PixelPilot performance-auditor.instructions.md

An automated Lighthouse performance audit procedure. Lighthouse is a tool that checks web pages for speed, accessibility, good engineering practices, and search-engine readiness, including Core Web Vitals, which measure loading and interaction quality.

In plain words
What is it for?
Use it to audit a local or deployed page with Chrome DevTools or Lighthouse, capture metrics such as LCP, INP, and CLS, and plan fixes for failing scores.
Why use it?
It turns a general performance check into measured results and connects failed checks to a prioritized fix plan before release.

Instructions file for GitHub Copilot

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/dev-lou/pixelpilot/performance-auditor
Clone the repo
git clone --depth 1 https://github.com/dev-lou/PixelPilot

Made for: GitHub Copilot.

Per session 3,104 This file is loaded in full into every session.
When invoked 3,104 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.03104 $0.03104
Opus 5 $0.01552 $0.01552
Sonnet 5 $0.00621 $0.00621
Haiku 4.5 $0.00310 $0.00310

Measured yesterday against content hash b4fb6892ef80, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

PixelPilot performance-auditor.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

vscode/.github/instructions/performance-auditor.instructions.md · 364 lines

How it starts

The opening of the file, as written. The whole thing — 364 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Performance Auditor 2026

Run → capture → score → fix. Automates Lighthouse audits via MCP (headless Chrome), reports CWV, and maps every failing audit to a concrete, token-aware fix.


CORE WEB VITALS TARGETS (2026)

Metric Good Needs Improvement Poor
LCP Largest Contentful Paint ≤ 2.5 s 2.5–4.0 s > 4.0 s
INP Interaction to Next Paint ≤ 200 ms 200–500 ms > 500 ms
CLS Cumulative Layout Shift ≤ 0.1 0.1–0.25 > 0.25
FCP First Contentful Paint ≤ 1.8 s 1.8–3.0 s > 3.0 s
TTFB Time to First Byte ≤ 800 ms 800–1800 ms > 1800 ms
TBT Total Blocking Time ≤ 200 ms 200–600 ms > 600 ms

Score targets:

  • Performance: ≥ 90
  • Accessibility: ≥ 95
  • Best Practices: ≥ 95
  • SEO: ≥ 90

STEP 1 — CHOOSE AUDIT METHOD

Method A — Chrome DevTools MCP (preferred for local dev)

// Navigate to target
await browser_navigate({ url: TARGET_URL });

// Wait for page to fully load
await browser_evaluate({ script: `
  await new Promise(resolve => {
    if (document.readyState === 'complete') return resolve();
    window.addEventListener('load', resolve);
  });
  await new Promise(r => setTimeout(r, 1000));
` });

// Collect Web Vitals via PerformanceObserver
const vitals = await browser_evaluate({ script: `
  const nav = performance.getEntriesByType('navigation')[0];
  const paint = performance.getEntriesByType('paint');
  const lcp  = await new Promise(res => {
    new PerformanceObserver(list => {
      const entries = list.getEntries();
      res(entries[entries.length - 1].startTime);
    }).observe({ type: 'largest-contentful-paint', buffered: true });
    setTimeout(() => res(null), 3000);
  });
  return {
    TTFB:  nav?.responseStart - nav?.requestStart,
    FCP:   paint.find(e => e.name === 'first-contentful-paint')?.startTime,
    LCP:   lcp,
    TBT:   nav?.domComplete - nav?.domInteractive,
    domSize: document.querySelectorAll('*').length,
    scripts: performance.getEntriesByType('resource')
             .filter(r => r.initiatorType === 'script')
             .map(r => ({ url: r.name.split('/').pop(), size: r.transferSize, duration: r.duration }))
             .sort((a,b) => b.size - a.size)
             .slice(0, 10),
    images:  performance.getEntriesByType('resource')
             .filter(r => r.initiatorType === 'img')
             .map(r => ({ url: r.name.split('/').pop(), size: r.transferSize }))
             .sort((a,b) => b.size - a.size)
             .slice(0, 10),
    thirdParty: performance.getEntriesByType('resource')
             .filter(r => !r.name.includes(location.hostname))
             .reduce((acc, r) => acc + r.transferSize, 0),
  };
` });

Read the full file on GitHub · 364 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 364 lines · 3,104 tokens per session scan A b4fb6892ef80

Subscribe to this mod's changes

PixelPilot performance-auditor.instructions.md is an instructions file published in the GitHub repository dev-lou/PixelPilot (2 stars, last pushed 4mo ago), licensed MIT. It adds 3,104 tokens to every session, about $0.0155 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.