claude-dev-env AGENTS.md

Repository instructions for Claude Code, an AI coding assistant, in a JavaScript package that distributes shared configuration. They explain the project structure, commands, architecture, and rules for keeping personal information and secrets out of the code.

In plain words
What is it for?
Use them when changing the package, its commands, documentation, rules, skills, or Python hooks, especially before testing or publishing updates.
Why use it?
They give the assistant consistent project context and prevent changes that could expose private information or affect the published package unexpectedly.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/jl-cmd/claude-dev-env/agents-md
Clone the repo
git clone --depth 1 https://github.com/jl-cmd/claude-dev-env

Made for: Codex, OpenCode.

Per session 2,078 This file is loaded in full into every session.
When invoked 2,078 The same file — it is already loaded in full.
Security scan B 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.02078 $0.02078
Opus 5 $0.01039 $0.01039
Sonnet 5 $0.00416 $0.00416
Haiku 4.5 $0.00208 $0.00208

Measured 2d ago against content hash 150c08bfc13d, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

claude-dev-env AGENTS.md scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Reads agent configuration directoriesmediumAgent snooping

.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.

`packages/claude-dev-env/bin/install.mjs` is the entry point. It detects the user's Python command, copies each shipped directory (`rules/`, `docs/`, `commands/`, `system-prompts/`, `scripts/`, `_shared/`, `audit-rubrics
AGENTS.md · 75 lines

How it starts

The opening of the file, as written. The whole thing — 75 lines — stays where its author put it; the contents beside it link to each section on GitHub.

less words. small words. few words. always. forever.

AGENTS.md

This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.

What this repo is

A monorepo that builds and ships claude-dev-env — an npm package of shared Claude Code config (rules, docs, commands, agents, skills, and Python hooks). Users run npx claude-dev-env to copy these files into ~/.claude/ and merge the hook entries into their settings.json. Editing files under packages/claude-dev-env/ changes what every user receives on their next install, so treat that directory as a published surface, not a private workspace.

package.json at the root declares the npm workspace (packages/*); packages/claude-dev-env/ is the only package.

PII and secrets never enter this repo

claude-dev-env ships to npm and hosts its own source, so nothing personal or private lands in the committed tree. That covers code, docs, comments, tests, fixtures, and commit messages. Never commit a real email, home path, private IP or host, ssh user or port, cloud, app, or session id, Neon, Apps Script, or Sheet id, a real account name, or a private repo name.

When the code needs a private value at run time, that value lives in git-ignored local config with a committed placeholder:

  • The shipped NAS ssh hook reads the CLAUDE_NAS_* environment variables or ~/.claude/local-identity.json, since it installs into ~/.claude/ and cannot read a repo file.

The pii_prevention_blocker hook blocks a write or a staged commit that carries high-confidence personal data, and the privacy-hygiene skill scans the tree for the same.

Commands

Run from the repo root unless noted. The shell is Windows pwsh.

Task Command
JS tests (installer + skill scripts) cd packages/claude-dev-env && npm test
Python tests (root suite, tests/) python -m pytest tests/
Python tests (package suite) python -m pytest packages/claude-dev-env
Python tests (default bare = root suite) python -m pytest
Python tests in parallel (root suite) python -m pytest tests/ -n auto
Python tests in parallel (package suite) python -m pytest packages/claude-dev-env -n auto
Quality gate (ruff + mypy + enforcer tests) pwsh -File packages/claude-dev-env/scripts/check.ps1
Install locally to ~/.claude/ and ~/.agents/ cd packages/claude-dev-env && node bin/install.mjs

Read the full file on GitHub · 75 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 75 lines · 2,078 tokens per session scan B 150c08bfc13d

Subscribe to this mod's changes

claude-dev-env AGENTS.md is an instructions file published in the GitHub repository jl-cmd/claude-dev-env (6 stars, last pushed 2d ago), licensed MIT. It adds 2,078 tokens to every session, about $0.0104 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,345 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

next.js AGENTS.md

Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens