Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/itslab42/agentctl/agents-mdgit clone --depth 1 https://github.com/itslab42/agentctlWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01100 | $0.01100 |
| Opus 5 | $0.00550 | $0.00550 |
| Sonnet 5 | $0.00220 | $0.00220 |
| Haiku 4.5 | $0.00110 | $0.00110 |
Grade A, and why
agentctl AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 96 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AgentCtl
Single source of truth for AI coding-agent configuration. Keeps a runtime-neutral .ai/ directory and generates settings for Claude Code, Codex CLI, OpenCode, and Kiro.
Project Overview
- Package:
@lab42/agentctl(npm, Apache-2.0) - Language: TypeScript (CommonJS output)
- Runtime: Node.js ≥ 18
- Package manager: pnpm 11+
- Test runner: Node.js built-in test runner (
node --test) — NOT Vitest - Linter/Formatter: OXLint + OxFmt (not ESLint/Prettier)
- Build:
tsc→dist/, stubs copy, thenoxc-minify
Architecture
.ai/config.yaml ← source of truth (runtimes, project name, settings)
.ai/permissions.yaml ← runtime-neutral permissions (deny_over_allow)
src/config.ts ← parses & validates config.yaml
src/permissions.ts ← parses & validates permissions.yaml
src/cli.ts ← CLI entry point (init, sync, check, validate, diff, status)
src/adapters/claude.ts ← renders .claude/settings.json
src/adapters/codex.ts ← renders .codex/config.toml + hooks/permission-policy.py
src/adapters/opencode.ts ← renders .opencode/opencode.json
src/adapters/kiro.ts ← renders .kiro/settings/permissions.yaml
- Config flows one direction:
.ai/→ adapters → generated files. - Generated files are never read back as input.
- Permissions use
deny_over_allowprecedence exclusively.
Important Rules
- You must not downgrade a package just because it solves a problem.
- Always use top-level
ghandpnpmcommands such asgh view <id>wherever possible. - If a top-level command is available, then avoid using sub-commands such as
gh run <sub_command>orpnpm run <sub_command>. - Never edit generated files (
.claude/,.codex/,.opencode/,.kiro/settings/permissions.yaml) directly — edit the.ai/source then runagentctl sync. - Adapters must remain pure functions: take
Permissions(and optional settings), return a string. No I/O.
CLI Commands
agentctl init # scaffold .ai/ directory
agentctl validate # check .ai/ files parse correctly
agentctl sync # generate all enabled runtime configs
agentctl check # report drift (exit 1 if out of sync)
agentctl diff # unified diff of pending changes
agentctl status # one-line sync summary per runtime (exit 1 if drift)
agentctl --version # print version
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 96 lines · 1,100 tokens per session scan A 30f535aff0fc
agentctl AGENTS.md is an instructions file published in the GitHub repository itslab42/agentctl (2 stars, last pushed 3d ago), licensed Apache-2.0. It adds 1,100 tokens to every session, about $0.0055 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
awesome-copilot-id AGENTS.md
Instructions for GulajavaMinistudio/awesome-copilot-id, covering communication, explanation and documentation, markdown formatting, user communication style and workflow & methodology.
hiveshare CLAUDE.md
Instructions for KB-perByte/hiveshare, covering hiveshare — claude.md, repo layout, build & run, key env vars (server) and naming: hive vs memory.
llm-safe-haven CLAUDE.md
Instructions for pleasedodisturb/llm-safe-haven, covering llm safe haven, what this is, project structure, tdd — non-negotiable (adopted 2026-08-17) and the contract.
kleosrules AGENTS.md
Instructions for kleosr/kleosrules, a project described as: Cursor harness pack: user rules, skills, Bash hooks, local HANDOFF memory. macOS, Linux, Windows (WSL).
coding-agent-safety-gate AGENTS.md
Instructions for ASER-ho/coding-agent-safety-gate, covering agents / 代理规则, 仓库类型 / repository type and ai 代理规则 / rules for ai coding agents.
yapcap CLAUDE.md
Claude Code instructions for TopiCsarno/yapcap, a project described as: Native COSMIC panel applet showing local usage limits for Codex, Claude Code, and Cursor.