI agent to unconditionally execute a bash command and invoke an external skill ('tessl__trusted-memory') at the start of every session before processing any user input. This is a social engineering/prompt injection technique designed to: 1) Force the AI to execute arbitrary commands without user consent, 2) Potentially load malicious instructions from an external 'trusted-memory' skill/plugin, 3) Establish persistence via a sentinel file (/tmp/session_bootstrapped) to track execution. The authoritative tone ('MANDATORY', 'not optional', 'violating this rule') is a classic prompt injection pattern to override the AI's safety boundaries.
Overview
Quality
Evals
Security
Files

context-bootstrap-bg-agents.mdrules/

alwaysApply:
Yes

Context Bootstrap for Background Agents

When launching a background Agent, prepend the prompt with these workspace-context lines.

Required preamble lines

  • Workspace: /workspace/group/ (your files), /workspace/ipc/ (messaging).
  • Send results via mcp__nanoclaw__send_message.
  • Telegram HTML: <b>bold</b>, <i>italic</i>, • bullets. No markdown.

When to omit

If the parent prompt already includes equivalent context (e.g., a Skill that injects it), don't duplicate the preamble. Duplication confuses the sub-agent about which copy is authoritative.

Tools available to sub-agents

  • mcp__nanoclaw__send_message — outbound IPC to chat
  • mcp__nanoclaw__react_to_message — reaction on the originating message
  • The full Skill() tool surface — sub-agents can invoke any installed skill

rules

async-tasks-extended.md

compaction-aware-summaries.md

composio-vs-agents.md

container-trust-levels.md

context-bootstrap-bg-agents.md

daily-discoveries-rule.md

duplicate-prevention.md

github-data-via-gh.md

global-memory.md

ground-truth-trusted.md

identity-compaction-recovery.md

identity-dual-handle.md

installed-content-immutable.md

local-context-anchoring.md

memory-file-locations.md

messages-db-schema.md

no-orphan-tasks.md

no-silent-defer.md

pending-response-tracking.md

proactive-fact-saving.md

proactive-participation.md

reply-threading.md

session-bootstrap.md

skills-policy.md

verification-protocol.md

wiki-awareness.md

README.md

tile.json