code AGENTS.md

A repository instruction file for Every Code, a coding product and command-line tool. It defines naming, documentation, workflow, and upstream-source rules.

In plain words
What is it for?
Use it when an agent changes Every Code code, docs, user interfaces, workflows, or commits.
Why use it?
It prevents inconsistent product names and helps agents follow the repository's release, import, and documentation conventions.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/cbusillo/code/agents-md
Clone the repo
git clone --depth 1 https://github.com/cbusillo/code

Made for: Codex, OpenCode.

Per session 3,952 This file is loaded in full into every session.
When invoked 3,952 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.03952 $0.03952
Opus 5 $0.01976 $0.01976
Sonnet 5 $0.00790 $0.00790
Haiku 4.5 $0.00395 $0.00395

Measured yesterday against content hash 674fd72368cd, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

code AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 243 lines

How it starts

The opening of the file, as written. The whole thing — 243 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Every Code Repository Guidance

Repo workflow metadata lives in .github/github.json; keep that file aligned with branch roles, validation gates, GitHub signal capabilities, workflow names, PR/release policy, docs routing, and local cleanup policy when those facts change.

Every Code is the product in this repository; code is the command users type. Use Every Code for the product name in prose, docs, UI copy, issue text, release text, and first mentions. Use Every Code CLI for the product CLI surface, and the code command when referring to the executable. Use the Every Code agent for the assistant identity; Code is only a short display name after Every Code context is established. Use Every Code harness for the runtime/session wrapper that we restart and dogfood, and Every Code runtime for process/session/tool-execution internals.

Upstream import sources are just-every/code and openai/codex. Treat just-every/code as a fork upstream/import source. Treat openai/codex / Codex CLI as the original/direct upstream and provenance source. The current product architecture is Codex CLI as the substrate with Every Code layered on top. Locally, codex-rs is a read-only mirror of openai/codex:main; edit Rust sources under code-rs, the Every Code product workspace built on the Codex CLI substrate.

CODE_HOME / ~/.code are the primary config and state locations. CODEX_HOME / ~/.codex are compatibility fallbacks. Keep CODEX_* names when they are part of external, backend, or upstream compatibility; add CODE_* aliases or rename only through a scoped migration. See docs/upstream-import-policy.md#code-and-codex-compatibility-policy before changing environment variable behavior.

Rust implementation lives under code-rs:

  • Crate names are ownership markers. Imported Codex substrate crates may keep their upstream codex-* names only when they remain compatibility-critical or mostly upstream-shaped. Every Code-owned crates and new product-layer crates should use code-* names unless a documented external compatibility contract requires the upstream spelling.
  • When using format! and you can inline variables into {}, always do that.
  • Treat codex-rs as a read-only mirror of openai/codex:main; edit Rust sources under code-rs, including imported Codex-based sources that become part of the Every Code product workspace.
  • When aligning with upstream, prefer moving code-rs closer to current Codex CLI shapes and adding Every Code behavior as a small product-layer overlay. Do not make codex-rs mirror Every Code or edit it directly.

Completion/build step

  • Always validate using ./build-fast.sh from the repo root. This is the single required check and must pass cleanly.
  • ./build-fast.sh can take 20+min to run from a cold cache!!! Please use long timeout when running ./build-fast.sh or waiting for it to complete.
  • Policy: All errors AND all warnings must be fixed before you’re done. Treat any compiler warning as a failure and address it (rename unused vars with _, remove mut, delete dead code, etc.).
  • Do not run additional format/lint/test commands on completion (e.g., just fmt, just fix, cargo test) unless explicitly requested for a specific task.
  • NEVER run rustfmt
  • Before release-bound work lands on main, run ./pre-release.sh to mirror the release preflight (dev-fast build, CLI smokes, workspace nextest).

Optional regression checks (recommended when touching the Rust workspace):

  • cargo nextest run --no-fail-fast — runs all workspace tests with the TUI helpers automatically enabled. The suite is green after the resume fixtures/git-init fallback updates; older Git builds may print a warning when falling back from --initial-branch, but tests still pass.
  • Focused sweeps stay quick and green: cargo test -p code-tui --features test-helpers, cargo test -p code-cloud-tasks --tests, and cargo test -p mcp-types --tests.

When debugging regressions or bugs, write a failing test (or targeted reproduction script) first and confirm it captures the issue before touching code—if it can’t fail, you can’t be confident the fix works.

Read the full file on GitHub · 243 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 243 lines · 3,952 tokens per session scan A 674fd72368cd

Subscribe to this mod's changes

code AGENTS.md is an instructions file published in the GitHub repository cbusillo/code (2 stars, last pushed 5d ago), licensed Apache-2.0. It adds 3,952 tokens to every session, about $0.0198 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

buildNext

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

next.js AGENTS.md

Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

spec-kit AGENTS.md

Instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,040 tokens

langchain AGENTS.md

Instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,345 tokens