oqto AGENTS.md

oqto AGENTS.md is an instructions file for Codex, OpenCode from byteowlz/oqto. It costs 831 tokens per session, scanned A, original, MIT.

Agent instructions for Oqto, a self-hosted workspace for AI coding agents, covering its issue tracker, domain documentation, architecture decisions, and working rules.

In plain words
What is it for?
Use them before changing Oqto code, configuration, or documentation, especially when creating or updating issues and making architecture decisions.
Why use it?
They tell agents where to track tasks, which project terms and past decisions to read, and how to handle unfamiliar work or repeated mistakes.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/byteowlz/oqto/agents-md
Clone the repo
git clone --depth 1 https://github.com/byteowlz/oqto

Made for: Codex, OpenCode.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for oqto AGENTS.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/byteowlz/oqto/agents-md.svg)](https://agentmods.dev/instructions/byteowlz/oqto/agents-md)
Your own site
<a href="https://agentmods.dev/instructions/byteowlz/oqto/agents-md"><img src="https://agentmods.dev/badge/instructions/byteowlz/oqto/agents-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 831 This file is loaded in full into every session.
When invoked 831 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00831 $0.00831
Opus 5 $0.00415 $0.00415
Sonnet 5 $0.00166 $0.00166
Haiku 4.5 $0.00083 $0.00083

Measured 4d ago against content hash e428a814f6d6, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

oqto AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 36 lines

How it starts

The opening of the file, as written. The whole thing — 36 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Oqto agent guide

Oqto is a self-hosted workspace for AI coding agents. Keep this file short; put runbooks/design detail in docs, skills, or repo-analysis/.

Agent skills

Issue tracker

Issues are tracked with trx in this repo; use trx ready/list/show/create/update/close and trx dep block/unblock, not GitHub Issues. See docs/agents/issue-tracker.md.

Domain docs

Single-context layout: project domain language lives in CONTEXT.md; architectural decisions live in docs/adr/. See docs/agents/domain.md.

Rules

  • Before changing code/config/docs: trx ready or trx list -> reuse/create issue -> trx update <id> --status in_progress; close/update it when done. Ambiguous git/trx commands are read-only first.
  • Search agntz memory before unfamiliar work. Add memories only for reusable architecture/interface/debugging lessons.
  • Use CONTEXT.md for project domain language. docs/adr/ is the canonical decision log; read past ADRs before architecture changes and add/update ADRs for new decisions.
  • Repeated failures must become mechanisms, not reminders: propose or add a lint, test, doctor, checklist, or skill when a mistake recurs.
  • No hacky fixes or legacy shims. Understand the root cause, respect the architecture, and delete dead compatibility paths when safe.
  • Architecture seams: actions go through runners; runner sessions use oqto-log as durable history authority; hstry is legacy/interop only; memory goes through mmry; do not bypass stores with ad-hoc DB/file writes.
  • Session identity is sacred: keep platform_id and external_id distinct; never persist pending-*/tmp:*; Pi owns JSONL session files and Oqto must not write them.
  • Chat/session changes require proof: name the durable authority, event source, ID mapping, reconnect/reload behavior, and regression test/trace. Never reconcile messages by text, index, array length, or visible order.
  • High-risk domains need their checklist before editing: chat persistence, sessions/forks/import, sandbox/security, setup/deploy, EAVS/user config, protocol/generated types, frontend event state.
  • User-owned config is preserve-first: anything under ~/.pi, ~/.config, per-user homes, model lists, or generated user settings needs backup + diff + merge semantics; never overwrite unknown entries.
  • Config/docs must match runtime truth. New config modes require implementation, tests, and fail-closed behavior for unsupported values.
  • Use just/package scripts for gates. Touched production code must be formatted, linted, tested, and warning-free; no “pre-existing” warning handoff without an explicit accepted-debt rationale.
  • Frontend: avoid raw useEffect; use approved hooks or an inline guardrail exception. Keep generated TypeScript types fresh after protocol/Rust type changes.
  • Rust: prefer anyhow::Result + context; no unwrap/expect in production paths unless explicitly justified and allowed by guardrails.
  • Deploy/release: use just bump for versions; package/deploy must pass manifest/artifact checks; release tags must match declared Cargo/package versions.
  • Debug UI with DISPLAY=:0 agent-browser ...; frontend dev is localhost:3000; use tmux logs for backend/frontend/runner.
  • If Claude Code cargo fails with EPERM/statx/timer_create on git deps, treat it as harness sandbox capability, not code failure; use standalone rustfmt/ast-grep locally and run cargo gates in an unsandboxed lane.
  • Keep documentation current when architecture changes, but prefer links over duplicating specs here.
  • Before declaring done, audit the objective against real evidence: files changed, commands run, tests/gates, known gaps, and trx status. Always update trx status for items that have been touched in a session.

Read the full file on GitHub · 36 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 36 lines · 831 tokens per session scan A e428a814f6d6

Subscribe to this mod's changes

oqto AGENTS.md is an instructions file published in the GitHub repository byteowlz/oqto (57 stars, last pushed 6d ago), licensed MIT. It adds 831 tokens to every session, about $0.0042 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,345 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

next.js AGENTS.md

Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens