We just went through this. Wanted to share our approach after we realized our initial exclusions were way too broad and let some real nasties slip through during a test.
The goal: exclude build artifacts and tool caches on our Jenkins agents without letting malware hide in them. The key is being as specific as possible with paths and file extensions. For example, we exclude `**/target/**/*.jar` but NOT `**/target/**/*.exe`. This catches our Java builds but flags any unexpected Windows executable that pops up in that tree.
We also had to make separate, tight exclusions for Node modules and Python virtual envs. A blanket exclusion for `**/node_modules/**` felt safe, but for Python, we found it was better to exclude the specific `venv` or `.venv` folder path on our build drives, rather than any `**/*.py` which would be a huge blind spot. It's a bit of a balancing act, but starting strict and relaxing slightly is better than the other way around.