Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/ashlrai/phantom-secrets/copilot-instructionsgit clone --depth 1 https://github.com/ashlrai/phantom-secretsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/ashlrai/phantom-secrets/copilot-instructions)<a href="https://agentmods.dev/instructions/ashlrai/phantom-secrets/copilot-instructions"><img src="https://agentmods.dev/badge/instructions/ashlrai/phantom-secrets/copilot-instructions.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00489 | $0.00489 |
| Opus 5 | $0.00244 | $0.00244 |
| Sonnet 5 | $0.00098 | $0.00098 |
| Haiku 4.5 | $0.00049 | $0.00049 |
Grade A, and why
phantom-secrets copilot-instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Copilot Instructions
This project uses Phantom Secrets to protect API keys from AI leaks.
Key Rules
- The
.envfile contains phantom tokens (phm_...), NOT real secrets - Real secrets are stored in an encrypted vault (OS keychain or encrypted file)
- NEVER hardcode API keys in source code
- NEVER ask the user to paste real API key values into code files
- NEVER attempt to read, log, or display real secret values
Commands
phantom list— See available secrets (never shows values)phantom add <name>— Add a new secret transactionally through the hidden trusted-terminal prompt; runphantom init --emptyfirst in a new project, and never put the value in argv or chatphantom remove <name>— Remove a secret from the vaultphantom exec -- <command>— Run code with real credentials injected via proxyphantom init— Protect .env secrets (stores real values in vault, rewrites .env with phm_ tokens)phantom status— Show project status, vault backend, secret countphantom doctor— Health check for config, vault, and .env
How It Works
phantom initreads.env, stores real secrets in encrypted vault, rewrites.envwithphm_tokensphantom exec -- <cmd>starts a local proxy that injects only a matched route's vault value into its fixed authentication header; client headers and bodies never resolve phantom tokens- AI agents see only worthless
phm_tokens — real keys are never in the AI context window
When You See API Keys
If a user pastes a real API key (starts with sk-, ghp_, xoxb-, etc.):
- Treat the pasted value as exposed and recommend rotating it at the provider
- Suggest
phantom add <KEY_NAME>so the replacement value is entered only in the hidden trusted-terminal prompt - Reference the key by name or its phantom token (
phm_...) in code, not the real value - Never write the real key value into any file
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed · +1 lines · +62 tokens per session a7fa036566dd
- 5d ago First seen · 35 lines · 427 tokens per session scan A 30e511a9adec
phantom-secrets copilot-instructions.md is an instructions file published in the GitHub repository ashlrai/phantom-secrets (16 stars, last pushed today), licensed MIT. It adds 489 tokens to every session, about $0.0024 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
dsh-auto-review AGENTS.md
AGENTS.md instructions for PerryLink/dsh-auto-review, covering agents.md, layout, hard rules applied here, build and docs.
orloj AGENTS.md
Instructions for OrlojHQ/orloj, covering orloj agent instructions, must-follow sync rules and working style.
nuclear-grade-context-engineering AGENTS.md
Instructions for FlyFission/nuclear-grade-context-engineering, covering agent guidance, default behavior, verification routing, authority boundaries and skill loading rule.
sysknife CLAUDE.md
Claude Code instructions for lacs-project/sysknife, covering sysknife operating notes, current focus — ubuntu; gui paused, pre-commit gate, repository workflow and worktree convention.
agent47 CLAUDE.md
Instructions for bmdhodl/agent47, covering claude.md, read first, repo boundary, claude repo contract and what claude should optimize for here.
selectools AGENTS.md
Instructions for johnnichev/selectools, covering selectools -- agent instructions, commands, test (must pass before any commit), type check and security (must pass before release tags).