Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/edithatogo/sourceright/copilot-instructionsgit clone --depth 1 https://github.com/edithatogo/sourcerightWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/edithatogo/sourceright/copilot-instructions)<a href="https://agentmods.dev/instructions/edithatogo/sourceright/copilot-instructions"><img src="https://agentmods.dev/badge/instructions/edithatogo/sourceright/copilot-instructions.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00519 | $0.00519 |
| Opus 5 | $0.00260 | $0.00260 |
| Sonnet 5 | $0.00104 | $0.00104 |
| Haiku 4.5 | $0.00052 | $0.00052 |
Grade A, and why
sourceright copilot-instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 69 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Sourceright Copilot Instructions
Use the current repository as the source of truth. Do not bulk-apply material
from .codex-plan/, do not overwrite existing Rust modules, and do not split
the crate into a workspace unless an issue explicitly asks for that after an
audit.
Preserve the project boundaries:
references.csl.jsonis canonical clean bibliographic data.references.verification.jsonstores provider evidence, provenance, confidence, conflicts, and review state.review-queue.jsonlis derived operational review work.- Provider data must not silently overwrite canonical CSL.
- Legal citations remain separate from academic CSL.
- Claim/source/provenance work must not assert claim truth.
- MCP write tools need stable read-only contracts, schemas, audit logs, and dry-run semantics before they write.
Prefer small, reviewable pull requests. For dependency or security work, keep changes narrowly scoped to the vulnerable dependency, pinned action, pinned image, workflow permission, or policy surface being remediated.
Use these checks when relevant:
cargo fmt --check
cargo clippy --all-targets -- -D warnings
cargo test
cargo check --locked
cargo run --bin sourceright -- bench
For docs-site changes, also run:
cd docs-site
npm ci
npm run build
When touching GitHub Actions, keep permissions least-privilege, keep actions pinned by full commit SHA, and avoid scheduled or notification-heavy workflows unless the issue explicitly requests them.
Conductor Track Workflow
Each implementation slice should reference a Conductor track by its ID
(e.g., 64-github-side-governance-additions). Before editing files under a
track's owned paths, run $conductor-review (if available) or manually verify:
- The track spec and test matrix are up to date.
- Changes stay within declared owned paths.
- Evidence level in
conductor/evidence-ledger.jsonaccurately reflects what was done.
Forbidden Claims
Sourceright code, docs, and PR metadata must never assert:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 69 lines · 519 tokens per session scan A b1ee9c9e0d88
sourceright copilot-instructions.md is an instructions file published in the GitHub repository edithatogo/sourceright (1 stars, last pushed yesterday), licensed MIT. It adds 519 tokens to every session, about $0.0026 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
med-paper-assistant AGENTS.md
AGENTS.md instructions for u9401066/med-paper-assistant, covering agents.md - vs code copilot agent 指引, 核心價值:逐步多輪演進, 運行模式, 檔案保護(normal/research) and 專案規則.
scientific-writing CLAUDE.md
Instructions for koljaschoepe/scientific-writing, covering scientific writing framework, schnellstart, workflow, befehle and regeln für generierte texte.
scitex-python CLAUDE.md
Claude Code instructions for scitex-ai/scitex-python, covering workflow orchestration, 1. plan mode default, 2. subagent strategy, 3. self-improvement loop and 4. verification before done.
avoid-overkill AGENTS.md
AGENTS.md instructions for 6Kmfi6HP/avoid-overkill: This repository packages a reusable Agent Skill and plugin manifests.
academic-writer-skills AGENTS.md
AGENTS.md instructions for muhammad1438/academic-writer-skills, covering academic writer skills — multi-agent workflow guide, skill dependency map, pipeline patterns, pattern 1: full research paper and pattern 2: grant application pipeline.
SciCrucible CLAUDE.md
Claude Code instructions for Xinyang-Li666/SciCrucible, covering 科学知识库, 知识库结构, 可用命令, 项目目录 and 工作原则.