mastra-system-check: Instructions file for Codex

AGENTS.md

mastra-system-check AGENTS.md is an instructions file for Codex, OpenCode from goldk3y/mastra-system-check. It costs 9,062 tokens per session, scanned B, original, MIT.

A checklist for checking Mastra projects, a framework for building AI agents, against 66 setup and reliability rules.

In plain words
What is it for?
It is for reviewing Mastra configuration and setup before development or deployment, including storage and runtime access.
Why use it?
It helps find configuration problems that can prevent memory, workflows, traces, or other parts of a Mastra project from working.

Instructions file for CodexOpenCode

Written for Codex and OpenCode: the file is AGENTS.md.

This is goldk3y/mastra-system-check's own configuration. It tells Codex and OpenCode how to work on mastra-system-check itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything mastra-system-check configures →

Reuse

Borrowing it

Nothing to install: this file belongs to goldk3y/mastra-system-check. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/goldk3y/mastra-system-check/main/AGENTS.md
Clone the repo
git clone --depth 1 https://github.com/goldk3y/mastra-system-check

Made for: Codex, OpenCode.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for mastra-system-check AGENTS.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/goldk3y/mastra-system-check/agents-md/github.svg)](https://agentmods.dev/instructions/goldk3y/mastra-system-check/agents-md)
Your own site
<a href="https://agentmods.dev/instructions/goldk3y/mastra-system-check/agents-md"><img src="https://agentmods.dev/badge/instructions/goldk3y/mastra-system-check/agents-md/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for mastra-system-check AGENTS.md

Your own site · 80×15
<a href="https://agentmods.dev/instructions/goldk3y/mastra-system-check/agents-md"><img src="https://agentmods.dev/badge/instructions/goldk3y/mastra-system-check/agents-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 9,062 This file is loaded in full into every session.
When invoked 9,062 The same file — it is already loaded in full.
Security scan B 2 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.09062 $0.09062
Opus 5 $0.04531 $0.04531
Sonnet 5 $0.01812 $0.01812
Haiku 4.5 $0.00906 $0.00906

Measured 9d ago against content hash 2d59e03381ed, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade B, and why

mastra-system-check AGENTS.md scanned grade B with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Instruction-override phrasingmediumPrompt injection

Text telling the model to disregard its earlier instructions or safety rules is the shape of a prompt injection, whoever wrote it.

- "ignore previous instructions"

Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

return await fetch(url, { signal: controller.signal });
AGENTS.md · 1,772 lines

How it starts

The opening of the file, as written. The whole thing — 1,772 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Mastra System Check - Comprehensive Guide

This document contains all 66 rules for validating Mastra AI agent projects. Rules are organized by category and priority level.

Priority Levels

Level Impact Action
CRITICAL System won't function Must fix immediately
HIGH Major functionality issues Fix before deployment
MEDIUM Quality/maintainability Fix when possible
LOW Performance/cost optimization Nice to have

Section 1: Configuration & Setup (CRITICAL)

Core configuration checks that prevent system failures.

1.1 Storage Provider Required

Impact: CRITICAL (Memory, workflows, and traces won't persist)

Mastra requires a storage provider for memory persistence, workflow state, suspended tool calls, and observability traces. Without storage, conversations lose context between requests and workflows cannot suspend/resume.

What to Check

  • Storage provider is configured in Mastra instance
  • Storage URL is valid (not empty or undefined)
  • Storage is accessible at runtime

Incorrect Configuration

// Missing storage - memory and workflows will fail
import { Mastra } from "@mastra/core";

export const mastra = new Mastra({
  agents: { myAgent },
  // No storage configured!
});

Correct Configuration

import { Mastra } from "@mastra/core";
import { LibSQLStore } from "@mastra/libsql";

export const mastra = new Mastra({
  storage: new LibSQLStore({
    id: "mastra-storage",
    url: process.env.DATABASE_URL || "file:./mastra.db",
  }),
  agents: { myAgent },
});

How to Fix

  1. Install a storage package: pnpm add @mastra/libsql@latest
  2. Import and configure the storage provider
  3. Set DATABASE_URL in your .env file for production
  4. For development, use file:./mastra.db or :memory:

1.2 Environment Variables Required

Impact: CRITICAL (API calls fail, system non-functional)

Mastra agents require API keys for LLM providers. Missing environment variables cause runtime failures when agents try to generate responses.

Read the full file on GitHub · 1,772 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 1,772 lines · 9,062 tokens per session scan B 2d59e03381ed

Subscribe to this mod's changes

mastra-system-check AGENTS.md is an instructions file published in the GitHub repository goldk3y/mastra-system-check (10 stars, last pushed 7mo ago), licensed MIT. It adds 9,062 tokens to every session, about $0.0453 per session on Opus 5. A static security scan graded it B with 2 findings (instruction-override phrasing, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,153 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

deepseek-harness AGENTS.md

AGENTS.md instructions for deepseek-ai/deepseek-harness, covering agents.md, pre-stable apis and released session data, repository layout, commands and host sandbox failures.

deepseek-ai/deepseek-harness · 3,735 tokens