# Init

Copy page

Scaffold AI-agent-safe ignore files in your project.

The `init` command prepares a repository for use with Shelve and, crucially, keeps your `.env*` files out of the context of AI coding agents. Running it is a one-off setup step — run it once per project.

```bash
shelve init
```

## [What it does](/content/docs/cli/init#what-it-does/index.html)

- Creates (or updates) an ignore file for every major AI agent so they can never read cached secrets:
  - `.cursorignore`
  - `.aiderignore`
  - `.codeiumignore`
  - `.continueignore`
  - `.aigignore`
- Appends a managed block to your `.gitignore` if one is not already present, so the encrypted cache directory (`.shelve/`) and all `.env*` files stay out of version control. `.env.example` and `.env.template` are whitelisted so you can still commit references.

Each ignore file is framed with `# shelve-managed-block` / `# end shelve-managed-block` markers. Running `shelve init` again only rewrites the managed block — your own entries above and below are preserved.

## [Options](/content/docs/cli/init#options/index.html)

cwd

string

Directory to initialize. Defaults to the current working directory.

## [Why this matters](/content/docs/cli/init#why-this-matters/index.html)

AI coding agents (Cursor, Claude Code, Codex, Aider, Continue…) can read every file in your workspace unless you tell them otherwise. If you ever run `shelve pull` to write a `.env` to disk, an agent can trivially exfiltrate its contents into a prompt or a suggested commit. `shelve init` closes that hole in one command.

Even with agent ignore files in place, prefer `shelve run -- <cmd>`: it pipes secrets to your subprocess through the environment and never writes them to disk in the first place.
