contextweaver context.instructions.md

Project instructions for ContextWeaver’s context engine, which selects and assembles information for an agent’s prompt.

In plain words
What is it for?
Changing context selection, dependency handling, filtering, firewall checks, scoring, duplicate removal, token-budget selection, or prompt assembly.
Why use it?
They preserve the required order of eight processing stages and ensure sensitive or unsafe raw tool output does not reach the prompt.

Instructions file for GitHub Copilot

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/dgenio/contextweaver/context
Clone the repo
git clone --depth 1 https://github.com/dgenio/contextweaver

Made for: GitHub Copilot.

Per session 1,093 This file is loaded in full into every session.
When invoked 1,093 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01093 $0.01093
Opus 5 $0.00547 $0.00547
Sonnet 5 $0.00219 $0.00219
Haiku 4.5 $0.00109 $0.00109

Measured yesterday against content hash a90cd5d94103, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

contextweaver context.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/instructions/context.instructions.md · 92 lines

How it starts

The opening of the file, as written. The whole thing — 92 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Context Engine — Agent Instructions

Path-scoped guidance for src/contextweaver/context/. Read before modifying any file here.

Pipeline stage ordering (must not be reordered)

ContextManager.build() executes exactly these 8 stages in order:

  1. generate_candidates (candidates.py) — phase + policy filter over event log
  2. resolve_dependency_closure (candidates.py) — pull in parent items via parent_id
  3. apply_sensitivity_filter (sensitivity.py) — drop/redact by sensitivity level
  4. apply_firewall_to_batch (firewall.py) — intercept raw tool_result text
  5. score_candidates (scoring.py) — recency + Jaccard token overlap + kind priority + token penalty
  6. deduplicate_candidates (dedup.py) — near-duplicate removal
  7. select_and_pack (selection.py) — budget-aware token selection
  8. render_context (prompt.py) — final prompt assembly

Never reorder these stages. Stages 2 and 4 have hard ordering constraints: dependency closure must run before scoring (ancestors must be scoreable), and the firewall must run before scoring (summaries, not raw text, must be scored).

Firewall invariants

  • Raw tool_result text never reaches the prompt. apply_firewall replaces item.text with a summary and stores the raw bytes in ArtifactStore.
  • The artifact handle is always f"artifact:{item.id}".
  • item.artifact_ref is set on every firewall-processed item.
  • Do not bypass apply_firewall_to_batch or move raw text past stage 4.
  • See firewall.py and docs/agent-context/invariants.md for full rationale.

Async-first pattern

  • The core pipeline runs in _build(), which is synchronous. Both build() (async) and build_sync() (sync) delegate directly to _build().
  • build() is async def so callers can await it today; true async I/O will be added if pipeline stages gain await-able steps in the future.
  • Do not wrap _build() in asyncio.run()build_sync() calls it directly.
  • The same pattern applies to _build_call_prompt()build_call_prompt() / build_call_prompt_sync().
  • When the manager is async-backed (an async store was passed), the async entry points build() and build_call_prompt() offload the synchronous pipeline body to a worker thread (issue #495) so the awaited store I/O does not block the caller's event loop. _build() holds self._build_lock so concurrent builds on one manager serialize and never race on the thread-unsafe in-memory stores. Keep the lock around the pipeline body if you touch _build(), and offload any new async pipeline entry point the same way.
  • The private store loop thread is released via weakref.finalize, not a close() method — do not add ContextManager.close() (or other public lifecycle methods) until the #73/#69 decomposition lands. For deterministic teardown call the finalizer (mgr._store_loop_finalizer()).

Read the full file on GitHub · 92 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 92 lines · 1,093 tokens per session scan A a90cd5d94103

Subscribe to this mod's changes

contextweaver context.instructions.md is an instructions file published in the GitHub repository dgenio/contextweaver (9 stars, last pushed 2d ago), licensed Apache-2.0. It adds 1,093 tokens to every session, about $0.0055 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.