Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/dgenio/contextweaver/contextgit clone --depth 1 https://github.com/dgenio/contextweaverWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01093 | $0.01093 |
| Opus 5 | $0.00547 | $0.00547 |
| Sonnet 5 | $0.00219 | $0.00219 |
| Haiku 4.5 | $0.00109 | $0.00109 |
Grade A, and why
contextweaver context.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 92 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Context Engine — Agent Instructions
Path-scoped guidance for src/contextweaver/context/. Read before modifying any file here.
Pipeline stage ordering (must not be reordered)
ContextManager.build() executes exactly these 8 stages in order:
generate_candidates(candidates.py) — phase + policy filter over event logresolve_dependency_closure(candidates.py) — pull in parent items viaparent_idapply_sensitivity_filter(sensitivity.py) — drop/redact by sensitivity levelapply_firewall_to_batch(firewall.py) — intercept rawtool_resulttextscore_candidates(scoring.py) — recency + Jaccard token overlap + kind priority + token penaltydeduplicate_candidates(dedup.py) — near-duplicate removalselect_and_pack(selection.py) — budget-aware token selectionrender_context(prompt.py) — final prompt assembly
Never reorder these stages. Stages 2 and 4 have hard ordering constraints: dependency closure must run before scoring (ancestors must be scoreable), and the firewall must run before scoring (summaries, not raw text, must be scored).
Firewall invariants
- Raw
tool_resulttext never reaches the prompt.apply_firewallreplacesitem.textwith a summary and stores the raw bytes inArtifactStore. - The artifact handle is always
f"artifact:{item.id}". item.artifact_refis set on every firewall-processed item.- Do not bypass
apply_firewall_to_batchor move raw text past stage 4. - See
firewall.pyanddocs/agent-context/invariants.mdfor full rationale.
Async-first pattern
- The core pipeline runs in
_build(), which is synchronous. Bothbuild()(async) andbuild_sync()(sync) delegate directly to_build(). build()isasync defso callers canawaitit today; true async I/O will be added if pipeline stages gainawait-able steps in the future.- Do not wrap
_build()inasyncio.run()—build_sync()calls it directly. - The same pattern applies to
_build_call_prompt()→build_call_prompt()/build_call_prompt_sync(). - When the manager is async-backed (an async store was passed), the async
entry points
build()andbuild_call_prompt()offload the synchronous pipeline body to a worker thread (issue #495) so the awaited store I/O does not block the caller's event loop._build()holdsself._build_lockso concurrent builds on one manager serialize and never race on the thread-unsafe in-memory stores. Keep the lock around the pipeline body if you touch_build(), and offload any new async pipeline entry point the same way. - The private store loop thread is released via
weakref.finalize, not aclose()method — do not addContextManager.close()(or other public lifecycle methods) until the #73/#69 decomposition lands. For deterministic teardown call the finalizer (mgr._store_loop_finalizer()).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 92 lines · 1,093 tokens per session scan A a90cd5d94103
contextweaver context.instructions.md is an instructions file published in the GitHub repository dgenio/contextweaver (9 stars, last pushed 2d ago), licensed Apache-2.0. It adds 1,093 tokens to every session, about $0.0055 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
kindex CLAUDE.md
Instructions for jmcentire/kindex, covering kindex — knowledge graph for ai-assisted workflows, running tests, all tests, specific module and with coverage.
ChainWeaver AGENTS.md
Instructions for dgenio/ChainWeaver, covering chainweaver — agent instructions, 1. project identity, 2. domain vocabulary, 3. repository layout and 4. core invariants.
ChainWeaver copilot-instructions.md
Instructions for dgenio/ChainWeaver, covering copilot instructions — chainweaver, scoped guidance, review-critical rules, executor guardrails and vocabulary.
ChainWeaver testing.instructions.md
Instructions for dgenio/ChainWeaver, covering testing instructions — chainweaver, framework, structure, fixtures and coverage patterns.
ChainWeaver python-source.instructions.md
Instructions for dgenio/ChainWeaver, covering python source instructions — chainweaver, module conventions, pydantic patterns, exception patterns and export rules.
ChainWeaver chainweaver.instructions.md
Instructions for dgenio/ChainWeaver: Also read the nearest path-scoped AGENTS.md for the subtree you are changing — the index is in AGENTS.md § 11.