agr AGENTS.md

Repository instructions for agr, a Python package manager for AI-agent resources, and agrx, a temporary skill runner. They describe the required commands, shared library structure, and dependency-file format.

In plain words
What is it for?
Use them when running tests or checks, working on the agr or agrx command-line tools, or adding skills and other dependencies to agr.toml.
Why use it?
They ensure commands run in the project's managed Python environment and that agent resources are declared in the format the tools expect.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/computerlovetech/agr/agents-md
Clone the repo
git clone --depth 1 https://github.com/computerlovetech/agr

Made for: Codex, OpenCode.

Per session 571 This file is loaded in full into every session.
When invoked 571 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00571 $0.00571
Opus 5 $0.00285 $0.00285
Sonnet 5 $0.00114 $0.00114
Haiku 4.5 $0.00057 $0.00057

Measured yesterday against content hash 3140bbe91251, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

agr AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 69 lines

How it starts

The opening of the file, as written. The whole thing — 69 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Agent Resources

The package manager for AI agents. Built for teams practicing Agentic Engineering.

Commands

This project uses uv for Python environment management. Always use uv run to execute Python commands to ensure they run in the correct virtual environment.

# Run tests
uv run pytest

# Run linters/formatters
uv run ruff check .
uv run ruff format .

# Run type checker
uv run ty check

# Test the CLI tools
uv run agr --help
uv run agrx --help

Architecture

Two CLI tools share a common core library:

  • agr — Main CLI (Typer app in agr/main.py). Commands: add, remove, sync, list, init, config.
  • agrx — Ephemeral skill runner (agrx/main.py). Downloads and runs a skill without persisting it.

For detailed architecture, contributing guides, code patterns, and recipes, see docs/contributing/.

agr.toml Format

The configuration file uses a flat array of dependencies:

dependencies = [
    {handle = "username/repo/skill", type = "skill"},
    {handle = "username/skill", type = "skill"},
    {path = "./local/skill", type = "skill"},
    {handle = "username/repo/my-ralph", type = "ralph"},
]

Each dependency has:

  • type: "skill" or "ralph". Skills install into each configured tool's skills dir; ralphs install once into .agents/ralphs/<name>/ (project-scoped, no per-tool fan-out, no global installs).
  • handle: Remote GitHub reference (username/repo/skill or username/skill)
  • path: Local path (alternative to handle)

Future: A tools section will configure which tools to sync to:

tools = ["claude", "cursor"]

Conventions

  • Commit messages: docs: explain X for users who want to Y, feat: add X so users can Y, fix: resolve X that caused Y
  • Dependencies: Keep runtime deps minimal. Prefer stdlib over new deps.
  • Tests: Include tests for new functionality. No external services, no API keys in tests.
  • Docs: Run mkdocs build --strict before committing doc changes.

Read the full file on GitHub · 69 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 69 lines · 571 tokens per session scan A 3140bbe91251

Subscribe to this mod's changes

agr AGENTS.md is an instructions file published in the GitHub repository computerlovetech/agr (452 stars, last pushed 20d ago), licensed MIT. It adds 571 tokens to every session, about $0.0029 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.