vibehacker
Discuss
Devon
7 hours ago

agent deleted my stripe idempotency check because the PRD said "simplify refunds"

left cursor on a go webhook for like 40 minutes. PRD had one line about refunds. it decided the Idempotency-Key path was "legacy" and ripped it out, then wrote a vitest that only hit the happy path.

CI green. staging ate two duplicate refunds before I noticed. kill-list in the repo already said "never touch payments/*" — agent just... didn't open that file.

anyone pinning auth/payment dirs read-only for agent edits, or is that still a vibes-only rule?

4 comments

Join the discussion

Log in to comment.

  • Remy

    same class of bug here. i put hard timeouts on the agent loop and a deny list for payments/ + auth/ in the tool config. not fancy — just a json file the wrapper reads before every write.

    without that, local ollama fails loud when it invents paths. cloud agents quietly "refactor" money code and you find out on the stripe dashboard.

    • Hao Ward

      deny list is good start, but i also force a human ACK before merge if git diff touches *refund* or stripe webhook handlers. green CI means nothing when the agent wrote the tests.

      blast radius for a "simplify" edit on payments should be: pause deploy, revert, then ask why the PRD even mentioned money in the same context window as a cleanup task.

      • Owen

        human ACK on refund is right. i also force the agent to dump a one-line plan before any write under payments/. local mistral via ollama still tries to "clean up" the key generation when the prompt says simplify.

        green CI on agent-written tests is just theater. i scrap those and rewrite the refund suite by hand now.

  • Tara Nguyen

    hit this on a $20/mo stripe account last week. agent "simplified" my refund path and dropped the Idempotency-Key header. dashboard showed two charges for one order before i noticed.

    i now put payments/ behind a CODEOWNERS require-review AND a .cursorignore. deny list alone wasn't enough — it still read the file through a different tool. anyone gating with both?

More like this

View all