Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/gilbarbara/react-joyride/claude-mdgit clone --depth 1 https://github.com/gilbarbara/react-joyrideWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01893 | $0.01893 |
| Opus 5 | $0.00946 | $0.00946 |
| Sonnet 5 | $0.00379 | $0.00379 |
| Haiku 4.5 | $0.00189 | $0.00189 |
Grade A, and why
react-joyride CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 133 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CLAUDE.md
Overview
React Joyride is a React library for creating guided tours (tooltips, walkthroughs, onboarding). Supports React 16.8-19 and SSR.
For deep architecture details, see docs/architecture.md.
Commands
Package manager: pnpm
pnpm lint # ESLint with --fix on src/, test/, and e2e/
pnpm typecheck # tsc using test/tsconfig.json
pnpm test # Vitest (run once)
pnpm test:coverage # With coverage
pnpm test:watch # Watch mode
pnpm e2e # Playwright (chromium, firefox, webkit)
pnpm e2e:chromium # Chromium only
pnpm website # Website at localhost:3000
pnpm website:build # Build website for production
pnpm website:start # Serve built website locally
pnpm website:serve # Build + start website
pnpm build # tsdown
pnpm check # lint → typecheck → test:coverage
pnpm validate # check → build → size → typevalidation
Single test: pnpm test modules/store | Single e2e: pnpm e2e:chromium standard
How It Works
Singleton Store class (ref-based) manages frozen state snapshots. React subscribes via useSyncExternalStore.
Two public APIs: <Joyride> component and useJoyride() hook (returns { controls, failures, on, state, step, Tour }).
State machine has two dimensions: tour Status (idle → ready → waiting → running ↔ paused → finished/skipped) and step Lifecycle (init → ready → beacon_before → beacon → tooltip_before → tooltip → complete). See architecture.md for full details.
Event system: Single onEvent(data, controls) callback receives discriminated events and tour controls: tour:start, step:before_hook, step:before, scroll:start, scroll:end, beacon, tooltip, step:after, step:after_hook, tour:end, tour:status, error:target_not_found, error.
Controlled (with stepIndex prop): Tour pauses at COMPLETE; parent manages index via onEvent. Uncontrolled: Store manages index internally; supports initialStepIndex.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 133 lines · 1,893 tokens per session scan A 806ed12ab2db
react-joyride CLAUDE.md is an instructions file published in the GitHub repository gilbarbara/react-joyride (7,849 stars, last pushed 1mo ago), licensed MIT. It adds 1,893 tokens to every session, about $0.0095 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
react-horizontal-scrolling-menu AGENTS.md
Instructions for asmyshlyaev177/react-horizontal-scrolling-menu, covering agents — react-horizontal-scrolling-menu, layout, commands, website/ is its own workspace and package management.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).