bobbit AGENTS.md

Repository instructions for Bobbit, covering its commands, architecture, editing workflow, and test levels. They explain where the server, user interface, agent runtime, and MCP tools live.

In plain words
What is it for?
Use them when building or running Bobbit, changing its interface or server, restarting services, and running layout, unit, browser, end-to-end, or manual tests.
Why use it?
They help contributors find the right code and choose the appropriate checks after making changes.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/g-research/bobbit/agents-md
Clone the repo
git clone --depth 1 https://github.com/G-Research/bobbit

Made for: Codex, OpenCode.

Per session 1,551 This file is loaded in full into every session.
When invoked 1,551 The same file — it is already loaded in full.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01551 $0.01551
Opus 5 $0.00776 $0.00776
Sonnet 5 $0.00310 $0.00310
Haiku 4.5 $0.00155 $0.00155

Measured 2d ago against content hash cdb3885bc3bc, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

bobbit AGENTS.md scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

**Driving the gateway from an agent**: prefer the `bobbit_read`/`bobbit_orchestrate`/`bobbit_admin` tools over hand-rolled `curl` where their tool-groups are enabled. See [docs/bobbit-gateway-tool.md](docs/bobbit-gateway
AGENTS.md · 78 lines

How it starts

The opening of the file, as written. The whole thing — 78 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Bobbit — Agent Guide

Commands

npm run build          # Build server + UI
npm run dev:harness    # Gateway + vite dev
npm run restart-server # Rebuild & restart after server changes
npm run check          # Layout + type checks
npm run test:layout    # Validate test conventions
npm run test:new -- <semantic> <name> # Scaffold canonical test
npm run test:unit      # Vitest tier-1, fixed 3-worker cap
npm run test:browser   # Playwright browser-v2
npm run test:e2e       # E2E v2: git/worktree/Docker/MCP/restart
npm run test:manual    # Real agents/LLM + Docker (~5 min); ONLY gate-exempt path

UI changes (src/ui/, src/app/) hot-reload under npm run dev:harness. Server changes (src/server/) require npm run restart-server. Run npm run check first. Sessions survive restarts via .bobbit/state/sessions.json.

Architecture map

Orient here, then rg for the symbol.

  • Server REST/WS: src/server/ — REST in server.ts::handleApiRoute(), WS in src/server/ws/.
  • Agent runtime: src/server/agent/ — sessions, manager, status, steer, respawn, store, project context. See docs/bg-process-persistence.md for bash_bg.
  • MCP / tools: src/server/mcp/, defaults/tools/<group>/ (project overrides under .bobbit/config/tools/<group>/). Descriptions budget-pinned by tests2/core/tool-description-budget.test.ts.
  • Skills: .claude/skills/<name>/SKILL.md.
  • Roles/tools/skills resolution: unified PackResolver over one ordered pack list in src/server/agent/pack-*.ts; built-in packs in market-packs/. See docs/marketplace.md.
  • UI shell: src/app/ — state, render, message-reducer, dialogs, follow-tail.
  • UI components: src/ui/ — components, tools/renderers/, lazy/.
  • Tests (v2): path/suffix determines runner ownership. See docs/testing-strategy.md.
  • Docs: docs/ (reference + design notes), docs/design/ (per-feature design docs), docs/debugging.md (full diagnostic checklists), docs/internals.md (config cascade, sandbox, search, MCP).

Read the full file on GitHub · 78 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 78 lines · 1,551 tokens per session scan A cdb3885bc3bc

Subscribe to this mod's changes

bobbit AGENTS.md is an instructions file published in the GitHub repository G-Research/bobbit (11 stars, last pushed 2d ago), licensed MIT. It adds 1,551 tokens to every session, about $0.0078 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.