Essential File Blocking for AI Coding Assistants: A Practical Security Checklist

AI coding assistants present a new security challenge: they read directly from your local filesystem, not just from your version-controlled repository. This means files protected by .gitignore from being pushed to GitHub remain accessible to the agent running on your machine.
Key Files to Block
Based on a Node/Firebase setup audit from the Reddit discussion, these are the critical files that should be blocked from AI coding assistants:
- AI Assistant Configs:
~/.claude/settings.json(contains MCP server API keys),~/.cursor/mcp.json - Service Credentials:
~/.npmrc(npm token for publishing packages), Firebase service account JSON files (with full project access),~/.config/gcloud/application_default_credentials.json(GCP credentials),~/.git-credentialsand~/.netrc(Git HTTPS tokens) - Common Oversights:
~/.ssh/id_*(SSH private keys),~/.bash_history(may contain pasted tokens),.envand.env.*files (gitignore doesn't protect from local agents), test files with hardcoded keys,.git/config(may contain HTTPS tokens),/proc/<pid>/environ(environment variables from running processes) - CI/CD Secrets: GitHub Actions, Vercel, and other CI/CD secrets that may appear in logs if echoed
Server-Specific Concerns
The discussion notes that on servers, additional files become vulnerable:
/etc/environment(global environment variables)/etc/ssl/private/*(TLS certificates)- Database configuration files with connection strings containing passwords
/var/log/*(logs that may accidentally contain tokens)- Crontabs with inline secrets in scheduled commands
The core issue highlighted is that traditional Git-based security measures like .gitignore don't protect against AI agents reading local files. Developers need to implement explicit blocking for sensitive files that AI coding assistants might access during their operation.
📖 Read the full source: r/ClaudeAI
👀 See Also

Claude's Security Review Command Has Limitations for Production Systems
A developer found Claude's security review command helpful for basic validation like MIME types and file size limits, but insufficient for production hardening against sophisticated threats. The solution required a two-week architectural overhaul separating file processing into a restricted worker with limited permissions.

Threat data from 91K AI agent interactions: Tool abuse up 6.4%, new multimodal attacks
Analysis of 91,284 AI agent interactions from February 2026 shows tool/command abuse increased 6.4% to 14.5%, with tool chain escalation as the dominant pattern. RAG poisoning shifted to metadata attacks (12.0%), and multimodal injection via images/PDFs emerged at 2.3%.

Secure Administrator Approval Flow for Group-Chat Assistants Against Prompt Injection
A practical approach to secure LLM assistants in shared group chats: pausing VM, OAuth, and code execution tools until admin approves via a timed link.

Claude Code Plugin Bug Causes CPU Spikes and Battery Drain
A user discovered that Claude Code's Telegram plugin spawns multiple bun.exe processes that run at 100% CPU even with the laptop lid closed, causing rapid battery drain. The processes survive sleep/wake cycles and require specific cleanup steps to remove.