Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/erniker/understudy/guardrailsgit clone --depth 1 https://github.com/erniker/understudyWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.02193 | $0.02193 |
| Opus 5 | $0.01097 | $0.01097 |
| Sonnet 5 | $0.00439 | $0.00439 |
| Haiku 4.5 | $0.00219 | $0.00219 |
Grade A, and why
understudy guardrails.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories โ prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency โ measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing โ 240 lines โ stays where its author put it; the contents beside it link to each section on GitHub.
๐ก๏ธ Guardrails โ Security and Behavior Limits of the Understudy
๐ฏ This file applies to ALL team agents.
In VS Code it auto-applies to all files (applyTo: "**").
In Copilot CLI it is activated with /instructions.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ What are guardrails? โ
โ โ
โ They are security and behavior limits that ALL โ
โ Understudy agents must respect, without exception. โ
โ They protect against: โ
โ - Unauthorized destructive actions โ
โ - Data or secret leaks โ
โ - Out-of-scope or unapproved changes โ
โ - Process violations (code without spec, without tests) โ
โ - Impact on production without change control โ
โ โ
โ Guardrails are NOT suggestions โ they are hard โ
โ restrictions that the agent MUST comply with. โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
1. ๐ก๏ธ Security
NEVER
- Generate code with hardcoded credentials, tokens, API keys, passwords or secrets
- Store secrets in files, pipeline environment variables, logs or comments
- Disable or bypass existing security controls (APIM policies, WAF rules, auth middleware)
- Generate code that accesses data beyond the scope defined in the task
- Suggest workarounds that circumvent governance, auditing or compliance
ALWAYS
- Use vault services (Key Vault, Secrets Manager) to retrieve secrets
- Use Managed Identity or approved Service Principals for authentication between services
- Validate and sanitize ALL inputs at system boundaries
- Apply the principle of least privilege to all identities and access
- Include audit logging for sensitive operations
- Treat all external inputs as untrusted
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen ยท 240 lines ยท 2,193 tokens per session scan A 9cdcad456f69
understudy guardrails.instructions.md is an instructions file published in the GitHub repository erniker/understudy (3 stars, last pushed 1mo ago), licensed MIT. It adds 2,193 tokens to every session, about $0.0110 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
codedb AGENTS.md
Instructions for justrach/codedb, covering codedb agent guidelines, what codedb is (and isn't), review guidelines, pre-merge verification and security-sensitive areas.
shep CLAUDE.md
Instructions for shep-ai/shep, covering claude.md, project, spec workflow, commands and architecture.
ai-helpers AGENTS.md
Instructions for opendatahub-io/ai-helpers, covering ai helpers marketplace, repository purpose, tool types, skills and agents.
FsLangMCP CLAUDE.md
Instructions for Neftedollar/FsLangMCP, covering fslangmcp โ business workspace, how to start (required for every session), 1. determine mode, 2. load context (depends on mode) and 3. act.
fast-mcp-telegram CLAUDE.md
Claude Code instructions for leshchenko1979/fast-mcp-telegram, covering fast-mcp-telegram, session corrections and 2026-05-27.
free-ai-gateway AGENTS.md
Instructions for zaber-dev/free-ai-gateway, covering ๐ค free-ai gateway - agentic development guidelines, ๐๏ธ monorepo architecture & package boundaries, ๐ strict architectural rules for agents, ๐ป essential developer commands and build all packages across monorepo.