Borrowing it
Nothing to install: this file belongs to attilaszasz/sdd-pilot. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/attilaszasz/sdd-pilot/main/AGENTS.mdgit clone --depth 1 https://github.com/attilaszasz/sdd-pilotWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/attilaszasz/sdd-pilot/agents-md)<a href="https://agentmods.dev/instructions/attilaszasz/sdd-pilot/agents-md"><img src="https://agentmods.dev/badge/instructions/attilaszasz/sdd-pilot/agents-md/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/instructions/attilaszasz/sdd-pilot/agents-md"><img src="https://agentmods.dev/badge/instructions/attilaszasz/sdd-pilot/agents-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.02724 | $0.02724 |
| Opus 5 | $0.01362 | $0.01362 |
| Sonnet 5 | $0.00545 | $0.00545 |
| Haiku 4.5 | $0.00272 | $0.00272 |
Grade A, and why
sdd-pilot AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 157 lines — stays where its author put it; the contents beside it link to each section on GitHub.
SDD Pilot — Agent Context
Apply the Spec-Driven Development rules below during feature delivery. Enforce the lifecycle order, phase gates, conventions, and execution policy. If any rule here conflicts with project-instructions.md, follow project-instructions.md.
Lifecycle
Specify → Clarify → Plan → Checklist (optional) → Tasks → Analyze (optional) → Implement → QC
Treat this order as strict. If a required artifact for the next phase is missing, stop and return the work to the phase that owns it.
Runtime Preflight
Every public /sddp-* command must run this preflight exactly once before reading or writing any SDD Pilot artifact, delegating a phase, or running another SDD Pilot script. Nested phases inherit the successful in-turn result and must not run it again:
if ! command -v node >/dev/null 2>&1; then
printf '%s\n' 'SDD Pilot requires Node.js 22 or newer available as node. Detected: not found. Install a supported Node.js LTS release: https://github.com/attilaszasz/sdd-pilot#prerequisites. No SDD Pilot artifact was modified.'
exit 1
fi
node scripts/runtime-preflight.mjs
On a non-zero result, halt without reading or modifying SDD Pilot artifacts. Do not install Node or use an editor-bundled runtime.
Phase Gates
Each phase boundary runs a mandatory structural validator before the next phase may start. A FAIL blocks the next phase: in autopilot the pipeline halts; interactively the user may override with "Proceed anyway" (the bypass is recorded in the conversation only — no persistent marker is written).
spec.mdmust exist before Clarify or Plan.- Spec → Plan gate:
/sddp-plandelegates the Spec Validator (_spec-validator.md) — allows 0–3 unresolved[NEEDS CLARIFICATION: ...]markers and fails at 4+, independently fails any unresolved CRITICAL/HIGH stress-test finding, and enforces concrete acceptance criteria for all P1 stories and frontmatter completeness. FAIL blocks Plan. plan.mdmust exist before Tasks.- Plan → Tasks gate:
/sddp-tasksdelegates the Plan Validator (_plan-validator.md) — enforces 100% P1 requirement coverage in the Requirement Coverage Map, no orphaned Architecture Decisions, and all declared dependencies installable. FAIL blocks Tasks. tasks.mdmust exist before Implement.- Tasks → Implement gate:
/sddp-implement(viareferences/gates.md) delegates the Tasks Validator (_tasks-validator.md) — enforces complete task parsing, ≤40 tasks, every P1 requirement has ≥1 task, no circularafter:chains,tasks.md≤ 6 KB, valid phase structure, and semantic reconciliation of checked task provenance against current spec/plan requirements, coverage, imports/exports, and dependencies. FAIL blocks Implement. - If
checklists/exists, all checklist items must be complete before Implement unless the user explicitly overrides. .completedmust exist before QC.- Do not treat a feature as release-ready until
.qc-passedexists and its report/evidence SHA-256 digests, Git baseline, and repository-state digest validate. - Any
project-instructions.mdviolation is CRITICAL severity.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago Changed · +14 lines · +187 tokens per session 83b1dc619d69
- 5d ago First seen · 143 lines · 2,537 tokens per session scan A 1730401d0300
sdd-pilot AGENTS.md is an instructions file published in the GitHub repository attilaszasz/sdd-pilot (95 stars, last pushed 3d ago), licensed MIT. It adds 2,724 tokens to every session, about $0.0136 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
deepseek-harness AGENTS.md
AGENTS.md instructions for deepseek-ai/deepseek-harness, covering agents.md, pre-stable apis and released session data, repository layout, commands and host sandbox failures.