PixelPilot uiux-easter-eggs.instructions.md

A guide for adding optional hidden interactions and surprises to an interface, such as the Konami code, secret features, or achievement unlocks. It also covers accessibility alternatives, performance, and keeping essential features visible.

In plain words
What is it for?
Use it to design and implement easter eggs, keyboard-sequence detectors, hidden interactions, and optional rewards in an interface.
Why use it?
It helps make exploration rewarding without hiding required functions, disrupting normal use, or excluding people who cannot perform the secret interaction.

Instructions file for GitHub Copilot

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/dev-lou/pixelpilot/uiux-easter-eggs
Clone the repo
git clone --depth 1 https://github.com/dev-lou/PixelPilot

Made for: GitHub Copilot.

Per session 4,164 This file is loaded in full into every session.
When invoked 4,164 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.04164 $0.04164
Opus 5 $0.02082 $0.02082
Sonnet 5 $0.00833 $0.00833
Haiku 4.5 $0.00416 $0.00416

Measured 2d ago against content hash e74a8ba63b02, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

PixelPilot uiux-easter-eggs.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

vscode/.github/instructions/uiux-easter-eggs.instructions.md · 699 lines

How it starts

The opening of the file, as written. The whole thing — 699 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Easter Eggs & Delightful Surprises

The best interfaces reward curiosity. This file covers hidden features, secret interactions, achievement unlocks, and delightful surprises that make users smile — without being annoying or inaccessible.


CRITICAL RULES

  1. Never hide essential features — Easter eggs are bonuses, not requirements.
  2. Accessible alternatives — If a secret is useful, provide another path to it.
  3. Don't break flow — Surprises should delight, not disrupt.
  4. Respect context — No easter eggs in serious/medical/legal contexts.
  5. Performance — Hidden features shouldn't load until triggered.

KONAMI CODE DETECTOR

The classic: ↑ ↑ ↓ ↓ ← → ← → B A

// useKonamiCode.ts
const KONAMI_CODE = [
  'ArrowUp', 'ArrowUp',
  'ArrowDown', 'ArrowDown',
  'ArrowLeft', 'ArrowRight',
  'ArrowLeft', 'ArrowRight',
  'KeyB', 'KeyA',
];

export function useKonamiCode(callback: () => void) {
  const [index, setIndex] = useState(0);

  useEffect(() => {
    const handleKeyDown = (e: KeyboardEvent) => {
      const expectedKey = KONAMI_CODE[index];
      
      if (e.code === expectedKey) {
        const nextIndex = index + 1;
        
        if (nextIndex === KONAMI_CODE.length) {
          callback();
          setIndex(0);
        } else {
          setIndex(nextIndex);
        }
      } else {
        setIndex(0);
      }
    };

    window.addEventListener('keydown', handleKeyDown);
    return () => window.removeEventListener('keydown', handleKeyDown);
  }, [index, callback]);
}

// Usage
function App() {
  const [partyMode, setPartyMode] = useState(false);

  useKonamiCode(() => {
    setPartyMode(true);
    swal.toast('🎉 Party mode activated!');
  });

  return (
    <div className={partyMode ? 'party-mode' : ''}>
      {/* ... */}
    </div>
  );
}

CUSTOM SECRET CODES

Create your own activation sequences:

// useSecretCode.ts
interface SecretCodeOptions {
  sequence: string[];      // Keys to detect
  timeout?: number;        // Reset after X ms of inactivity
  onActivate: () => void;
  onProgress?: (progress: number) => void;
}

export function useSecretCode({
  sequence,
  timeout = 2000,
  onActivate,
  onProgress,
}: SecretCodeOptions) {
  const [index, setIndex] = useState(0);
  const timeoutRef = useRef<number>();

  useEffect(() => {
    const handleKeyDown = (e: KeyboardEvent) => {
      // Clear previous timeout
      if (timeoutRef.current) {
        clearTimeout(timeoutRef.current);
      }

      const expectedKey = sequence[index];
      
      if (e.code === expectedKey || e.key.toLowerCase() === expectedKey.toLowerCase()) {
        const nextIndex = index + 1;
        onProgress?.(nextIndex / sequence.length);
        
        if (nextIndex === sequence.length) {
          onActivate();
          setIndex(0);
        } else {
          setIndex(nextIndex);
          
          // Reset after timeout
          timeoutRef.current = window.setTimeout(() => {
            setIndex(0);
            onProgress?.(0);
          }, timeout);
        }
      } else if (e.key.length === 1) {
        // Wrong key - reset (but ignore modifier keys)
        setIndex(0);
        onProgress?.(0);
      }
    };

    window.addEventListener('keydown', handleKeyDown);
    return () => {
      window.removeEventListener('keydown', handleKeyDown);
      if (timeoutRef.current) clearTimeout(timeoutRef.current);
    };
  }, [sequence, index, timeout, onActivate, onProgress]);

  return { progress: index / sequence.length };
}

// Usage: Type "debug" to open debug panel
function App() {
  const [showDebug, setShowDebug] = useState(false);

  useSecretCode({
    sequence: ['d', 'e', 'b', 'u', 'g'],
    onActivate: () => setShowDebug(true),
  });

  return (
    <>
      {/* ... */}
      {showDebug && <DebugPanel onClose={() => setShowDebug(false)} />}
    </>
  );
}

Read the full file on GitHub · 699 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 699 lines · 4,164 tokens per session scan A e74a8ba63b02

Subscribe to this mod's changes

PixelPilot uiux-easter-eggs.instructions.md is an instructions file published in the GitHub repository dev-lou/PixelPilot (2 stars, last pushed 4mo ago), licensed MIT. It adds 4,164 tokens to every session, about $0.0208 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.