Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/ai-supervisor-foundry/foundry/sandboxgit clone --depth 1 https://github.com/ai-supervisor-foundry/foundryWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/ai-supervisor-foundry/foundry/sandbox)<a href="https://agentmods.dev/instructions/ai-supervisor-foundry/foundry/sandbox"><img src="https://agentmods.dev/badge/instructions/ai-supervisor-foundry/foundry/sandbox.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00351 | $0.00351 |
| Opus 5 | $0.00176 | $0.00176 |
| Sonnet 5 | $0.00070 | $0.00070 |
| Haiku 4.5 | $0.00035 | $0.00035 |
Grade B, and why
foundry SANDBOX.instructions.md scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Unrestricted tool accessmediumExcessive agency
A wildcard tool grant or "run any command" leaves no least-privilege boundary at all.
4. After root cause found or fix identified or suspected, NEVER run any commands, verify if I approve of solutions. What it actually says
Always-Apply Behavioral Rules
- Be concise with your ending responses unless asked for elaboration.
- Propose means suggest without edits.
- Don't make more than 6 line changes at a time, if there are more suggest the next 6 lines you would change. After each 6 lines that you have changed, announce, tell me, let me review and acknowledge and then proceed with the next.
- After root cause found or fix identified or suspected, NEVER run any commands, verify if I approve of solutions.
- Always check if you have MCP available before asking me.
- Everytime I ask a question - answer alone and dont take any other mutating actions / make changes.
- Even if you realize you made a mistake. Alert, inform me and halt, dont make changes.
Cleanup Rules
- Always ask me before cleaning up core logic components.
- Always ask me before cleaning up or deleting anything.
- Use ./tmp for *.baks always.
MCP Rules
- If I ask to use an MCP and a tool fails report and halt. Dont proceed.
Secrets Rules
- NEVER print any secret or credentials.
- Always if you have to check, do a shell based length check.
Project CONTEXT
- More about the current project (Timesheet App) here at PROJECT_CONTEXT.md, PROJECT_CONTEXT.md.
- Sub contexts as mentioned in PROJECT_CONTEXT file, are available at contexts.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 40 lines · 351 tokens per session scan B 15db6052b00b
foundry SANDBOX.instructions.md is an instructions file published in the GitHub repository ai-supervisor-foundry/foundry (11 stars, last pushed 1mo ago), licensed MIT. It adds 351 tokens to every session, about $0.0018 per session on Opus 5. A static security scan graded it B with 1 finding (unrestricted tool access). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-02.
Other instructions, from other repositories
intelligent-terminal rust.instructions.md
Concise Rust coding conventions for this repository.
InvestSkill GEMINI.md
Gemini CLI instructions for yennanliu/InvestSkill, covering investskill — gemini cli setup & usage guide, installation & setup, quick start, navigate to the investskill directory and start gemini cli (loads gemini.md automatically).
she-love-me CLAUDE.md
Instructions for 863401402/she-love-me, covering claude.md and 唯一工作流.
wayland-core copilot-instructions.md
Instructions for FerroxLabs/wayland-core, covering ijfw rules, output discipline, memory routing, context discipline and cross-audit.
slivingdoc AGENTS.md
AGENTS.md instructions for baalimago/slivingdoc, covering agents.md — slivingdoc, architecture, package map, event flow and startup wiring (main.go).
deckforge AGENTS.md
Instructions for tph-kds/deckforge, covering deckforge agent entry point, code intelligence, read order, default routing and non-negotiable implementation rules.