cirdan AGENTS.md

A set of AGENTS.md instructions for developing Cirdan, a Python on-call repair system that links production alerts to services and repositories, tests fixes, and can open verified pull requests.

In plain words
What is it for?
Use it when changing Cirdan, including its command-line tool, daemon, MCP server, HTTP API, alert handling, isolated reproductions, and verification tests.
Why use it?
It gives a coding agent the project’s setup, architecture, testing commands, and repair workflow in one place.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/adanb13/cirdan/agents-md
Clone the repo
git clone --depth 1 https://github.com/adanb13/cirdan

Made for: Codex, OpenCode.

Per session 1,466 This file is loaded in full into every session.
When invoked 1,466 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01466 $0.01466
Opus 5 $0.00733 $0.00733
Sonnet 5 $0.00293 $0.00293
Haiku 4.5 $0.00147 $0.00147

Measured yesterday against content hash 796340d2902c, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

cirdan AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 63 lines

How it starts

The opening of the file, as written. The whole thing — 63 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Working on Cirdan

Cirdan is a Python package (cirdanops) providing the cirdan CLI and cirdand daemon. It is an on-call software repair agent: a production alert (Grafana / Alertmanager / Slack) resolves to a registered service and repo via the explicit services: registry in cirdan.yaml, the failure is reproduced in an isolated runner (Docker Compose / K8s), a coding agent fixes the code (an in-process API provider, or a workspace-spawned local agent CLI in the cli posture), the fix is re-verified against the pinned repro probe and the repo test suite, and a verified PR opens (@cirdan review loop; CI checks watched). When policy allows, delivery merges, deploys, and verifies production recovery, stopping at manual_required on failure.

Setup

python3 -m venv --without-pip .venv          # ensurepip may be unavailable on Debian/Ubuntu
python3 -m pip --python .venv/bin/python install -e ".[all,dev]"
.venv/bin/python -m pytest tests/ -q

Architecture in one paragraph

cirdan.engine.CirdanEngine is the single wiring point used by the CLI (cirdan/cli/main.py), MCP server (cirdan/mcp/server.py), HTTP API (cirdan/api/http.py), and daemon (cirdan/daemon/server.py). It owns config (cirdan/config.py — the services: registry of ServiceEntry/DeployTargetConfig, routing policy, safety gates), the access context (a probed mirror of what the session can do — cirdan/access/), the SQLite store (cirdan/graph/store.py — one file holding incidents, alerts, events, agent runs, and kv state; a storage substrate, not topology), and the audit log. cirdan/registry.py is the source of truth for what is repairable: alert→service matching (match_alert), service→repo resolution (repairable_repo), and the typed runtime target (LiveTarget) consumed by probe exec, MCP get_logs/get_state, and the docker/kubernetes adapters. Alerts arrive through cirdan/ingest/, route through the first-match-wins policy in cirdan/incidents/routing.py (a registered service at qualifying severity defaults to reproduce_and_pr_only; everything else fails safe to triage_only), and become lifecycle-managed incidents in cirdan/incidents/. The responder (cirdan/incidents/responder.py) drives the repair: repair/workspace.py clones an isolated workspace (remote URL + auth from integrations/github.clone_context, whose push_url is always the canonical configured repo — pushes structurally cannot land anywhere else), the compose/k8s runners (repair/{compose_runner,k8s_runner}.py) reproduce the failure, agents/api_agent.py (in-process API providers) or agents/cli_agent.py (workspace-spawned host CLIs) edits the code, and verification (repair/{probe,testsuite,verify}.py) gates the PR (integrations/github.py). repair/delivery.py advances merge → deploy → prod-verify to resolved or manual_required; repair/{pr_checks,pr_comments,review_loop}.py watch CI and drive the @cirdan review loop; cirdan/readiness.py computes the checklist behind the setup UI banner and cirdan status --checks; the remaining adapters (docker, kubernetes, loki, prometheus, tempo) collect logs, state, and telemetry evidence only.

Read the full file on GitHub · 63 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 63 lines · 1,466 tokens per session scan A 796340d2902c

Subscribe to this mod's changes

cirdan AGENTS.md is an instructions file published in the GitHub repository adanb13/cirdan (0 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 1,466 tokens to every session, about $0.0073 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.