Borrowing it
Nothing to install: this file belongs to IBM/galaxium-travels. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/IBM/galaxium-travels/main/AGENTS.mdgit clone --depth 1 https://github.com/IBM/galaxium-travelsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/ibm/galaxium-travels/agents-md)<a href="https://agentmods.dev/instructions/ibm/galaxium-travels/agents-md"><img src="https://agentmods.dev/badge/instructions/ibm/galaxium-travels/agents-md/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/instructions/ibm/galaxium-travels/agents-md"><img src="https://agentmods.dev/badge/instructions/ibm/galaxium-travels/agents-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.02261 | $0.02261 |
| Opus 5 | $0.01130 | $0.01130 |
| Sonnet 5 | $0.00452 | $0.00452 |
| Haiku 4.5 | $0.00226 | $0.00226 |
Grade A, and why
galaxium-travels AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 150 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Galaxium Travels
A demo interplanetary flight-booking app that mimics a real enterprise system. Its purpose is to showcase challenges agents face in a multi-service codebase — not to run in production.
When you are asked to create a plan while in agent mode, do other things you need to do, like gathering data from a CLI and then explicitly switch to plan mode.
When creating planning documents, put them on the root level in all caps.
Before you start building anything look for information about tests and verification
For any exploration task, use subagents. E.g. when you are asked to create an onboarding document
Footguns
- MCP server MUST be created before FastAPI app —
server.pyline 22 instantiatesFastMCPbeforeFastAPI. Swapping the order breaks lifespan composition. - MCP tools bypass FastAPI DI — they call
SessionLocal()anddb.close()directly; they do NOT useDepends(get_db). - Service functions return Union types, not exceptions —
booking.pyreturnsBookingOut | ErrorResponse. Callers checkisinstance(result, ErrorResponse). book_flight()validates bothuser_idANDname— intentional non-standard security pattern; name mismatch rejects the booking.- SQLite is the production database —
DATABASE_URLis intentionally unset on ECS;db.pydefaults to./booking.db. Data is ephemeral per container task. SEED_DEMO_DATA=truere-seeds on every start — set tofalseif you need data to survive a restart locally.- Tests must patch
SessionLocalin two places —conftest.pylines 49–50 patches bothdb.SessionLocalandserver.SessionLocal. Patching only one leaves the MCP tools hitting the real DB. - Java hold service requires Java 17 or 21 — Lombok does not support Java 22+. The start script auto-detects sdkman candidates; set
JAVA_HOMEmanually if needed. docker-compose.ymlJava service is behind a profile — it usesprofiles: [hold-service]. Rundocker compose --profile hold-service upto include it, or usee2e/docker-compose.e2e.ymlwhich enables it unconditionally.- Python proxy swallows Java 404s — proxy endpoints in
server.pycatchhttpx.HTTPErrorand return{"error": "..."}with HTTP 200. Callers must check the response body, not just the status code (seetest_holds.pyline 82). holds.dbandbooking.dbare committed artefacts — do not delete; they seed local dev. They are regenerated on startup viaspring.jpa.hibernate.ddl-auto=updateandSEED_DEMO_DATA=true.- Some of the rules above are enforced by lifecycle hooks, not just documented — see
.bob/settings.json. Deleting a.dbfile and committing while the backend suite is red are both blocked outright. If a tool call is reported as blocked, read.bob/hooks/state/.last-blockfor the reason — the hook writes the full explanation there.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 150 lines · 2,261 tokens per session scan A 6bfbb3163b82
galaxium-travels AGENTS.md is an instructions file published in the GitHub repository IBM/galaxium-travels (53 stars, last pushed 13d ago), licensed Apache-2.0. It adds 2,261 tokens to every session, about $0.0113 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.