Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/go4cas/quiver/copilot-instructionsgit clone --depth 1 https://github.com/go4cas/quiverWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00827 | $0.00827 |
| Opus 5 | $0.00413 | $0.00413 |
| Sonnet 5 | $0.00165 | $0.00165 |
| Haiku 4.5 | $0.00083 | $0.00083 |
Grade A, and why
quiver copilot-instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 74 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Quiver — GitHub Copilot instructions
Quiver is an Arrow.js starter template. Stack: Arrow.js · Vite · Tailwind CSS v4 · Vitest · Playwright.
Arrow.js rules
- Reactive slots must be arrow functions. Use
${() => value}for any interpolation that references state. Static values don't need() =>. - No HTML comments inside templates. Never write
<!-- -->insidehtml`...`— Arrow.js uses comment nodes as slot markers and this throwsInvalid HTML position. .disabledis not DOM disabled..disabled="${() => bool}"sets a literal attribute named.disabled. Usearia-disabled="true/false"+ CSS (opacity-50 cursor-not-allowed) instead.- Use
.key()in loops.items.map(i => Card(i).key(i.id))— prevents DOM re-creation on state changes.
Patterns
Page (src/pages/path.js):
import { html } from '@arrow-js/core'
import { useMeta } from '../framework/index.js'
export const meta = { layout: 'menu', title: 'Title' }
function MyPage() {
useMeta({ title: 'Title' })
return html`<div>...</div>`
}
export default MyPage
State module (src/state/myState.js):
import { createStore } from '../framework/index.js'
export const myState = createStore((reactive) => {
const state = reactive({ items: [] })
return {
get items() { return state.items },
addItem(item) { state.items.push({ ...item, id: crypto.randomUUID() }) },
}
})
Component (src/components/MyCard.js):
import { html } from '@arrow-js/core'
export function MyCard({ title }) {
return html`<div>${title}</div>`
}
Import directly from the component file (no barrel): import { MyCard } from '../components/MyCard.js'
File-based routing
src/pages/index.js→/src/pages/users/index.js→/userssrc/pages/users/[id].js→/users/:id(read withuseRoute().params())src/pages/not-found.js→ 404 handler- Guards:
beforeEach(({ from, to }) => ...)— returnfalseto cancel or a path to redirect; also runs on initial load withfrom: null
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 74 lines · 827 tokens per session scan A 7473f502b506
quiver copilot-instructions.md is an instructions file published in the GitHub repository go4cas/quiver (5 stars, last pushed 1mo ago), licensed MIT. It adds 827 tokens to every session, about $0.0041 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
OneJS AGENTS.md
Instructions for Singtaa/OneJS, covering onejs v3: agent guide, requirements, install, project setup and build and live reload.
vuestrata AGENTS.md
Instructions for boussadjra/vuestrata, covering using vite+, the unified toolchain for the web, built-in commands vs scripts, tool versions, review checklist and vuestrata project rules.
vuestrata CLAUDE.md
Instructions for boussadjra/vuestrata, covering claude.md, the one thing that trips people up, slash commands, verifying and testing reka-backed components.
vuestrata copilot-instructions.md
Instructions for boussadjra/vuestrata, covering copilot instructions, copilot-specific notes and before you finish.
OneJS CLAUDE.md
Instructions for Singtaa/OneJS: Agent guidance for this repository lives in AGENTS.md. Read it first.
vital AGENTS.md
Instructions for jvidalv/vital, covering ai agent development guide, quick reference, component creation workflow, step 1: determine component level and step 2: create component files.