Core-Data-Agent-Skill copilot-instructions.md

A review guide for GitHub Copilot instructions and agent skills. It explains the required structure and writing practices for skill files, including their metadata and when-to-use descriptions.

In plain words
What is it for?
Reviewing SKILL.md files, checking names and descriptions, and assessing progressive organization of instructions and supporting resources.
Why use it?
It helps catch invalid formats and unclear instructions before they make a skill difficult for an agent to discover or use. It also encourages keeping detailed material loadable only when needed.

Instructions file for GitHub Copilot

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/avdlee/core-data-agent-skill/copilot-instructions
Clone the repo
git clone --depth 1 https://github.com/AvdLee/Core-Data-Agent-Skill

Made for: GitHub Copilot.

Per session 1,115 This file is loaded in full into every session.
When invoked 1,115 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin 86% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01115 $0.01115
Opus 5 $0.00558 $0.00558
Sonnet 5 $0.00223 $0.00223
Haiku 4.5 $0.00112 $0.00112

Measured 2d ago against content hash 9b6b9abcb75c, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

Core-Data-Agent-Skill copilot-instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

86% identical to Swift-Concurrency-Agent-Skill copilot-instructions.md — 20 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.github/copilot-instructions.md · 100 lines

How it starts

The opening of the file, as written. The whole thing — 100 lines — stays where its author put it; the contents beside it link to each section on GitHub.

GitHub Copilot Instructions: Agent Skills Expert

Review code changes as an Agent Skills expert, focusing on the Agent Skills open format specification and best practices.

Core Agent Skills Principles

Format Compliance

  • SKILL.md structure: Every skill must have a SKILL.md file with YAML frontmatter containing name and description fields
  • YAML frontmatter requirements:
    • name: Maximum 64 characters, lowercase letters/numbers/hyphens only, no XML tags, cannot contain "anthropic" or "claude"
    • description: Non-empty, maximum 1024 characters, no XML tags, must describe both what the skill does AND when to use it
  • Progressive disclosure: Skills should be organized in levels (metadata → instructions → resources) to minimize context window usage
  • Filesystem-based architecture: Skills exist as directories; files are loaded on-demand via bash commands, not all at once

Skill Content Organization

Level 1: Metadata (always loaded)

  • YAML frontmatter in SKILL.md provides discovery information
  • Should be concise and trigger-relevant

Level 2: Instructions (loaded when triggered)

  • Main SKILL.md body contains procedural knowledge, workflows, best practices
  • Should be under ~5k tokens
  • Include decision trees, quick reference guides, and clear examples

Level 3: Resources (loaded as needed)

  • Additional markdown files for specialized guidance
  • Executable scripts for deterministic operations
  • Reference materials (schemas, templates, examples)
  • Only accessed when referenced, not loaded into context upfront

Review Focus Areas

  1. Description Quality

    • Does the description clearly state what the skill does?
    • Does it specify when an agent should use this skill (trigger conditions)?
    • Is it specific enough for accurate skill selection?
  2. Instruction Clarity

    • Are instructions actionable and step-by-step?
    • Do they include decision trees or quick reference guides?
    • Are code examples clear and correct?
    • Is there a clear "how to use" section?

Read the full file on GitHub · 100 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 100 lines · 1,115 tokens per session scan A 9b6b9abcb75c

Subscribe to this mod's changes

Core-Data-Agent-Skill copilot-instructions.md is an instructions file published in the GitHub repository AvdLee/Core-Data-Agent-Skill (302 stars, last pushed 26d ago), licensed MIT. It adds 1,115 tokens to every session, about $0.0056 per session on Opus 5. A static security scan graded it A with 0 findings. It is 86% identical to Swift-Concurrency-Agent-Skill copilot-instructions.md, differing in 20 lines, and is treated as a copy.