guidelines

A set of Markdown files containing written rules for how a team works, such as how to write commit messages or review Go code. Markdown is a plain-text format used for documents.

In plain words
What is it for?
Use it to maintain existing guidelines, inspect their format, view their history, and manage the rules that workflows include in their output.
Why use it?
It preserves team conventions so automated workflows can follow the team's preferred wording and review standards.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/px0-ai/px0/guidelines
Clone the repo
git clone --depth 1 https://github.com/px0-ai/px0
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,358 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.01358
Opus 5 $0.00000 $0.00679
Sonnet 5 $0.00000 $0.00272
Haiku 4.5 $0.00000 $0.00136

Measured 2d ago against content hash 371cf141e75c, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

guidelines scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

docs/commands/guidelines.md · 179 lines

How it starts

The opening of the file, as written. The whole thing — 179 lines — stays where its author put it; the contents beside it link to each section on GitHub.

px0 guidelines

Guidelines are Markdown files describing how you work — how you word a commit message, what your Go reviews check. Workflows inline them verbatim, so output comes back in your voice instead of the model's default.

You do not create them. px0 workflows new decides whether the workflow it is building leans on a durable convention the store has no file for, drafts it, and lists it on the workflow — see guidelines the build writes. What is here are the operations on a file that already exists.

Implemented by px0/guidelines.py (the file format), px0/authoring.py (the files) and px0/claims.py (claim identity and history).

The file

A guideline is frontmatter over rules, the same shape as a skill:

---
name: commit-messages
description: How to word a commit message. Use when the workflow writes or rewrites one.
---

## Imperative mood summary line

Write the summary line in the imperative mood: "Add retry logic", not "Added".
Keep it under 72 characters and drop the trailing period.

## Explain why, not what

The diff already shows what changed. Use the body to explain why.
Field What it is for
name The guideline's name, which is its filename. A folder groups a topic (code-review/go.md is named go) and is not part of the name
description One sentence: what the convention covers and when a workflow should follow it. This is the only thing px0 workflows new matches a new workflow against, so it decides whether the file is ever attached
body The rules, as ## sections. This is what a run inlines — the frontmatter never reaches the model

The description is the whole reason this file has frontmatter. Matching on the body instead attached commit-messages.md to a nightly standup that only reads commits: the words overlapped, the conventions did not.

A file with no frontmatter still works — the name falls back to its filename and the description to its first rule — but it will rarely be picked, and px0 doctor lists it under guideline_descriptions. Add the two lines with px0 guidelines edit <name>.

Read the full file on GitHub · 179 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 179 lines · 0 tokens per session scan A 371cf141e75c

Subscribe to this mod's changes

guidelines is a command published in the GitHub repository px0-ai/px0 (241 stars, last pushed 5d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,358 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.