jeff AGENTS.md

A set of instructions for Jeff, a quality-control workflow that coordinates coding agents across tools such as Claude Code, Codex, Cursor, Grok Build, and Pi. It organizes work into small tasks, separate specialist sessions, records, and checks.

In plain words
What is it for?
Use it to break work into tasks, run independent work lanes, preserve evidence, record progress, and apply targeted fixes across supported coding-agent hosts.
Why use it?
It helps keep multi-step agent work organized and makes decisions and results easier to verify. It is a workflow guide, not a security sandbox that isolates computers or tools.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/johanthoren/jeff/agents-md
Clone the repo
git clone --depth 1 https://github.com/johanthoren/jeff

Made for: Codex, OpenCode.

Per session 1,875 This file is loaded in full into every session.
When invoked 1,875 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01875 $0.01875
Opus 5 $0.00937 $0.00937
Sonnet 5 $0.00375 $0.00375
Haiku 4.5 $0.00187 $0.00187

Measured 2d ago against content hash 550a7ea3b796, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

jeff AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 77 lines

How it starts

The opening of the file, as written. The whole thing — 77 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AGENTS.md: jeff

jeff is a model-native quality control plane, distributed as Claude Code, Codex, and Cursor plugins and a Pi package. Grok Build consumes the Claude Code-compatible plugin surface directly. The method is the product, not a runtime: a thin orchestrator drives atomic tasks through fresh specialist contexts, with enforced separation, durable evidence, and deterministic gates. It is a cooperative workflow protocol for one trusted Chef and friendly frontier agents, not a security sandbox; host tool isolation is not a cross-host invariant.

Claude Code, Codex, Cursor, Grok Build, and Pi are first-class hosts over the same method and checked core; Oh My Pi installs the Pi package and uses its dispatch bridge. A Grok Bot loads Jeff through the shipped Cursor plugin. Grok Build is the coding client, while Grok is also a model family alongside Claude and GPT. Host mechanics differ; the method semantics stay shared.

Jeff 6.0 adds Graph Engineering at the work layer: fake-edge decomposition, task-DAG ready sets and atomic claims, isolated parallel lanes, facts-only context packets, write-ahead journaling, typed targeted repair, evidence-scaled convergence, and a versioned read-only projection. The implementation record and adjacent-system survey live in the 6.0 Graph Engineering slate.

  • Design spec: docs/specs/jeff-design.md
  • State schema: skills/cook/reference/jeff-state-schema.md
  • Operational procedure: skills/cook/SKILL.md
  • Voice/persona canon: docs/brand.md

Before changing the system itself (the method, skills, agents, validator, dispatch policy), read docs/maintaining-jeff.md: the maintenance and model-drift stance. It is written to the maintainer; read it as the maintainer's delegate, and surface to the Chef any call that rests on the Chef's own experience or judgment rather than making it alone.

Model expectation

jeff is built for a frontier-tier model: Claude Opus 5, GPT-5.6 Sol, Grok 4.5, or a successor of that class. That is a design target, not a gate. The harness assumes that tier's judgment and carries no scaffolding to prop up less.

Read the full file on GitHub · 77 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 77 lines · 1,875 tokens per session scan A 550a7ea3b796

Subscribe to this mod's changes

jeff AGENTS.md is an instructions file published in the GitHub repository johanthoren/jeff (4 stars, last pushed 5d ago), licensed Apache-2.0. It adds 1,875 tokens to every session, about $0.0094 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.