Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/indianic/byline/claude-mdgit clone --depth 1 https://github.com/indianic/bylineWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/indianic/byline/claude-md)<a href="https://agentmods.dev/instructions/indianic/byline/claude-md"><img src="https://agentmods.dev/badge/instructions/indianic/byline/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.01270 | $0.01270 |
| Opus 5 | $0.00635 | $0.00635 |
| Sonnet 5 | $0.00254 | $0.00254 |
| Haiku 4.5 | $0.00127 | $0.00127 |
Grade A, and why
byline CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 86 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Rules for working in this repository
Nine defects reached working code here. Every one typechecked, built, and passed its tests. Not one was caught by the suite. These rules are what they cost.
Verification
- A mocked test proves the code does what you told it. It cannot prove you told it the right thing. For anything crossing a boundary — HTTP, the MCP tool layer, the filesystem, a terminal — the test that counts goes through the real thing and reads back what happened.
- Read the actual output. The English a tool prints, the image generated, the post read back off the live site, the brief a writer will act on. Four separate defects were visible only that way.
- Never encode an unverified external fact — an API shape, a config path, an endpoint's auth requirement. Probe it live first.
healthCheck()must gate on an endpoint that genuinely requires authentication. Verify with a fabricated-but-well-formed credential and confirm a non-2xx. Ghost'sGET /site/needs no auth; probing it reported fabricated keys as valid for four phases, andinitaccepted them.- Mark UNVERIFIED claims UNVERIFIED, in code and in docs, and never promote one on the strength of a probe that did not exercise it. The restrictive WordPress path is still unmeasured.
- A NOTES file's consequence column is a claim about the code. When the code deliberately does the opposite, correct the file and say why — a prescription nobody implemented reads as a to-do.
Design
- A guard satisfiable by any non-empty string is not a guard. Name what it actually checks, in the code and in the docs. Say plainly when something is trusted rather than verified.
- A tool description that promises unbuilt behaviour is worse than a missing feature. The host model repeats it to the user, so an overclaim there tells someone their work was verified when nothing checked it. Three such claims had to be walked back in one phase.
- One rule, one definition — and this applies to prose, not just code. Two
hand-maintained copies drift:
SLUG_PATTERN,IMAGE_LOOKS, and the providers' env var names all proved it in code, and the news-mode boundary proved it in English — stated in three places, and the third copy was the wrong one. src/cli/contains no platform- or provider-specific branches, with two named exceptions, both anchored to one legacy field. Plugins describe themselves viaCredentialField; the installer walks whatever it is given. The exceptions arestatus's legacyimageProvidersfield, frozen toimagesby definition and kept verbatim beside the family-genericprovidersarray, anddoctor's warning thatgenerate_imagewill refuse — keyed off that same already-images-specific field, because that one tool genuinely is image-specific. Nothing else insrc/cli/may name a family, a platform, or a provider.- Assume a profile's collections can be empty. A
?? 'div'fallback that fabricates a tag name shipped a sentence telling a WordPress writer a<div>would be stripped, on the one platform where it survives. - Nothing fails silently. Every tool returns a result or a
ToolErrornaming the failing API and its status. Write-back diffing exists because Ghost accepts read-only fields with a 201 and discards the value. - Research is either/or. One article, one origin: a BYOR
researchstring or providerfindings, never both. Never a fallback between Brave and Tavily — they return different shapes, and substituting one silently changes what the writer receives.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 86 lines · 1,270 tokens per session scan A a4851874d97e
byline CLAUDE.md is an instructions file published in the GitHub repository indianic/byline (2 stars, last pushed 24d ago), licensed MIT. It adds 1,270 tokens to every session, about $0.0064 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).