ScaffoldGuard: Instructions file for Codex

AGENTS.md

ScaffoldGuard AGENTS.md is an instructions file for Codex, OpenCode from damienbenveniste/ScaffoldGuard. It costs 4,254 tokens per session, scanned A, original, MIT.

A project guide for ScaffoldGuard, a Python command-line tool that creates starter repositories with coding-agent instructions, strict tooling, automated checks, and optional language layouts.

In plain words
What is it for?
Use it when changing ScaffoldGuard, its generated repository layouts, installation guidance, agent instructions, CI setup, or policy checks.
Why use it?
It keeps development and public documentation aligned with the tool's intended setup, profiles, and safety rules.

Instructions file for CodexOpenCode

Written for Codex and OpenCode: reads ~/.codex or $CODEX_HOME, but also the file is AGENTS.md. Also seen: mentions CLAUDE.md; mentions subagents; mentions Claude Code.

This is damienbenveniste/ScaffoldGuard's own configuration. It tells Codex and OpenCode how to work on ScaffoldGuard itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything ScaffoldGuard configures →

Reuse

Borrowing it

Nothing to install: this file belongs to damienbenveniste/ScaffoldGuard. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/damienbenveniste/ScaffoldGuard/main/AGENTS.md
Clone the repo
git clone --depth 1 https://github.com/damienbenveniste/ScaffoldGuard

Made for: Codex, OpenCode.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ScaffoldGuard AGENTS.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/damienbenveniste/scaffoldguard/agents-md.svg)](https://agentmods.dev/instructions/damienbenveniste/scaffoldguard/agents-md)
Your own site
<a href="https://agentmods.dev/instructions/damienbenveniste/scaffoldguard/agents-md"><img src="https://agentmods.dev/badge/instructions/damienbenveniste/scaffoldguard/agents-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 4,254 This file is loaded in full into every session.
When invoked 4,254 The same file — it is already loaded in full.
Security scan A 1 finding. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.04254 $0.04254
Opus 5 $0.02127 $0.02127
Sonnet 5 $0.00851 $0.00851
Haiku 4.5 $0.00425 $0.00425

Measured 8d ago against content hash 4ded518ac514, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

ScaffoldGuard AGENTS.md scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Runs shell commandslowCapability

Expected in a hook, worth knowing in a rule or an instructions file.

- Use `subprocess.run` without `shell=True` for command execution.
AGENTS.md · 372 lines

How it starts

The opening of the file, as written. The whole thing — 372 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Agent Instructions

These rules apply to every code, test, documentation, template, and configuration change in this repository.

Product Orientation

  • Build scaffold-guard: a PyPI-installable Python CLI that generates strict starter repositories designed for safe coding-agent collaboration.
  • Public user-facing docs should present uv tool install scaffold-guard followed by the installed scaffold-guard command. Do not advertise transient no-install execution paths, uvx, or uv run scaffold-guard ... in user-facing install or quickstart flows. Keep uv run scaffold-guard ... only for repo-local development, CI, or generated agent operating instructions when project-local dependency resolution is required.
  • Preserve the V1 promise: generate a repository with clear agent instructions, strict local tooling, GitHub Actions or GitLab CI, and policy checks that catch common agent mistakes. The default minimal profile should add guardrails only; python should be explicit when users want Python package folders and tooling; typescript and monorepo should be explicit when users want TypeScript or mixed Python+TypeScript starter layouts.
  • New monorepo projects should use semantic workspace layouts: application generates apps/api and apps/web, library generates packages/core and packages/client, and custom requires two explicit safe relative paths. Preserve recorded workspace paths when upgrading existing projects; never rename or move user-owned seed directories automatically.
  • Keep scaffold-guard init friendly for first-time users: omitting NAME starts guided setup, and leaving the project-name prompt blank initializes the current empty directory. Passing NAME and flags remains the stable automation path. Keep . as a compatibility alias for current-directory automation, but do not present it as the primary guided user flow. Do not add guided-only generation behavior without matching non-interactive flags.
  • Guided setup should present meaningful setup choices, not one yes/no prompt per mature tool when a preset or scoped selector is clearer. Keep Python and TypeScript tool prompts profile-aware, and keep generated files, config, CI, validation, docs, and agent instructions synchronized with those choices.
  • Keep V1 focused on a developer CLI. Do not add a SaaS dashboard, telemetry, external AI calls, complex YAML DSL, plugin ecosystem, package/release publish automation, or automatic mutation of mature existing repositories. A guarded git commit/push wrapper is acceptable only when it validates, refuses mixed scope, and requires explicit user intent.
  • When generated instructions, Codex rules, CI, or docs depend on a ScaffoldGuard command added after the initial release, define its minimum supported ScaffoldGuard version in one shared code constant and render that dependency floor into every generated project profile that can invoke it. Use project-local uv run scaffold-guard ... command forms when stale global installs could shadow the generated dependency.
  • Always generate AGENTS.md for scaffolded projects. Treat it as the shared cross-agent instruction source.
  • Keep adapter behavior explicit:
    • Codex uses AGENTS.md for behavior.
    • Claude Code uses CLAUDE.md as a wrapper that imports AGENTS.md, with optional .claude/rules/.
    • Cursor uses .cursor/rules/*.mdc plus AGENTS.md.
  • Prefer small, shippable V1 behavior over speculative framework design.

Read the full file on GitHub · 372 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 372 lines · 4,254 tokens per session scan A 4ded518ac514

Subscribe to this mod's changes

ScaffoldGuard AGENTS.md is an instructions file published in the GitHub repository damienbenveniste/ScaffoldGuard (7 stars, last pushed 20d ago), licensed MIT. It adds 4,254 tokens to every session, about $0.0213 per session on Opus 5. A static security scan graded it A with 1 finding (runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,153 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens