Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/carlkcarlk/device-envoy/agents-mdgit clone --depth 1 https://github.com/CarlKCarlK/device-envoyWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/carlkcarlk/device-envoy/agents-md)<a href="https://agentmods.dev/instructions/carlkcarlk/device-envoy/agents-md"><img src="https://agentmods.dev/badge/instructions/carlkcarlk/device-envoy/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.10307 | $0.10307 |
| Opus 5 | $0.05153 | $0.05153 |
| Sonnet 5 | $0.02061 | $0.02061 |
| Haiku 4.5 | $0.01031 | $0.01031 |
Grade A, and why
device-envoy AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 791 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Coding Notes for Agents
This file contains both shared workspace rules and crate-specific rules for this repository.
General Policies
-
When autonomous work is interrupted or reaches a stopping point, report the current status, what remains, and the recommended next step. If the next step is within the current task and safe to perform, perform it rather than stopping merely to recommend it.
-
In this repository, devolve means inlining a code element's behavior at its call sites (or into its containing function) and deleting the original struct, enum, helper, or other abstraction. Prefer the clearer term inline in prose when there is no need for the project-specific shorthand.
-
Never silently skip required build targets in xtask/CI. Every supported target (e.g., ESP32-C6, ESP32-S3, Pico 1, Pico 2) must be built on every
check-allrun. If a required toolchain component is missing, fail loudly with a clear error message and instructions to install it — do not skip or silently ignore the missing target. Silent skips hide real breakage. -
When loading data from flash (or any other storage) into a local variable, name the variable after the concrete type. Example:
DeviceConfigdata should live in variables likedevice_config, not genericconfigorflash0. -
Avoid introducing
unsafeblocks. If a change truly requiresunsafe, call it out explicitly and explain the justification so the user can review it carefully. -
Avoid silent clamping; prefer asserts or typed ranges so out-of-range inputs fail fast.
-
Prefer
no_rundoctests; useignoreonly when absolutely necessary (and call out why). Running doctests is best when possible, but rarely feasible for embedded code. -
Always use
rust,no_runin doctest fences, not justno_run. -
For programs that should run forever, use
pending().awaitinstead of a timer loop. -
Hide boilerplate in doctests using the
#prefix (e.g.,# #![no_std]). Hide lines that are noise to the reader but required for compilation:#![no_std],#![no_main], and standard imports likeuse embassy_executor::Spawner;. Keep only the essential code showing how to use the API. See the crate-specific sections below for platform-specific imports to hide or show. -
When adding docs for modules or public items, link readers to the primary struct and keep the single compilable example on that struct; other items should point back to it rather than duplicating examples.
-
Prefer
constvalues defined in the local context (inside the function/example) rather than at module scope when they're only used there. -
Do not add redundant
justrecipes that only mirror an existingcargoalias/command. If the behavior is the same, keep only thecargocommand. -
For
cargoaliases that target embedded triples, include--no-default-featuresunless there is an explicit, documented reason to keep default features enabled.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 791 lines · 10,307 tokens per session scan A b1933527362b
device-envoy AGENTS.md is an instructions file published in the GitHub repository CarlKCarlK/device-envoy (50 stars, last pushed 3d ago), licensed Apache-2.0. It adds 10,307 tokens to every session, about $0.0515 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.