Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/gakonst/nanocodex/agents-mdgit clone --depth 1 https://github.com/gakonst/nanocodexWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/gakonst/nanocodex/agents-md)<a href="https://agentmods.dev/instructions/gakonst/nanocodex/agents-md"><img src="https://agentmods.dev/badge/instructions/gakonst/nanocodex/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00668 | $0.00668 |
| Opus 5 | $0.00334 | $0.00334 |
| Sonnet 5 | $0.00134 | $0.00134 |
| Haiku 4.5 | $0.00067 | $0.00067 |
Grade A, and why
nanocodex AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Nanocodex development
js/nanocodexandjs/nanocodex-reactare stable contracts. Cover changes with focused contract, type, package, and runtime tests.js/nanocodex-viteowns the Vite plugin, WASM build, OAuth relay, and Cloudflare Vite integration. Do not recreate those responsibilities in apps or adapters.- Adapters are not a dumping ground. Put behavior at its real owner and expose a narrow entrypoint.
- Apps and Workers are independent deployables. Never import another app's or Worker's source; shared code needs an explicit package owner.
- During JS/platform work, do not edit Rust unless the user explicitly requests it. Generated WASM is the Rust boundary.
- Product code gets almost no unit tests: keep only pure policy and important protocol boundaries. Require canonical browser and real service/Worker evidence for product behavior.
pnpm devuses Turbo to start the complete stack through Portless athttps://nanocodex.localhost; linked worktrees gethttps://<branch>.nanocodex.localhost. The paired playground ishttps://playground.nanocodex.localhostorhttps://<branch>.playground.nanocodex.localhost. With a highPORTLESS_PORT, append that port to each URL. Deploy from the root, in order, withpnpm deploy:egress,pnpm deploy:managed,pnpm deploy:connect-dialog,pnpm deploy:connect-api,pnpm deploy:chief-of-staff,pnpm deploy:connect-playground, andpnpm deploy:account. Each component script must build its complete workspace dependency graph from a clean checkout; do not manually prebuild omitted packages.- pnpm owns the JavaScript workspace, Turbo owns task concurrency and build caching, Portless owns local names and ports, and Vite/Wrangler own runtime.
- Do not add custom stack, deploy, test, rollout, probe, or verification wrappers. Keep installs, migrations, resource changes, deployment, and evidence explicit.
- CI deployment starts independently of tests. Pull requests dry-run stateful
Workers and publish Cloudflare previews only for Workers that support them;
masterdeploys the production configs directly. - Wrangler upload success is not behavior evidence. Exercise the exact changed journey, inspect console/network/storage/sockets/CSP, and verify provider secrets never reach browser or app surfaces.
- The product journeys are: passkey account reauthentication; two durable agent turns across reload/reconnect; exact Connect approval projection; connector or MCP connect/call/revoke fencing; attachment lifecycle; and cross-account isolation. Test only the journeys touched by a change.
- Preserve Cloudflare names, bindings, migrations, grants, durable state, public exports, and customer behavior during moves.
- Never mix, delete, or reset concurrent work; never commit secrets, generated builds, caches, retained jobs, or another user's files.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago Changed · -120 lines · -1,359 tokens per session ea59c3bdde09
- 6d ago First seen · 166 lines · 2,027 tokens per session scan A 6f1f0e6d840c
nanocodex AGENTS.md is an instructions file published in the GitHub repository gakonst/nanocodex (466 stars, last pushed yesterday), licensed Apache-2.0. It adds 668 tokens to every session, about $0.0033 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
langgraph AGENTS.md
AGENTS.md instructions for langchain-ai/langgraph, covering agents instructions, corridor security analysis, libraries and dependency map.
gptme AGENTS.md
AGENTS.md instructions for gptme/gptme, covering agent instructions for gptme, git workflow, code style, testing and project structure.
chatgpt-cli CLAUDE.md
Claude Code instructions for kardolus/chatgpt-cli, covering chatgpt-cli — release runbook, prerequisites, 1. cut the release, 2. publish the github release + binaries and 3. update the homebrew tap.
AstrBot copilot-instructions.md
Copilot instructions for AstrBotDevs/AstrBot, covering astrbot development instructions, working effectively, bootstrap and install dependencies, running the application and dashboard build (vue.js/node.js).
codexia AGENTS.md
AGENTS.md instructions for milisp/codexia, covering agents.md, project info, project tech, common commands and project structure.
rikkahub AGENTS.md
AGENTS.md instructions for rikkahub/rikkahub, covering repository guidelines, project overview, build, test, and development commands, module structure and concepts.