.embedderignore at the project root to restrict direct agent edits to selected files. Embedder can still read, search, and reference matching files.
.embedderignore
Write patterns
Patterns use gitignore-style syntax:vendor/matches a directory and its contents.*.binmatches that suffix at any depth.src/**/*.hmatches headers belowsrc./buildanchors the match to the directory containing the rule file.!config/public.jsonallows a path after an earlier restriction.#starts a comment; blank lines are ignored.
Use rules for one package
A nested.embedderignore applies below its directory:
packages/legacy/.embedderignore
Understand the boundary
Matching paths remain readable. Direct edits and recognized shell writes to them are blocked, even with Skip all approvals enabled. A build system, custom program, or script can write files without the restriction identifying every destination. Commands you enter yourself through the terminal UI’s! mode are also outside this restriction.
Use operating-system permissions or a separate controlled environment if you need to prevent all writes by other programs.
Permit an intended edit
Narrow or remove the matching rule, or add an appropriate exception. Changes to.embedderignore apply without restarting the conversation.
There is no one-time approval that bypasses a matching rule. Ask Embedder to explain the blocked path before changing the restriction.
Troubleshoot
- A protected file is still visible: expected; the restriction applies to edits.
- A rule does not match: check the active project root, relative path, and nested overrides.
- A build changed a file: the build may write beyond the recognized direct-edit forms.
- An alias is blocked: rules also apply to the resolved target of a symbolic link.

