droid-session-explorer AGENTS.md

A Bun and TypeScript command-line application with a terminal interface for indexing and searching coding-agent session data. It stores its index database in the user cache rather than in the project repository.

In plain words
What is it for?
Use it to develop or verify the session indexer, search layer, terminal interface, development build, compiled binary, and release process.
Why use it?
It provides a searchable local index of sessions and documents the checks needed to keep the command-line tool, terminal interface, and compiled releases working.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/ain3sh/droid-session-explorer/agents-md
Clone the repo
git clone --depth 1 https://github.com/ain3sh/droid-session-explorer

Made for: Codex, OpenCode.

Per session 1,443 This file is loaded in full into every session.
When invoked 1,443 The same file — it is already loaded in full.
Security scan E 3 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01443 $0.01443
Opus 5 $0.00722 $0.00722
Sonnet 5 $0.00289 $0.00289
Haiku 4.5 $0.00144 $0.00144

Measured 2d ago against content hash 897e0e3c8d62, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade E, and why

droid-session-explorer AGENTS.md scanned grade E with 3 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Downloads and executes remote codehighSupply chain

curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.

Release. Users install via `install.sh` (curl | bash), which defaults to the

Recursive force deletehighDestructive command

rm -rf with a variable or a broad path is one typo away from removing the wrong tree.

/tmp/dsx-rel-test/dsx --version && rm -rf /tmp/dsx-rel-test

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

Release. Users install via `install.sh` (curl | bash), which defaults to the
AGENTS.md · 124 lines

How it starts

The opening of the file, as written. The whole thing — 124 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AGENTS.md

Guidance for coding agents working in this repo.

Project shape

  • Bun + TypeScript. CLI entry src/index.ts (commander), TUI in src/tui/ (OpenTUI Solid, JSX via @opentui/solid), indexer/query layers in src/indexer/ and src/query/.
  • The index DB lives at ~/.cache/dsx/index.db, never in the repo.
  • dist/ is gitignored build output.

Verify before committing

bun test            # fixture-based indexer/query tests
bunx tsc --noEmit   # typecheck
bun run build       # dev bundle (dist/index.js, used by `bun link`)
bun run compile     # host-platform SEA (dist/dsx-<target>), smoke test it:
./dist/dsx-* --no-refresh list -n 2

For TUI changes, test the actual terminal behavior (e.g. with tuistory): launch bun run dev or the compiled binary with tui, exercise the views, confirm clean exit.

Cutting a release

Releases are SEA binaries built by CI on v* tags and attached to a GitHub Release. Users install via install.sh (curl | bash), which defaults to the latest release.

  1. Make sure main is green: bun test && bunx tsc --noEmit.

  2. Bump version in package.json and the .version() string in src/cli/program.ts (keep them in sync).

  3. Commit and push to main.

  4. Tag and push the tag; this triggers .github/workflows/release.yml:

    git tag v0.x.y
    git push origin v0.x.y
    

    Pushing requires an account with write access to ain3sh/droid-session-explorer; switch with gh auth switch if the active account lacks access (and switch back afterwards).

    If (and only if) the user you are working with is Ainesh (the project is OSS, so check): wrap every push as gh auth switch --user ain3sh → push → gh auth switch --user factory-ain3sh.

  5. Watch the run and confirm all four assets land:

    gh run watch --repo ain3sh/droid-session-explorer $(gh run list --repo ain3sh/droid-session-explorer -L 1 --json databaseId -q '.[0].databaseId') --exit-status
    gh release view v0.x.y --repo ain3sh/droid-session-explorer --json assets -q '.assets[].name'
    

Read the full file on GitHub · 124 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 124 lines · 1,443 tokens per session scan E 897e0e3c8d62

Subscribe to this mod's changes

droid-session-explorer AGENTS.md is an instructions file published in the GitHub repository ain3sh/droid-session-explorer (10 stars, last pushed 4d ago), licensed MIT. It adds 1,443 tokens to every session, about $0.0072 per session on Opus 5. A static security scan graded it E with 3 findings (downloads and executes remote code, recursive force delete, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,345 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

next.js AGENTS.md

Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens