ironcurtain: Instructions file for GitHub Copilot

.github/instructions/security-boundary.instructions.md

ironcurtain security-boundary.instructions.md is an instructions file for GitHub Copilot from provos/ironcurtain. It costs 747 tokens per session, scanned A, original, Apache-2.0.

A set of review rules for the security boundary, the code that decides whether an AI tool call may proceed, must be refused, or needs human review.

In plain words
What is it for?
Use it to review tool-call routing, argument normalization, allow/deny/escalate decisions, audit logging, and symlink-safe file path checks.
Why use it?
It helps prevent tool calls from bypassing policy checks, missing audit records, mishandling escalation, or accessing files through unsafe paths.

Instructions file for GitHub Copilot

Written for GitHub Copilot: a Copilot instructions file.

This is provos/ironcurtain's own configuration. It tells GitHub Copilot how to work on ironcurtain itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything ironcurtain configures →

Reuse

Borrowing it

Nothing to install: this file belongs to provos/ironcurtain. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/provos/ironcurtain/master/.github/instructions/security-boundary.instructions.md
Clone the repo
git clone --depth 1 https://github.com/provos/ironcurtain

Made for: GitHub Copilot.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ironcurtain security-boundary.instructions.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/provos/ironcurtain/security-boundary.svg)](https://agentmods.dev/instructions/provos/ironcurtain/security-boundary)
Your own site
<a href="https://agentmods.dev/instructions/provos/ironcurtain/security-boundary"><img src="https://agentmods.dev/badge/instructions/provos/ironcurtain/security-boundary.svg" alt="Measured on agentmods" height="20"></a>
Per session 747 This file is loaded in full into every session.
When invoked 747 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00747 $0.00747
Opus 5 $0.00374 $0.00374
Sonnet 5 $0.00149 $0.00149
Haiku 4.5 $0.00075 $0.00075

Measured 6d ago against content hash a249619777e0, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

ironcurtain security-boundary.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/instructions/security-boundary.instructions.md · 35 lines

How it starts

The opening of the file, as written. The whole thing — 35 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Security Boundary Review Rules

Files in src/trusted-process/ form the security kernel of IronCurtain. Every change here requires careful review against these invariants.

Mandatory Checks

  • Every tool call must pass through ToolCallCoordinator.handleToolCall() (which invokes the handleCallTool pipeline in tool-call-pipeline.ts). Look for code paths that bypass the coordinator or route directly to proxy subprocesses.
  • prepareToolArgs() must be called to normalize arguments before policy evaluation. Raw request.arguments must not be passed to policyEngine.evaluate().
  • Audit logging must occur for every tool call outcome. Verify no code path exits without calling the audit log. The single AuditLog instance lives in the coordinator — proxy subprocesses do not write audit entries.
  • The three-state decision (allow | deny | escalate) must be fully handled. Check switch statements and if/else chains for missing escalate handling.
  • Path operations must use resolveRealPath() from src/types/argument-roles.ts, not raw path.resolve(). The symlink resolution is security-critical.
  • isWithinDirectory() must use resolvedDir + '/' in the startsWith() check. Without the trailing slash, /tmp/sandbox-evil would match /tmp/sandbox.
  • Protected path checks must resolve both sides through symlinks before comparison.
  • The SERVER_CREDENTIALS env var must be deleted from process.env immediately after parsing to prevent child process inheritance.
  • Error paths in the auto-approver must return escalate, never approve. The auto-approver can never return deny.
  • The circuit breaker (inside the coordinator) must run AFTER policy evaluation to ensure every call is audited.
  • Trust-boundary validation: at every point where data crosses into the kernel from untrusted or out-of-process sources (file-IPC escalation responses, subprocess JSON, parsed config, env vars), runtime-validate every field you read. TypeScript as casts are erased at runtime and provide no security guarantee. Fail closed — unrecognized values must deny, never fall through to approve.
  • Authoritative over derived: classify a response's outcome (allow / deny / escalate / error) from the authoritative decision field (e.g., _policyDecision.status), not from substring matching on human-readable error text. Text matching silently breaks when a new producer writes a message that doesn't match the expected prefixes.
  • Audit completeness: every early return from handleCallTool must write an audit entry first. Silent early returns (unknown-tool, missing-annotation, internal errors) hide routing bugs, annotation drift, and unknown-tool probes from audit review.
  • Populated-in-production check: optional fields used in security decisions (e.g., resolvedSandboxConfigs for AuditEntry.sandboxed and [SANDBOX BLOCKED] annotation) must be actually populated by every production wiring path, not just theoretically populatable. Verify with an end-to-end test that exercises the full wiring, not just unit tests with hand-built inputs.

Read the full file on GitHub · 35 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 35 lines · 747 tokens per session scan A a249619777e0

Subscribe to this mod's changes

ironcurtain security-boundary.instructions.md is an instructions file published in the GitHub repository provos/ironcurtain (601 stars, last pushed yesterday), licensed Apache-2.0. It adds 747 tokens to every session, about $0.0037 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens