# The draft is true. It is not enough.

> /init describes the code. It decides nothing.

- **Format:** short video, 9 steps, ~50 seconds
- **Topic:** The complete AGENTS.md playbook — why an AGENTS.md generated by Copilot /init describes the code but decides nothing, and how a human edit adds business rules and a security section that stop an agent logging customer data.
- **Author:** Suthahar Jegatheesan (MSDEVBUILD)
- **Category:** GitHub Copilot · copilot
- **Published:** 2026-01-21
- **Tags:** githubcopilot, agentsmd, aicoding, security, flutter, developerproductivity, softwareengineering, msdevbuild
- **Canonical URL:** https://blog.msdevbuild.com/shorts/agents-md-generate-then-edit/

---
## What you'll learn

- What Copilot /init gets right when it drafts AGENTS.md
- Which sections only a person can write
- How to audit an AGENTS.md file in five grep lines

## Understand it one step at a time

### 1. /init writes a draft

Copilot scans the repo and drafts AGENTS.md from what it finds.

### 2. What it cannot see

Business rules and security policy are not in the code. They are in people.

### 3. Tuesday: an export button

An agent logs the whole order while debugging. The order holds a phone number.

### 4. Wednesday: a promo

The discount is calculated inside the checkout widget, not in Promo.

### 5. Audit the file

Count sections, vague lines, hard rules and security rules.

### 6. Write the business rules

Totals from Cart. Promos through Promo.discountFor. Word for word.

### 7. Write the security section

Never log names, phones or addresses. debugPrint counts as logging.

### 8. Audit again

Nine sections, zero vague lines, fifteen hard rules, four security rules.

### 9. Generate, then edit

Keep what /init got right. Add business rules and security by hand. Audit the file.

---

## The takeaway

**Generate the draft. Then write what only people know.**

Business rules and security are the sections no scan can infer.
