cd /news/ai-agents/i-wrote-my-agent-s-rules-for-months-… · home › topics › ai-agents › article
[ARTICLE · art-142575] src=dev.to ↗ pub= topic=ai-agents verified=true sentiment=· neutral

I wrote my agent's rules for months. Nobody loaded them.

A developer who runs multiple AI coding agents audited their rules setup and found that a hand-written "constitution" of agent rules was never actually loaded by any agent, that the rules folder was not under version control, and that one agent's global config had duplicated and drifted from the original rules. The developer packaged the resulting read-only audit ritual — which requires fresh command output for any claim about the setup and reports PASS, WARN or FAIL with evidence — as a free SKILL.md skill that runs on Claude Code, Codex, OpenCode and similar agents.

by read3 min views5 publishedSep 30, 2026

I run a few AI coding agents daily, and I treat them more like servers than like chat windows. Rules files, memory, skills, a home lab, git for everything. Last week I finally audited that whole setup properly, and the first finding was embarrassing.

I have a constitution. One file with the rules my agents are supposed to follow: how they handle secrets, when they must show evidence, what counts as "done". I wrote it by hand over weeks and I thought it was load-bearing.

It turned out nobody loaded it.

Not the identity file. Not the per-agent config files. Not the project instructions. The constitution existed as a nice document on disk while every agent I use was running on different, older, mostly thinner rules. Months of careful policy, zero enforcement. If my agent had broken one of those rules last month and I'd checked, I would have found out the rule was decoration.

Two more things came out of the same audit. The folder with my rules was not in git at all, so one bad delete and the constitution becomes folklore. And one agent's global config had started duplicating chunks of the constitution into itself. Two copies, edited separately, drifting apart. Nobody notices that until two agents answer the same request differently.

Here is the part that I think generalizes. Written rules feel like control. But between "the rule is written" and "the model actually sees this rule at the moment it decides" there is a chain of wiring: which files load, in what order, on which machine, for which tool. That chain rots quietly. You only find out when it matters. It is the same bug as a security policy that was never deployed, except with agents most people never even check.

So I made the check a ritual. For every claim about my setup, like "rules are loaded" or "memory is healthy", the answer must come from a command I ran right now, not from what I remember. If there is no fresh output, the honest answer is UNKNOWN, not "probably fine". The audit is read-only by default, findings are PASS, WARN or FAIL with the evidence attached, and every fix goes through an approval first. It also tests behavior, not just files: can the agent be talked into skipping its own safety gates, can prompt injection smuggle a command past it, will it fabricate a passing result if it's under pressure.

I packaged the ritual as a SKILL.md that runs on Claude Code, Codex, OpenCode and similar agents, not just my stack. It is free, security-scanned on Agensi, and the source is on GitHub if you want to read it before you run it. Do run it. If your agent is important enough to have rules, it is important enough to check that the rules are actually in the room.

What I am doing on this blog: agent reliability, evidence over vibes, and building a one-person product in public with real numbers. The numbers start at zero, and I will show them anyway, because that part is the interesting part.

If you have a setup where agents follow written rules, or if you tried this audit on yours, I would like to hear how it went. Comments work fine.

── more in #ai-agents 4 stories · sorted by recency
── more on @claude code 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/i-wrote-my-agent-s-r…] indexed:0 read:3min 2026-09-30 · —