tokentrace: Instructions file for Codex

AGENTS.md

tokentrace AGENTS.md is an instructions file for Codex, OpenCode from abhiyoheswaran1/tokentrace. It costs 1,004 tokens per session, scanned A, original, MIT.

Repository instructions for TokenTrace, including its required development workflow, testing approach, code-quality checks, and release restrictions. TDD means writing a failing test first, then implementing the change and confirming the test passes.

In plain words
What is it for?
Use them when implementing or reviewing TokenTrace changes, running tests and ProjScan checks, or preparing work without releasing it.
Why use it?
They help agents make behavior changes safely and avoid publishing releases or changing version files without explicit approval.

Instructions file for CodexOpenCode

Written for Codex and OpenCode: the file is AGENTS.md.

This is abhiyoheswaran1/tokentrace's own configuration. It tells Codex and OpenCode how to work on tokentrace itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything tokentrace configures →

Reuse

Borrowing it

Nothing to install: this file belongs to abhiyoheswaran1/tokentrace. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/abhiyoheswaran1/tokentrace/main/AGENTS.md
Clone the repo
git clone --depth 1 https://github.com/abhiyoheswaran1/tokentrace

Made for: Codex, OpenCode.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for tokentrace AGENTS.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/abhiyoheswaran1/tokentrace/agents-md/github.svg)](https://agentmods.dev/instructions/abhiyoheswaran1/tokentrace/agents-md)
Your own site
<a href="https://agentmods.dev/instructions/abhiyoheswaran1/tokentrace/agents-md"><img src="https://agentmods.dev/badge/instructions/abhiyoheswaran1/tokentrace/agents-md/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for tokentrace AGENTS.md

Your own site · 80×15
<a href="https://agentmods.dev/instructions/abhiyoheswaran1/tokentrace/agents-md"><img src="https://agentmods.dev/badge/instructions/abhiyoheswaran1/tokentrace/agents-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 1,004 This file is loaded in full into every session.
When invoked 1,004 The same file — it is already loaded in full.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.01004 $0.01004
Opus 5 $0.00502 $0.00502
Sonnet 5 $0.00201 $0.00201
Haiku 4.5 $0.00100 $0.00100

Measured 8d ago against content hash 9b5cdd3a2abe, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

tokentrace AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 49 lines

How it starts

The opening of the file, as written. The whole thing — 49 lines — stays where its author put it; the contents beside it link to each section on GitHub.

TokenTrace Agent Instructions

These instructions apply to coding agents working in this repository.

Mandatory Workflow

  • Use the Superpowers methodology from https://github.com/obra/superpowers for coding work.
  • Before non-trivial implementation, use the relevant Superpowers skills for brainstorming, systematic debugging, test-driven development, planning, code review, and verification.
  • Prefer TDD for behavior changes: write a failing test, verify it fails for the expected reason, implement the smallest fix, and verify it passes.
  • Use ProjScan from https://www.npmjs.com/package/projscan as a standard code-intelligence and quality gate.
  • Run targeted projscan commands when exploring substantial changes, and run npm run projscan:doctor after substantial implementation or before release readiness claims.
  • ProjScan does not replace tests, typecheck, lint, build, package, or smoke verification.

Release Discipline

  • Do not bump package.json, update package-lock.json for a version bump, create git tags, push release tags, create GitHub Releases, or publish to npm unless the maintainer explicitly asks for a release.
  • Build and test substantial improvements before any release conversation.
  • User-facing changes must be recorded in CHANGELOG.md under Unreleased while in development.
  • Read docs/RELEASE_CHECKLIST.md before any release work.
  • Final public release gates include npm run release:check, packed-install smoke when needed, ProjScan doctor, changelog section extraction, tag/version matching, GitHub Trusted Publishing, and npm verification.

Maintenance Pass

TokenTrace is in maintenance mode: feature-complete, iterate from feedback. New features are pull-based (wait for real usage signals); health is push-based (run proactively). A maintenance pass is read-only triage — it reports and proposes, it does not bump versions or release. Run it periodically or when asked for a "health check".

Steps:

  • Test/type/lint gate: npm run verify must be fully green (vitest + tsc --noEmit + eslint). Treat any failure as a regression to fix before other work.
  • Dependency drift: npm outdated. Patch/minor bumps within the current major are low-risk; batch and verify them. Hold major bumps (e.g. eslint 10, @vitejs/plugin-react 6, @types/node 25, eslint-plugin-react-hooks 7) for a deliberate, separately-tested upgrade — never fold a major into a routine pass.
  • Security: npm audit --audit-level=moderate (expect 0 vulnerabilities) and npm run security:ioc. For release-grade checks use npm run security:package.
  • Provider/ecosystem drift (highest-value signal for a cost tool): check pricing/default-model-prices.json freshness and refresh with npm run pricing:refresh when models, tokenizers, or provider pricing have changed upstream. This is "feedback from reality," not from users — act on it without waiting for a complaint.
  • Package surface: npm pack --dry-run and confirm the tarball contains only intended files. Nothing untracked-in-git should reach npm. The files array includes public/, so anything dropped into public/ ships — keep non-product assets (brand kits, screenshots, scratch files) out of it or .gitignore them.
  • ProjScan: npm run projscan:doctor for code-intelligence and release-readiness signal.
  • Report, don't release: summarize findings and propose fixes. Apply only low-risk, verified maintenance (patch bumps, lockfile, packaging hygiene) under the Release Discipline rules above; leave version bumps and publishing to an explicit maintainer request.

Read the full file on GitHub · 49 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 49 lines · 1,004 tokens per session scan A 9b5cdd3a2abe

Subscribe to this mod's changes

tokentrace AGENTS.md is an instructions file published in the GitHub repository abhiyoheswaran1/tokentrace (0 stars, last pushed 2mo ago), licensed MIT. It adds 1,004 tokens to every session, about $0.0050 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,153 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

deepseek-harness AGENTS.md

AGENTS.md instructions for deepseek-ai/deepseek-harness, covering agents.md, pre-stable apis and released session data, repository layout, commands and host sandbox failures.

deepseek-ai/deepseek-harness · 3,737 tokens