gridbash copilot-instructions.md

Pull-request review instructions for GridBash, a terminal application that manages coding sessions, written for a skeptical senior maintainer.

In plain words
What is it for?
Checking changes for correctness, data loss, hangs, races, credential risks, cross-platform issues, configuration compatibility, terminal behavior, and regression tests.
Why use it?
They focus reviews on real defects, security risks, compatibility problems, and missing tests instead of personal style preferences or repeating the changes.

Instructions file for GitHub Copilot

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/jasonsuhari/gridbash/copilot-instructions
Clone the repo
git clone --depth 1 https://github.com/jasonsuhari/gridbash

Made for: GitHub Copilot.

Per session 297 This file is loaded in full into every session.
When invoked 297 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00297 $0.00297
Opus 5 $0.00148 $0.00148
Sonnet 5 $0.00059 $0.00059
Haiku 4.5 $0.00030 $0.00030

Measured 2d ago against content hash b5463b3e8d5c, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

gridbash copilot-instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/copilot-instructions.md · 31 lines

What it actually says

GridBash code review instructions

Review pull requests as a skeptical senior maintainer. Report only actionable problems introduced or exposed by the change; do not block on personal style preferences or restate the diff.

Prioritize these areas:

  • Correctness, data loss, hangs, races, resource leaks, and broken error paths.
  • Trust boundaries around PTY input/output, local control APIs, credentials, session data, GitHub Actions tokens, and contributor-controlled content.
  • Windows, macOS, and Linux behavior, including shell resolution, process lifecycle, path handling, terminal capabilities, and native packaging.
  • Compatibility of CLI flags, TOML configuration, saved sessions, npm package layout, and existing user workflows.
  • Ratatui layout behavior in small terminals and keyboard handling conflicts.
  • Missing regression tests for behavior that can be exercised deterministically.

Use these severities:

  • P0: immediate security compromise, destructive data loss, or universally broken release.
  • P1: likely user-facing defect, hang, major regression, or meaningful security weakness that should block merge.
  • P2: narrower correctness or maintainability defect worth fixing before merge when practical.

For every finding, name the affected file and line or changed hunk, explain the concrete failure scenario, and suggest the smallest useful correction. If there are no findings, say so plainly and mention any validation gap that remains.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 31 lines · 297 tokens per session scan A b5463b3e8d5c

Subscribe to this mod's changes

gridbash copilot-instructions.md is an instructions file published in the GitHub repository jasonsuhari/gridbash (131 stars, last pushed 2d ago), licensed MIT. It adds 297 tokens to every session, about $0.0015 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.