Borrowing it
Nothing to install: this file belongs to hlop3z/claude-ai-dangerous. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/hlop3z/claude-ai-dangerous/main/CLAUDE.mdgit clone --depth 1 https://github.com/hlop3z/claude-ai-dangerousWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/hlop3z/claude-ai-dangerous/claude-md)<a href="https://agentmods.dev/instructions/hlop3z/claude-ai-dangerous/claude-md"><img src="https://agentmods.dev/badge/instructions/hlop3z/claude-ai-dangerous/claude-md/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/instructions/hlop3z/claude-ai-dangerous/claude-md"><img src="https://agentmods.dev/badge/instructions/hlop3z/claude-ai-dangerous/claude-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.01850 | $0.01850 |
| Opus 5 | $0.00925 | $0.00925 |
| Sonnet 5 | $0.00370 | $0.00370 |
| Haiku 4.5 | $0.00185 | $0.00185 |
Grade A, and why
claude-ai-dangerous CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 112 lines — stays where its author put it; the contents beside it link to each section on GitHub.
How to develop here
This project drives all work through OpenSpec, governed by a canon of engineering rules that is ours and comes first. Follow the pipeline — the rules apply themselves.
/opsx:explore Think it through. Decompose (invariants, boundaries, ≥3 strategies). No code.
↓
/opsx:propose Generate proposal.md (WHY/scope) + specs (abstract WHAT) + design.md (HOW).
↓
/ai:decide Build-vs-adopt gate: per critical concern, Rent>Adopt>Extend>Fork>Build.
↓ Records each decision into design.md. Run before implementing.
/opsx:apply Implement the tasks. Thin entry points; adapters isolate every dependency.
↓
/opsx:sync Fold the change's delta specs into the main specs.
↓
/opsx:archive Close out the completed change.
The canon comes first
.canon/ holds the rules this project lives by. It is ours — no external tool writes
there. When an opsx command's instructions conflict with a rule in .canon/, the rule wins;
say so rather than silently following the command. See .canon/README.md for the full
precedence and ownership contract.
The rules (open the file when the trigger fires)
| # | Trigger | In one line |
|---|---|---|
| 1 | explaining or changing architecture | Draw it in Mermaid, in docs/architecture/, describing what is. |
| 2 | code touching any external system | Pure core, ports and adapters at the boundary; dependencies point inward. |
| 3 | finishing any multi-file task | Review the diff, split by intent, Conventional Commits, never co-author. |
| 4 | any branch merge | A clean merge is not a correct one — you are the reviewer. |
| 5 | a merge just landed | Delete what the merge superseded; git history is the history. |
| 6 | about to claim something is done | Run the checks in .canon/checks.md; report what you couldn't run as unverified. |
| 7 | code sits beside an existing pattern | Coherence beats minimal diff; consolidate duplicates, flag out-of-scope mess. |
| 8 | architecture or API changed | Docs that contradict the code are defects — same change set, not later. |
| 9 | defining schemas, IDs, vocabularies | Adopt the global standard: JSON Schema/OpenAPI/AsyncAPI; Wikidata/DOI/ORCID/LEI + UUID; Schema.org/RDF/ISO. |
| 10 | starting a system or bounded context | Modular monolith on a kernel by default; DDD contexts, events between them, reads split from writes. |
| 11 | naming or registering system objects | One grammar — kind:namespace.object_name, lowercase snake_case — in one kernel registry that every projection derives from. |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 112 lines · 1,850 tokens per session scan A 0cdac5b6fe0e
claude-ai-dangerous CLAUDE.md is an instructions file published in the GitHub repository hlop3z/claude-ai-dangerous (2 stars, last pushed 25d ago), licensed MIT. It adds 1,850 tokens to every session, about $0.0093 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.