Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/forgesworn/402-mcp/copilot-instructionsgit clone --depth 1 https://github.com/forgesworn/402-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/forgesworn/402-mcp/copilot-instructions)<a href="https://agentmods.dev/instructions/forgesworn/402-mcp/copilot-instructions"><img src="https://agentmods.dev/badge/instructions/forgesworn/402-mcp/copilot-instructions.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00555 | $0.00555 |
| Opus 5 | $0.00278 | $0.00278 |
| Sonnet 5 | $0.00111 | $0.00111 |
| Haiku 4.5 | $0.00056 | $0.00056 |
Grade A, and why
402-mcp copilot-instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- 402-mcp GEMINI.md — 95% identical, 2 lines differ
How it starts
The opening of the file, as written. The whole thing — 37 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Copilot Instructions — 402-mcp
L402 + x402 client MCP server. AI agents discover, pay for, and consume any payment-gated API autonomously.
Commands
npm run build— compile TypeScript to build/npm test— run all tests (vitest)npm run typecheck— type-check without emitting
Conventions
- British English — colour, initialise, behaviour, licence
- ESM-only —
"type": "module", target ES2022, module Node16 - Tool pattern — each tool file exports a
handle*function (testable with injected deps) and aregister*Toolfunction (MCP wiring) - Tests live in
tests/, not co-located with source. Each handler'shandle*function is tested directly with mock deps usingvi.fn() - Commit messages —
type: descriptionformat (feat:, fix:, docs:, chore:, refactor:). No Co-Authored-By lines.
Key Patterns
- Atomic spend tracking — always use
spendTracker.tryRecord(sats, limit), never splitwouldExceed()+record()(TOCTOU race) - Preimage validation — validate hex format before storing. Preimages are sent raw in
Authorization: L402 {macaroon}:{preimage}headers - SSRF guard — all outbound HTTP goes through the SSRF guard. Money-mutating POSTs pass
{ retries: 0 }to disable retry - cashu-ts v2 —
getDecodedToken()returns{ mint, proofs, unit }at top level. There is NO.tokenarray - nostr-tools NIP-44 — use
getConversationKey(privkey, pubkey)thenencrypt(plaintext, conversationKey). Do NOT use NIP-04
Structure
src/index.ts— entry point: config, wiring, transport setupsrc/config.ts— environment variable parsing with validationsrc/tools/— one file per MCP tool (handler + registration)src/wallet/— payment implementations (NWC, Cashu, human-in-the-loop)src/store/— persistent JSON stores (credentials, Cashu tokens)src/l402/— L402 protocol utilities (parse, detect, cache, bolt11)src/fetch/— resilient fetch: SSRF guard, timeout, retry, transport selectiontests/— mirrors src/ structure
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 37 lines · 555 tokens per session scan A 9da7b5f5ec65
402-mcp copilot-instructions.md is an instructions file published in the GitHub repository forgesworn/402-mcp (0 stars, last pushed 12d ago), licensed MIT. It adds 555 tokens to every session, about $0.0028 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
ln-agent-poc-v2 CLAUDE.md
Instructions for cachet-jp/ln-agent-poc-v2, covering claude.md, project, layout, common commands and architecture notes.
cashu.me AGENTS.md
Instructions for cashubtc/cashu.me, covering cashu.me developer guide for agents, 1. tech stack, core frameworks, mobile & desktop and cashu & cryptography.
sparkbtcbot CLAUDE.md
Claude Code instructions for echennells/sparkbtcbot, covering sparkbtcbot, what this skill does, structure, trigger phrases and dependencies.
SaturnZap copilot-instructions.md
Instructions for lqwdtech/SaturnZap, covering saturnzap — copilot instructions, build & test, architecture, conventions and test patterns.
SaturnZap tests.instructions.md
Use when writing, editing, or debugging SaturnZap tests. Covers fixtures, mocking patterns, CLI runner usage, and live test markers.
lightning-enable-mcp CLAUDE.md
Instructions for refined-element/lightning-enable-mcp, covering claude.md — lightning enable mcp, project overview, bug fix workflow and engineering standards.