Hermes_WorldKit_MCP AGENTS.md

Hermes_WorldKit_MCP AGENTS.md is an instructions file for Codex, OpenCode from DeployFaith/Hermes_WorldKit_MCP. It costs 420 tokens per session, scanned A, original, MIT.

A set of AGENTS.md instructions for a WorldKit MCP control-plane repository, which connects AI agents with a Godot editor. It defines the repository's role, security boundaries, allowed operations, and validation rules.

In plain words
What is it for?
Use it to guide agent work on the repository, enforce authenticated local editor connections, restrict Godot operations to an allowlist, and validate scene selections and project roots.
Why use it?
It prevents agents from treating this control plane as the game engine or from making unsafe, unrestricted changes. The rules limit connections, authentication, file access, and editor operations.

Instructions file for CodexOpenCode

Written for Codex and OpenCode: the file is AGENTS.md. Also seen: mentions AGENTS.md.

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/deployfaith/hermes_worldkit_mcp/agents-md
Clone the repo
git clone --depth 1 https://github.com/DeployFaith/Hermes_WorldKit_MCP

Made for: Codex, OpenCode.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for Hermes_WorldKit_MCP AGENTS.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/deployfaith/hermes_worldkit_mcp/agents-md.svg)](https://agentmods.dev/instructions/deployfaith/hermes_worldkit_mcp/agents-md)
Your own site
<a href="https://agentmods.dev/instructions/deployfaith/hermes_worldkit_mcp/agents-md"><img src="https://agentmods.dev/badge/instructions/deployfaith/hermes_worldkit_mcp/agents-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 420 This file is loaded in full into every session.
When invoked 420 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00420 $0.00420
Opus 5 $0.00210 $0.00210
Sonnet 5 $0.00084 $0.00084
Haiku 4.5 $0.00042 $0.00042

Measured 5d ago against content hash 26ea17cc575a, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

Hermes_WorldKit_MCP AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 31 lines

How it starts

The opening of the file, as written. The whole thing — 31 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AGENTS.md

Repository identity

This repository is the separate, first-party WorldKit MCP control plane. It is not WorldKit Core and is not a base dependency of the WorldKit Godot adapter.

Hard boundaries

  • Do not add this repository as a dependency of WorldKit Core or addons/hermes_worldkit.
  • The Godot component is an optional EditorPlugin, installable at addons/worldkit_mcp_bridge.
  • The Python process is a FastMCP stdio server for agents and a localhost-only WebSocket server for the outbound Godot editor connection.
  • Require protocol-v2 mutual nonce/HMAC authentication and exact canonical project-root pinning before accepting a bridge client. Never transmit or log the raw token.
  • Bind and connect only to literal loopback addresses. Reject browser Origin headers and require one atomically claimed editor client.
  • Expose only explicit allowlisted operations. No terminal, shell, arbitrary file writes, GDScript evaluation, generic method invocation, unrestricted property mutation, runtime autoload, or project-setting mutation.
  • Selection operations require the exact inspected scene token and may address only canonical, owned, non-internal nodes under the current edited-scene root.
  • Bound editor-main-thread work, request queues, scene traversal, and selection serialization.
  • Every request and response carries a request ID. Failures use stable structured error codes.
  • Every MCP tool has a clear docstring and strict-client-friendly input schema: no Optional/union parameters and no anyOf.

Vertical-slice tool allowlist

  • worldkit_status
  • worldkit_capabilities
  • worldkit_scene_summary
  • worldkit_selected_nodes
  • worldkit_select_node(node_path, expected_scene_token)

Validation discipline

Use the project-local .venv via uv. Run Python tests, lint, server import, and generated FastMCP schema checks. Godot headless parsing is valuable but is not editor E2E. Never claim editor E2E without actually running an editor and exercising the plugin.

Read the full file on GitHub · 31 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 31 lines · 420 tokens per session scan A 26ea17cc575a

Subscribe to this mod's changes

Hermes_WorldKit_MCP AGENTS.md is an instructions file published in the GitHub repository DeployFaith/Hermes_WorldKit_MCP (0 stars, last pushed 1mo ago), licensed MIT. It adds 420 tokens to every session, about $0.0021 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

unity-code-style-guide AGENTS.md

Instructions for krogh-jacobsen/unity-code-style-guide, covering agents.md — unity 6 c, project setup — edit this block, never do these — they corrupt the project, deprecated in unity 6 and if you read nothing else.

krogh-jacobsen/unity-code-style-guide · 4,528 tokens

nes-php-glfw copilot-instructions.md

Instructions for oliverearl/nes-php-glfw, covering github copilot development guidelines for nes emulator, agent document source of truth, project overview, code style & standards and documentation.

oliverearl/nes-php-glfw · 2,719 tokens

game-and-watch-retro-go-sd CLAUDE.md

Claude Code instructions for sylverb/game-and-watch-retro-go-sd, covering claude.md, what this project is, build / flash workflow, architecture and three storage tiers, one elf.

sylverb/game-and-watch-retro-go-sd · 2,946 tokens

base-building-trap-defense-design-agent-skill CLAUDE.md

Instructions for dungnotnull/base-building-trap-defense-design-agent-skill, covering claude.md — skill 250: base-building-trap-defense-design, skill identity, problem this skill solves, harness flow summary and sub-skills.

dungnotnull/base-building-trap-defense-design-agent-skill · 1,910 tokens

trident-mcp AGENTS.md

Instructions for mordor-forge/trident-mcp, covering agents.md, what this is, build and test, single-file verification and e2e tests.

mordor-forge/trident-mcp · 1,465 tokens

unreal-mcp-additional-tools CLAUDE.md

Claude Code instructions for nodormu/unreal-mcp-additional-tools, covering claude.md, what this is, commands, architecture and transports (src/transports/).

nodormu/unreal-mcp-additional-tools · 1,727 tokens