← All TILs · git

Configuring a repository for coding agents: what the guidance actually says

git - 2026-09-27

This repo is mostly written with a coding agent (Claude Code, running in a cloud session). The agent opens branches and PRs and fixes CI. After a few rounds of that I wondered whether there's any agreed guidance on how the repository should be set up for it: branch protection, CI, instructions files. The answer: yes, but it's spread across vendors, and Simon Willison's guide, which I expected to cover it, mostly doesn't.

Simon Willison: git is the safety net, not the gate

Simon's Agentic Engineering Patterns is about how you work with an agent, not how you configure the repo. The relevant chapter, Using Git with coding agents, treats git as the thing that makes mistakes cheap:

The other relevant chapter is First run the tests: give the agent a fast check it can run itself. Here that's make check.

GitHub: agents don't push to main, and don't merge

GitHub's docs for its own cloud agent read as general guidance for any agent: Building guardrails and Risks and mitigations.

Anthropic: when the agent runs inside your CI

The claude-code-action security guide covers a different case: an agent triggered by @claude comments inside GitHub Actions.

GitLab: prompt injection and identity

GitLab's security threats in agentic systems page frames things around prompt injection, a dedicated service identity for the agent, and sandboxing. Its external agents page warns that third-party agents like Claude Code don't get GitLab's built-in prompt scanning or network isolation.

What that meant for this repo

Already covered:

The gaps the guidance exposed, and what I did about each:

Created 2026-09-27T17:01:42+02:00 · Edit