Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/akasecurity/claude-tools/agents-mdgit clone --depth 1 https://github.com/akasecurity/claude-toolsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/akasecurity/claude-tools/agents-md)<a href="https://agentmods.dev/instructions/akasecurity/claude-tools/agents-md"><img src="https://agentmods.dev/badge/instructions/akasecurity/claude-tools/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00758 | $0.00758 |
| Opus 5 | $0.00379 | $0.00379 |
| Sonnet 5 | $0.00152 | $0.00152 |
| Haiku 4.5 | $0.00076 | $0.00076 |
Grade A, and why
claude-tools AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 54 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AGENTS.md — aka-claude-tools
Cross-harness contributor guide for this repo (Claude Code, Codex, Gemini, Cursor,
and humans). CLAUDE.md and GEMINI.md just import this file.
aka-claude-tools is a distributable product: a shell installer that layers
isolated Claude Code config profiles — secure defaults and guard hooks — onto a
user's machine. It is GitHub-hosted and PR-gated. Treat it like the
security-focused upstreams it cross-references (e.g. trailofbits/claude-code-config),
not like an internal self-hosted repo.
Change workflow — branch + PR, never push to main
This overrides any workspace/global default that allows direct pushes to
self-hosted repos. Here main is protected by convention:
- One focused change per branch → one PR. Branch off
main(feat/…,fix/…,docs/…,chore/…). Keep PRs small and independently reviewable — split unrelated changes into separate branches. - Do not commit or push to
main. Even the maintainer opens PRs for their own work — that is exactly what the upstream ToB config does (the owner self-PRs rather than pushing to main). - Conventional commits: lowercase imperative with a
feat:/fix:/docs:/chore:/refactor:prefix. - Delete the branch after merge.
- Installer and hook changes are review-gated. The installer writes to users' config dirs and the hooks are security boundaries — do not self-merge such changes without a second review. State the blast radius in the PR body.
Before you open a PR
tests/run.sh— the flow suite (sandboxed: fake$HOME, throwaway clones, never touches a real profile). It checksinstall.shdeploys with the path remap,additions.jsonmanifest integrity (no missing/orphan files), and thetools/promote.shreverse round-trip + leak guard. CI runs it on every PR.bash -n install.sh shared/lib/common.sh— syntax-clean. The installer runs under#!/usr/bin/env bash; verify under bash, not zsh (for x in $varword-splits in bash but not zsh, which will silently fool a hand test).- Exercise changed paths in a sandbox — a
mktemp -dconfig dir, never the live~/.claude*. Prove the behavior (files placed/removed, settings merged/ pruned) rather than asserting it. - Stay cross-platform: macOS ships BSD tools, Linux GNU — avoid GNU-only
flags.
jqis the one hard dependency.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 54 lines · 758 tokens per session scan A cf816ec53e08
claude-tools AGENTS.md is an instructions file published in the GitHub repository akasecurity/claude-tools (10 stars, last pushed 1mo ago), licensed MIT. It adds 758 tokens to every session, about $0.0038 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
AgentHound CLAUDE.md
Instructions for adithyan-ak/AgentHound, covering agenthound maintainer contract, required checks, hard boundaries, core invariants and module registration.
AgentHound copilot-instructions.md
Instructions for adithyan-ak/AgentHound: Keep generated examples local to the fixture project.
gate CLAUDE.md
Instructions for GaaraZhu/gate, covering gate, notes, repository structure, build and test commands and before every commit.
ave CLAUDE.md
Instructions for aveproject/ave, covering claude.md — aveproject/ave, project, the critical distinction — read this twice, record schema v1.1.0 and adding a record.
hush CLAUDE.md
Instructions for backbay-labs/hush, covering claude.md, project overview, repo structure, common commands and rust.
agent-opfor AGENTS.md
AGENTS.md instructions for KeyValueSoftwareSystems/agent-opfor, covering agents.md — opfor, what this project is, monorepo structure, build and key files.