chassis copilot-instructions.md

Project-specific instructions for adding features to the Chassis TypeScript web service. They describe how its routes, responses, validation, configuration, errors, and generated resources should be written.

In plain words
What is it for?
Use them when adding API endpoints or resources, validating request data, handling errors, reading environment settings, generating database-backed code, and running the project's checks.
Why use it?
They prevent new code from conflicting with the project's existing structure and error-handling rules. They also define the verification command required before finishing.

Instructions file for GitHub Copilot

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/dvd90/chassis/copilot-instructions
Clone the repo
git clone --depth 1 https://github.com/dvd90/chassis

Made for: GitHub Copilot.

Per session 258 This file is loaded in full into every session.
When invoked 258 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00258 $0.00258
Opus 5 $0.00129 $0.00129
Sonnet 5 $0.00052 $0.00052
Haiku 4.5 $0.00026 $0.00026

Measured 2d ago against content hash fe9653114c56, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

chassis copilot-instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/copilot-instructions.md · 23 lines

What it actually says

Copilot instructions

This project follows the conventions in AGENTS.md — read it before making changes. Summary of the non-negotiables:

  • Endpoints are @route-decorated methods on a Routable controller; export the class from src/controllers/index.ts to mount it. There are no router files to edit.
  • Respond via req.resHandler (ok, created, notFound, conflict, …), never res.status().json().
  • Signal errors by throw new AppError(ERROR_CODES.X, message) — no try/catch in controllers; Express 5 forwards rejected promises to a central handler.
  • Validate input with validate({ body: zodSchema }) in the route's middleware array.
  • Only src/config reads process.env.
  • Don't edit src/core/** to build a feature.

Scaffold a new resource with npm run gen <Name> rather than hand-writing one — it is database-aware and wires the controller to the installed ORM.

Finish by running npm run verify (typecheck + lint + test) and make it pass before stopping.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 23 lines · 258 tokens per session scan A fe9653114c56

Subscribe to this mod's changes

chassis copilot-instructions.md is an instructions file published in the GitHub repository dvd90/chassis (6 stars, last pushed 26d ago), licensed MIT. It adds 258 tokens to every session, about $0.0013 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

react-starter-kit AGENTS.md

AGENTS.md instructions for kriasoft/react-starter-kit, covering monorepo structure, tech stack, commands, database: bun db:{push,generate,migrate,studio,seed,export} and verification.

kriasoft/react-starter-kit · 1,319 tokens

react-starter-kit CLAUDE.md

Claude Code instructions for kriasoft/react-starter-kit, a project described as: Modern React starter kit with Bun, TypeScript, Tailwind CSS, tRPC, Stripe, and Cloudflare Workers. Production-ready monorepo for building fast web apps.

kriasoft/react-starter-kit · 57 tokens

react-starter-kit copilot-instructions.md

Copilot instructions for kriasoft/react-starter-kit: Read AGENTS.md in the repository root and any subdirectory AGENTS.md files for project context, conventions, and architecture details before making changes.

kriasoft/react-starter-kit · 29 tokens

node-typescript-boilerplate AGENTS.md

Instructions for jsynowiec/node-typescript-boilerplate, covering agents.md, ground rules (always), typescript, node.js and testing (vitest).

jsynowiec/node-typescript-boilerplate · 543 tokens

nextarter-tailwind AGENTS.md

AGENTS.md instructions for agustinusnathaniel/nextarter-tailwind, covering next.js: always read docs before coding, ai agent guidance: nextarter-tailwind, 1. mental model for agents, implementation delegation and tooling strategy.

agustinusnathaniel/nextarter-tailwind · 1,839 tokens

appointme CLAUDE.md

Instructions for bravodev-hub/appointme, covering claude.md, build and development commands, running the full stack (recommended), backend only and frontend only.

bravodev-hub/appointme · 2,201 tokens