Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/alifanov/darkflow/claude-mdgit clone --depth 1 https://github.com/alifanov/darkflowWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/alifanov/darkflow/claude-md)<a href="https://agentmods.dev/instructions/alifanov/darkflow/claude-md"><img src="https://agentmods.dev/badge/instructions/alifanov/darkflow/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01569 | $0.01569 |
| Opus 5 | $0.00785 | $0.00785 |
| Sonnet 5 | $0.00314 | $0.00314 |
| Haiku 4.5 | $0.00157 | $0.00157 |
Grade A, and why
darkflow CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 130 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CLAUDE.md — Dark Flow
Dark Flow is a workflow installer for AI-assisted development projects.
Never start, restart, or relaunch the global worker yourself — always ask the user to do it from their own terminal. The worker's
claude/codexengine authenticates from the user's interactive/login session (keychain / env credentials that a Claude Code session does not have). A worker you launch inherits your credential-less environment, so every routine fails withNot logged in · Please run /loginuntil the user relaunches it themselves. This holds even forlaunchctl bootstrap/kickstart— loading a launchd agent still needs to happen from the user's own session for keychain access to work. A running worker also holds the old script in memory, so after a self-update tell the user to restart it:# the USER runs this in their own terminal: make reload # (re)starts the worker under launchd; the webapp does NOT run under launchd make web # runs the webapp interactively (required for the cmux launch buttons) # or, if the worker is still a bare background process (pre-launchd): pkill -f ~/.darkflow/darkflow-run.sh nohup /usr/local/bin/bash ~/.darkflow/darkflow-run.sh >/dev/null 2>> ~/.darkflow/worker.err.log &The webapp must run in the user's interactive session (
make web), not launchd: cmux's control socket rejects launchd-detached processes ("Broken pipe"), so the "Open in cmux" buttons would silently create no workspace. Same keychain/session reason as the worker. Stopping/killing the worker on request is fine (no credentials needed). Starting or restarting it is always the user's action — do not run it for them, not even in the background, not even when explicitly asked to "restart it"; instead, print the command above and ask them to run it.A restart is only needed when the worker's own script changes. Config edits — routine cron, model, enabled — take effect on the next tick without one: each tick
set_project()re-fetches/api/projects/by-repointo.darkflow.d/state/config.json, so schedules are never cached in memory. Don't ask the user to reload after a schedule change.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 130 lines · 1,569 tokens per session scan A ed7ee820ef58
darkflow CLAUDE.md is an instructions file published in the GitHub repository alifanov/darkflow (2 stars, last pushed 5d ago), licensed MIT. It adds 1,569 tokens to every session, about $0.0078 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
cctop AGENTS.md
AGENTS.md instructions for st0012/cctop, covering agents.md - development guide for cctop, scope and sources, required development rules, driver workflow and github and pr rules.
toh-framework CLAUDE.md
Claude Code instructions for wasintoh/toh-framework, covering claude.md — toh framework (repo development guide), what this is, everyday commands, verification protocol and single source, transformed per ide.
agent-rules child-process.instructions.md
Instructions for lirantal/agent-rules, covering system processes secure coding guidelines, your mission and spawning system processes.
claude-code-templates CLAUDE.md
Claude Code instructions for Justdvp/claude-code-templates, covering claude.md, project overview, development commands, package management and application commands.
examples CLAUDE.md
Claude Code instructions for rossoctl/examples, covering claude.md - agent examples, repository structure, key commands, code style and dco sign-off (mandatory).
deckforge AGENTS.md
Instructions for tph-kds/deckforge, covering deckforge agent entry point, code intelligence, read order, default routing and non-negotiable implementation rules.