Borrowing it
Nothing to install: this file belongs to Dayananda-D/DevCDP. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/Dayananda-D/DevCDP/main/GEMINI.mdgit clone --depth 1 https://github.com/Dayananda-D/DevCDPWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/dayananda-d/devcdp/gemini-md)<a href="https://agentmods.dev/instructions/dayananda-d/devcdp/gemini-md"><img src="https://agentmods.dev/badge/instructions/dayananda-d/devcdp/gemini-md/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/instructions/dayananda-d/devcdp/gemini-md"><img src="https://agentmods.dev/badge/instructions/dayananda-d/devcdp/gemini-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00859 | $0.00859 |
| Opus 5 | $0.00430 | $0.00430 |
| Sonnet 5 | $0.00172 | $0.00172 |
| Haiku 4.5 | $0.00086 | $0.00086 |
Grade A, and why
DevCDP GEMINI.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Debugging a web app with DevCDP
DevCDP is attached to a real Chrome tab over the DevTools Protocol. It can read the page, drive it, and stop it mid-execution to show you live values.
Start here
devtools_connectfirst — nothing else works until a tab is claimed.- Console and network capture begin at attach, so anything logged before attach is
gone for good — Chrome does not replay it.
page_reloadreplays the page with DevCDP watching; do that before concluding nothing was logged. workflow_guideexplains the division of labour;ui_inspectandapp_discoverdescribe the screen you are actually on.
Driving the page — use the ui_* tools
ui_click,ui_fill,ui_type,ui_select,ui_check,ui_press,ui_hover,ui_scroll,ui_drag,ui_upload,ui_wait_for.- They wait until the element is genuinely actionable — rendered, enabled, no longer moving, not covered — then dispatch trusted input. Each reports what it caused: requests fired, console errors, whether the DOM changed. A click and its consequences are one call, not three.
- Target by
selector, by thetexta person reads, or bytestid. When a target does not match,ui_inspectlists the controls really on screen and the exact target to use for each. ui_fillsets the value in one step.ui_typesends a key per character and is the one to use for typeahead, autocomplete and masked fields — ifui_fillleft the field looking right but the application unaware, switch toui_type.- Never sleep to wait for the UI.
ui_wait_forreturns the moment the condition holds, and says what the page looked like when it does not. - When an action reports
nothingHappened, the event was delivered and the application ignored it. That is a different problem from a wrong selector.
Prefer these over a general browser-automation server while DevCDP is attached. That server drives its own separate browser, so it cannot see the tab you are debugging — and it needs a full page snapshot before each action, which costs far more context than naming the element. Reach for it only for what DevCDP does not do: downloads, the operating system's file-chooser dialog, and tracing.
Debugger
- Always check
boundin the reply todebugger_set_breakpoint. An unbound breakpoint is accepted by Chrome and never fires. - Breakpoints capture and then resume by themselves, so the page is not left frozen.
debugger_get_capturereturns the frame, scope and values from the last pause.
Sharing a machine with other sessions
- One tab belongs to one session. If a tab is unavailable,
sessions_listsays who holds it; DevCDP opens its own window rather than sharing one. devtools_disconnectwhen finished, so the tab is released and the page left clean.
Telling the user what is happening
- Every tool call already announces itself on the page — "searching the source", "clicking Save order". What that cannot show is why, because your prose never reaches DevCDP; only your tool calls do.
- So
notify_useris how you speak. Call it whenever you would have said something out loud: what you are about to try, what you just concluded, what surprised you. The person is watching their own application, not the transcript, and a running commentary is the difference between "it is working on it" and "it is stuck". Two or three words is enough —notify_user(action:'debug', detail:'the save handler never fires'). session_ask_userwhen a step needs a human — logging in, choosing a record.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 60 lines · 859 tokens per session scan A 34b9f8dffb4e
DevCDP GEMINI.md is an instructions file published in the GitHub repository Dayananda-D/DevCDP (1 stars, last pushed yesterday), licensed MIT. It adds 859 tokens to every session, about $0.0043 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-10.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.