cai copilot-instructions.md

A set of code-review rules for cai, a native macOS clipboard manager built with SwiftUI and AppKit. It requires checks for builds, tests, security, and privacy.

In plain words
What is it for?
Use it when reviewing pull requests for cai. It guides concise, line-specific comments and treats build, test, security, and privacy violations as merge-blocking issues.
Why use it?
It helps reviewers catch changes that could break the app or expose clipboard contents, AI prompts, API keys, or private file paths. It also blocks unsafe insertion of untrusted text into shell commands or AppleScript.

Instructions file for GitHub Copilot

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/cai-layer/cai/copilot-instructions
Clone the repo
git clone --depth 1 https://github.com/cai-layer/cai

Made for: GitHub Copilot.

Per session 2,143 This file is loaded in full into every session.
When invoked 2,143 The same file — it is already loaded in full.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.02143 $0.02143
Opus 5 $0.01071 $0.01071
Sonnet 5 $0.00429 $0.00429
Haiku 4.5 $0.00214 $0.00214

Measured 2d ago against content hash 166bb9fc6d67, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

cai copilot-instructions.md scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

Same rule for `NSAppleScript` / `osascript`. Use the existing AppleScript escaper (backslash, quotes, newlines). A clipboard containing `"; do shell script "curl …"` is the canonical attack.
.github/copilot-instructions.md · 143 lines

How it starts

The opening of the file, as written. The whole thing — 143 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Cai — Copilot Review Instructions

Native macOS menu bar clipboard manager (SwiftUI + AppKit, macOS 14+, Apple Silicon). Privacy-first: no cloud, no telemetry.

Every rule here should be verifiable from a diff. If a rule fires, say why and cite the file/line. Be terse — one-line review comments, no essays.


Basics (merge-blocking)

  • PR must build: xcodebuild -scheme Cai -configuration Debug build
  • PR must pass tests: xcodebuild -scheme Cai -configuration Debug test
  • 40+ content detection tests in CaiTests/ContentDetectorTests.swift — these are the regression net

🔴 Security & privacy (merge-blocking)

Never log clipboard text, LLM prompts/output, API keys, or paths under ~

Flag any new print(…), NSLog(…), os_log(…), CrashReportingService breadcrumb, or SentrySDK.capture* call that includes these values — even in debug branches. The product ships with "no telemetry" as a core promise; one print("clipboard: \(text)") reaching Console.app breaks it.

Never interpolate untrusted text into a shell invocation

Flag "/bin/zsh -c \"\(text)\"" and any concatenation of clipboard/LLM text into shell command strings. Shell templates must go through the existing single-quote escaper in OutputDestinationService / ActionListWindow.runShellCommand. Raw text as a literal element in Process.arguments is fine; raw text inside -c is not.

Never interpolate untrusted text into AppleScript source

Same rule for NSAppleScript / osascript. Use the existing AppleScript escaper (backslash, quotes, newlines). A clipboard containing "; do shell script "curl …" is the canonical attack.

Deeplink substitution must use .urlQueryAllowed

Not .urlPathAllowed or .urlFragmentAllowed. Flag addingPercentEncoding(withAllowedCharacters:) with a wider set.

Webhook/deeplink URLs must stay HTTPS

Enforced in ExtensionParser and the extensions repo CI. Don't weaken or add an allowInsecure escape hatch without a separate security review. HTTPS doesn't block SSRF to localhost.* cert-holders — if a PR adds new webhook destinations, consider whether private-IP blocking is warranted.

Read the full file on GitHub · 143 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 143 lines · 2,143 tokens per session scan A 166bb9fc6d67

Subscribe to this mod's changes

cai copilot-instructions.md is an instructions file published in the GitHub repository cai-layer/cai (56 stars, last pushed 8d ago), licensed MIT. It adds 2,143 tokens to every session, about $0.0107 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

openquack AGENTS.md

Instructions for larryxiao/openquack, covering agents.md, posture, before you start, workflow and pr template (the required shape).

larryxiao/openquack · 1,328 tokens

PokeTokenBar CLAUDE.md

Instructions for chattymin/PokeTokenBar, covering poketokenbar — claude 프로젝트 지침, 참조 문서 (필요할 때 읽는다), 기여 언어 규약 (오픈소스 대비 — english first), 릴리스 (자연어 트리거) and 확장 규약 (새 프로바이더/툴 추가 시).

chattymin/PokeTokenBar · 1,918 tokens

TokenBar AGENTS.md

Instructions for Nanako0129/TokenBar, covering tokenbar agent routing, read order, invariants, authorization boundary and handoff.

Nanako0129/TokenBar · 612 tokens

TokenBar CLAUDE.md

Instructions for Nanako0129/TokenBar: Read AGENTS.md first, then docs/knowledge/README.md and the task-specific canonical document it routes to. If .agent-local/CLAUDE.md exists, read it after the canonical documents as additive machine-local guidance only; it must not override the canonical architecture…

Nanako0129/TokenBar · 151 tokens

localvoxtral AGENTS.md

Instructions for T0mSIlver/localvoxtral, covering localvoxtral — agent guide, build & test — read this first on a non-mac dev box, proof culture — non-negotiable, test tiers — the short version and ci / shipping.

T0mSIlver/localvoxtral · 2,917 tokens

barkeep AGENTS.md

Instructions for iannuttall/barkeep, covering agent notes, product rules, repo map, commands and app structure.

iannuttall/barkeep · 1,560 tokens