Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/getkimchi/kimchi/agents-mdgit clone --depth 1 https://github.com/getkimchi/kimchiWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/getkimchi/kimchi/agents-md)<a href="https://agentmods.dev/instructions/getkimchi/kimchi/agents-md"><img src="https://agentmods.dev/badge/instructions/getkimchi/kimchi/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.02161 | $0.02161 |
| Opus 5 | $0.01081 | $0.01081 |
| Sonnet 5 | $0.00432 | $0.00432 |
| Haiku 4.5 | $0.00216 | $0.00216 |
Grade A, and why
kimchi AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 160 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Agent guidelines for Kimchi
You are editing the kimchi coding harness. This repo extends the pi-mono SDK (@earendil-works/pi-coding-agent) — core agent loop lives upstream; this repo adds extensions in src/extensions/.
Environment
- Package manager: pnpm (NEVER use npm/yarn)
- Runtime: Bun for dev (
pnpm run dev), Node 22+ for built binaries - Test runner: vitest (
pnpm run test— unit,pnpm run test:smoke,pnpm run test:e2e:tui,pnpm run test:e2e:acp— e2e) - Linter: biome (
pnpm run lint,pnpm run lint:fix) - Type check: TypeScript (
pnpm run typecheck)
Hard constraints
- NEVER modify
patches/files directly — patches apply at install; changes here don't affect runtime - NEVER touch
src/core/export-html/HTML templates — bundled JS is auto-generated from source - Test files: Co-locate as
*.test.tsalongside source (NOT in a separate test/ folder)
Development patterns
- Auto-formatting:
lint:fixruns automatically after file edits (PostToolUse hook) — don't run manually - Pre-commit:
.husky/pre-commitrunspnpm run lint— CI runs fullcheck(lint + typecheck) - README changes: Run
./scripts/copy-resources.js --devafter editing to propagate to dist/
CLI arguments
- Declare Kimchi-local flags in
src/cli-args.ts: add them toCLI_OPTIONSwithtype,description, and an optionalshortalias /placeholder. This catalog is the single source of truth for both the parser and help text. - Read parsed CLI args via
getParsedCliArgs(): do not scanprocess.argvby hand outside ofsrc/cli.tsstartup/bootstrap code, and do not stash CLI state onprocessglobals. The cached parse is populated once (bycli.ts) after@file/ resume-id normalization so downstream code sees the same argument list that upstream pi-mono receives.
Testing expectations
- Always add or update tests with behavior changes. Bug fixes should include a regression test that fails before the fix; new features should cover the user-visible behavior they introduce. If a test is not practical, say why in the PR/commit notes.
- Keep unit/integration tests close to the code as
*.test.tsbeside the source file. Prefer focused tests that exercise the contract of the module or extension being changed. - Use TUI E2E tests for user workflows. Put terminal-level scenarios under
tests/e2e/tui/*.test.tsand run them withpnpm run test:e2e:tui. - Treat TUI E2E tests as human-designed behavioural specs. They should describe important UX flows a user would recognize, not broad agent-generated coverage. Keep one clear workflow per test, name it by the behavior, and assert on user-visible terminal text/state.
- Structure TUI tests through the shared fixture. Use
runKimchiSession, deterministic fake OpenAI responses, isolated tempHOME/workdir, and trace steps for meaningful checkpoints. Avoid brittle ANSI/snapshot assertions unless the rendering itself is the behavior under test. - Known product bugs can use
test.fail. Add a short comment naming the bug/repro. When the underlying issue is fixed, the unexpected pass is the signal to removetest.fail. - Quarantine only for unstable tests. Use
tests/e2e/tui/skip-list.jswith a specific reason and remove the entry as soon as the instability is fixed. - Don't hand-write common dependency mocks in tests. Avoid creating
ExtensionContext(ctx) orExtensionAPI(pi) mocks inline inside a test file. Use shared mocks (e.g. undersrc/extensions/__mocks__/**for unit tests) when they exist, and add new ones there if several tests need the same dependency. Don't copy-paste partial mocks across tests.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 160 lines · 2,161 tokens per session scan A a1f1939d58f3
kimchi AGENTS.md is an instructions file published in the GitHub repository getkimchi/kimchi (2,218 stars, last pushed today), licensed Apache-2.0. It adds 2,161 tokens to every session, about $0.0108 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
next.js AGENTS.md
Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.