Borrowing it
Nothing to install: this file belongs to emiliaprotocol/emilia-protocol. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/emiliaprotocol/emilia-protocol/main/CLAUDE.mdgit clone --depth 1 https://github.com/emiliaprotocol/emilia-protocolWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/emiliaprotocol/emilia-protocol/claude-md)<a href="https://agentmods.dev/instructions/emiliaprotocol/emilia-protocol/claude-md"><img src="https://agentmods.dev/badge/instructions/emiliaprotocol/emilia-protocol/claude-md/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/instructions/emiliaprotocol/emilia-protocol/claude-md"><img src="https://agentmods.dev/badge/instructions/emiliaprotocol/emilia-protocol/claude-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00852 | $0.00852 |
| Opus 5 | $0.00426 | $0.00426 |
| Sonnet 5 | $0.00170 | $0.00170 |
| Haiku 4.5 | $0.00085 | $0.00085 |
Grade A, and why
emilia-protocol CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 37 lines — stays where its author put it; the contents beside it link to each section on GitHub.
EMILIA Protocol - Repo Guide
Required context
- Read
AGENTS.mdandAI_CONTEXT.mdbefore analyzing or editing this repository. - Use
public/.well-known/emilia-context.jsonfor current evidence counts and provenance. - Do not infer current behavior or standards status from archived, staged, private, or randomly sampled documents.
Critical
- This repo is PUBLIC. Everything tracked is world-readable. Business, strategy, GTM, investor, fundraising, outreach, competitive, and pitch material belongs in the private
emiliaprotocol/emilia-companyrepository, never in tracked paths here.docs/strategy-private/remains ignored only as a compatibility safeguard, not as a source of truth. Runnpm run check:repository-boundarybefore publishing. When in doubt, don'tgit addit. - main == production within minutes. Multiple agent sessions commit and push this same checkout in near-real-time, so a local commit is NOT a hold. Anything that must not publish yet goes on a branch or stays outside the repo. Re-fetch before reasoning about origin state.
- Branch protection is active. Prefer a branch and pull request for reviewable changes, and do not treat owner bypass as independent review. Until a second human maintainer exists, any owner-bypass direct push must be locally verified and documented in its commit.
Build & ship
- Run the full production build before pushing, not just tsc/eslint/tests.
- Don't sit and watch CI after pushing; push and continue, fix only if it fails.
Outbound & claims
This repo owns the VERIFIED-vs-ACCEPTED and reproduction-vs-independent distinctions, so its own outbound is held to them. Before any EMILIA/IETF/standards email, list post, or draft:
- Read the exact artifact before you describe it. Run or read the specific file in
examples/orconformance/that backs each claim, never a memory of how it works. The current seam is precise: inexamples/scitt/capsule-seam-vector-v2.mjsthe shipped EP verifier checks the Signed Statement and carried receipt offline; a separate binding check joins it to the Capsule action and authority reference. Say that, not "both verified together." The unversionedcapsule-seam-vector.jsonis an immutable legacy compatibility artifact, not profile-valid SCITT evidence. - The five traps: (1) an external party re-running an
@emilia-protocolpackage is REPRODUCTION, never an "independent implementation." (2) VERIFIED (crypto checks pass) never collapses into ACCEPTED (trusted under a pinned root). (3) "fail-closed" means malformed or attacker input returns a reason, not a crash: prove it against the bad input. (4) composition legs join by a shared action digest, never by one verifier ingesting another's evidence into its trust boundary. (5) no EP Internet-Draft is IETF-adopted or endorsed.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 37 lines · 852 tokens per session scan A 16690437210b
emilia-protocol CLAUDE.md is an instructions file published in the GitHub repository emiliaprotocol/emilia-protocol (650 stars, last pushed yesterday), licensed Apache-2.0. It adds 852 tokens to every session, about $0.0043 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.