Borrowing it
Nothing to install: this file belongs to 0xNyk/lacp. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/0xNyk/lacp/main/CLAUDE.mdgit clone --depth 1 https://github.com/0xNyk/lacpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/0xnyk/lacp/claude-md)<a href="https://agentmods.dev/instructions/0xnyk/lacp/claude-md"><img src="https://agentmods.dev/badge/instructions/0xnyk/lacp/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.04078 | $0.04078 |
| Opus 5 | $0.02039 | $0.02039 |
| Sonnet 5 | $0.00816 | $0.00816 |
| Haiku 4.5 | $0.00408 | $0.00408 |
Grade C, and why
lacp CLAUDE.md scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Recursive force deletehighDestructive command
rm -rf with a variable or a broad path is one typo away from removing the wrong tree.
| `pretool_guard.py` | PreToolUse | Co-author, scp/root, rm -rf, publishing, exfiltration guards | How it starts
The opening of the file, as written. The whole thing — 319 lines — stays where its author put it; the contents beside it link to each section on GitHub.
LACP — Local Agent Control Plane
Framework for hardening, orchestrating, and validating Claude Code sessions on local machines.
Key Directories
| Path | Purpose |
|---|---|
bin/ |
CLI commands (lacp-test, lacp-doctor, lacp-brain-expand, etc.) |
hooks/ |
Claude Code hooks (SessionStart, PostToolUse, Stop) |
scripts/lacp-lib.sh |
Shared shell library — sourced by all bin/ commands |
scripts/ci/ |
CI test scripts (test-*.sh) |
scripts/runners/ |
Pipeline runners (brain-expand steps, etc.) |
automation/scripts/ |
44 Python + 22 shell automation scripts (brain-expand steps, RAG, benchmarks, sync) |
config/ |
Policy files (sandbox, MCP auth, route policy) |
dist/ |
Distribution/packaging assets |
Formula/ |
Homebrew formula |
Running Tests
# Full suite (~60 tests)
bin/lacp-test
# Quick suite (doctor + route policy)
bin/lacp-test --quick
# Isolated (temporary roots, no side effects)
bin/lacp-test --isolated
# Single test
bash scripts/ci/test-<name>.sh
Conventions
- All bash scripts use
set -euo pipefail - All bin/ scripts source
scripts/lacp-lib.shfor shared functions (log,die,require_cmd, etc.) - CI tests use
assert_eqpattern — compare actual vs expected, print PASS/FAIL - CI tests create temp dirs,
trap cleanup EXIT— no leftover state - JSON output via
--jsonflag on bin/ commands
Hook Architecture
Hooks live in hooks/ and are installed to ~/.claude/ via bin/lacp-claude-hooks apply-profile.
| Hook | Event | Purpose |
|---|---|---|
stop_quality_gate.py |
Stop | Criteria-based scoring (4 dimensions, weighted avg) + test verification + heuristics + handoff artifact generation |
session_start.py |
SessionStart | Git context + test cmd caching + focus brief + handoff injection + stale contract cleanup |
eval_checkpoint.py |
PostToolUse(Write/Edit) | Continuous QA — runs tests at intervals during work, injects feedback on failure |
pretool_guard.py |
PreToolUse | Co-author, scp/root, rm -rf, publishing, exfiltration guards |
thinking_nudge.py |
UserPromptSubmit | Nudges user to state position before asking questions (opt-in) |
detect_session_changes.py |
(library) | Scans transcript for file changes (imported by stop hook) |
hook_telemetry.py |
(library) | JSONL telemetry logger with rotation (imported by stop hook) |
hook_contracts.py |
(library) | Typed state exchange between hooks (SessionStartOutput, SprintContract, EvalCheckpoint, HandoffArtifact) |
write_validate.py |
PostToolUse(Write) | YAML frontmatter schema validation |
session_orient.sh |
SessionStart | Vault tree, recent changes (legacy bash) |
stop_quality_gate.sh |
Stop | Ollama-backed rationalization detection (legacy bash) |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 319 lines · 4,078 tokens per session scan C 9e851690db86
lacp CLAUDE.md is an instructions file published in the GitHub repository 0xNyk/lacp (303 stars, last pushed 17d ago), licensed MIT. It adds 4,078 tokens to every session, about $0.0204 per session on Opus 5. A static security scan graded it C with 1 finding (recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.