a2acast AGENTS.md

A set of project instructions for a2acast, a Python system that connects coding agents across machines. It includes repository constraints and special guidance for security-related code such as encryption, identity, certificates, and network messages.

In plain words
What is it for?
Use it when changing the mesh, its Claude Code, Codex, or Copilot integrations, or any code involving authentication, cryptography, certificates, verdicts, or wire formats.
Why use it?
It prevents agents from introducing unsupported dependencies, breaking Python version compatibility, or making untested security claims.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/husker/a2acast/agents-md
Clone the repo
git clone --depth 1 https://github.com/husker/a2acast

Made for: Codex, OpenCode.

Per session 961 This file is loaded in full into every session.
When invoked 961 The same file — it is already loaded in full.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00961 $0.00961
Opus 5 $0.00481 $0.00481
Sonnet 5 $0.00192 $0.00192
Haiku 4.5 $0.00096 $0.00096

Measured 2d ago against content hash 12ba4d730643, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

a2acast AGENTS.md scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

`curl`-able and readable end to end. CI catches this (`stdlib_only` job, #140) and the local suite does too (`StdlibOnlyTests`); a third-party import fails before push. Stay vigilant — the test catches imports, not subtl
AGENTS.md · 71 lines

How it starts

The opening of the file, as written. The whole thing — 71 lines — stays where its author put it; the contents beside it link to each section on GitHub.

a2acast — agent instructions

Cross-machine agent-to-agent mesh. One stdlib-only Python file (mesh.py) plus harness integrations for Claude Code, Codex CLI, and Copilot CLI. Tests in tests/test_mesh.py.

These rules exist because they were learned the expensive way. Read them before writing code, not after.

Hard constraints

  • mesh.py is stdlib-only. No third-party imports, ever. It is meant to be curl-able and readable end to end. CI catches this (stdlib_only job, #140) and the local suite does too (StdlibOnlyTests); a third-party import fails before push. Stay vigilant — the test catches imports, not subtle misuse of a stdlib facility.
  • Python 3.8+. requires-python = ">=3.8". No match statements, no X | Y unions evaluated at runtime, no 3.9+ stdlib.
  • Tests: python3 -m unittest discover -s tests (python on Windows)

Writing security-relevant code

Anything touching crypto, identity, pins, certs, revocation, verdicts, or the wire format is security-relevant. So is anything on a #62 / #74 / #76 / #93 line.

  1. Never claim a property you have not tested. A PR body is a hypothesis, not evidence. On 2026-07-25 three PRs in one batch each shipped a confident description asserting the exact property its code lacked — a rename guard that left both known seams open, a rollout gate that was send-side against a receive-side hazard, and a non-suppressibility mechanism that inverted into a suppression primitive. All three were caught only by reviewers reading the code. Write what the code does. If a guard is partial, say which case it misses.

  2. Every security fix ships a test that fails without it. Not a test that passes with it — one that fails when the fix is reverted.

  3. A guard must be load-bearing in both directions. Revert the fix: the attack test must fail. Disable the mechanism entirely: the legitimate-use test must fail. A guard that only ever blocks is a guard you can delete.

Read the full file on GitHub · 71 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 71 lines · 961 tokens per session scan A 12ba4d730643

Subscribe to this mod's changes

a2acast AGENTS.md is an instructions file published in the GitHub repository husker/a2acast (7 stars, last pushed 4d ago), licensed MIT. It adds 961 tokens to every session, about $0.0048 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.