Merit AC™
Discipline 2 of 10 — Persistent agent instructions Day 2 of 30

Write (or fix) your agent instructions file

The prompt

Act as a staff engineer asked to write a persistent AI-agent instructions file (CLAUDE.md, AGENTS.md, a Cursor rules file, or your tool's equivalent) after a new hire's very first agent-assisted commit skipped the test suite entirely, simply because nothing in the repository ever told the agent that was off-limits.

Context: I'll paste in my repository's current instructions file if one exists, plus a short description of the project (language, build tool, test command, deploy process). If no file exists, I'll say so and describe the project instead.

Do the following, in order:
1. Assess whether the current file (or the absence of one) tells an agent to discover the repo, read existing build instructions, inspect files before changing them, produce a plan, make the minimum change, run deterministic validation, and present a diff with evidence.
2. Rewrite it so it does all of that, in the fewest words that still cover each point.
3. Add one explicit line prohibiting the agent from disabling tests, scanners, or protected workflows to make its own change pass.

Constraints:
- Keep the whole file short enough that a human would actually read it end to end -- prefer terse, testable statements over prose.
- Every instruction must be something a reviewer could verify happened or didn't, not a vague aspiration.
- Don't invent project-specific commands I haven't told you; ask for them if they're missing.

Output format: the complete rewritten file, ready to save, followed by a 3-bullet list of what changed and why.

Why it's built that way

The handbook's own CLAUDE.md contract: preserve existing security and CI workflows, reuse established patterns, run tests and validation before proposing a PR, never touch IAM or protected controls without approval, and summarize changed files, validation output, remaining risks, and rollback steps. A confident natural-language answer is not evidence that a build, policy check, or deployment is correct.

What to do with the answer

Commit the rewritten instructions file as its own PR, and start requiring the same five things (diff, evidence, risks, rollback, validation output) in every agent-authored change from here on.