Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/joinwell52-ai/fcop/agents-mdgit clone --depth 1 https://github.com/joinwell52-AI/FCoPWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.55112 | $0.55112 |
| Opus 5 | $0.27556 | $0.27556 |
| Sonnet 5 | $0.11022 | $0.11022 |
| Haiku 4.5 | $0.05511 | $0.05511 |
Grade E, and why
FCoP AGENTS.md scanned grade E with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Hidden instructionshighPrompt injection
Directives inside HTML comments, invisible characters or bidirectional overrides are read by the model and not by the person reviewing the file.
<!-- Host-neutral reminder / 宿主中立提示: The conventions below describe FCoP itself (a file-based coordination protocol), not anything specific to Cursor. The `.mdc` wrapper and `alwaysApply` frontmatter are a Cursor-specifi Reaches for credential fileshighPrivilege escalation
SSH keys, cloud credentials, git-credentials, .npmrc, /etc/shadow: reading these is how a config file becomes a credential leak.
- PM 在 TASK 文档里写 G6 描述:"cached diff 对 `\.env|\.aws/credentials` 0 命中" Copies of this mod
1 near-identical copy found in the catalogue:
- FCoP CLAUDE.md — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 3,703 lines — stays where its author put it; the contents beside it link to each section on GitHub.
FCoP Protocol Rules · agent-host-neutral copy
This file is deployed by
fcopfor agent hosts that readAGENTS.md/CLAUDE.mdas their system-prompt source (Codex, Claude Code, Devin, Cursor, etc.). Cursor IDE users get the same content via.cursor/rules/fcop-rules.mdcand.cursor/rules/fcop-protocol.mdc.The source of truth is the
fcopPython package. To upgrade this file afterpip install -U fcop[-mcp], ADMIN runs the MCP toolredeploy_rules()(or callsProject.deploy_protocol_rules(force=True)directly).
Rules version:
3.2.5· Protocol commentary version:3.2.5
FCoP Rules · FCoP 协议规则
本文件定义 FCoP 协议的规则,由
fcopMCP 自动部署。 这些规则在具体场景里怎么用——文件怎么命名、YAML 怎么写、目录怎么组织、 巡检怎么触发——属于协议解释,见同目录的fcop-protocol.mdc。 两个文件冲突时,以本文件为准。This file defines the rules of the FCoP protocol. It is auto-deployed by the
fcopMCP. How each rule actually applies in practice — file naming, YAML shape, directory layout, patrol triggers — is the job of the protocol commentary infcop-protocol.mdc(same directory). In case of conflict between the two, this file wins.
目的 / Purpose
让 Agent 通过 FCoP 与团队协同工作。
Enable agents to coordinate with a team via FCoP.
"团队"可以是多 Agent 多角色,也可以是单 Agent(solo 模式)。任何情况下:
- 协作走文件(Rule 0.a)
- 决策与执行不能由同一个角色独自完成(Rule 0.b)
- 落到文件里的必须是真的(Rule 0.c)
A "team" can be multi-agent/multi-role or single-agent (solo). In every
case: coordination goes through files (Rule 0.a), no single role completes
decision-plus-execution alone (Rule 0.b), and what gets landed in a file
must be truthful (Rule 0.c).
FCoP 的定位与七大核心概念 / Protocol Position & Seven Core Concepts
协议层定位 / Protocol Layer
FCoP 是多 Agent 协作中的行为治理协议层——约束 Agent 行为,而非调度任务。 它定义 Agent 如何"说清楚自己在做什么",以及"别人如何验证它做过什么"。 三件核心事:让行为可见(report)、让行为可审计(review)、让行为可约束(capability governance)。
FCoP is the behavior governance protocol layer for multi-agent collaboration — governing agent behavior, not scheduling tasks. It defines how agents declare what they are doing, and how others verify what they have done. Three core responsibilities: observability (report), auditability (review), capability governance.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 3,703 lines · 55,112 tokens per session scan E 796281fea0c4
FCoP AGENTS.md is an instructions file published in the GitHub repository joinwell52-AI/FCoP (2 stars, last pushed 8d ago), licensed MIT. It adds 55,112 tokens to every session, about $0.2756 per session on Opus 5. A static security scan graded it E with 2 findings (hidden instructions, reaches for credential files). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
Meta_Kim AGENTS.md
Instructions for KimYx0207/Meta_Kim, covering metakim for codex, fast read, codex output rules, what this repository is and source of truth.
Meta_Kim CLAUDE.md
Instructions for KimYx0207/Meta_Kim, covering metakim for claude code, fast read, what this repository is, claude code's role and canonical vs runtime files.
agent-config AGENTS.md
Instructions for event4u-app/agent-config, covering event4u/agent-config, source of truth, working on this repo, pointers and emergency triage — when nothing else is reachable.
agent-config copilot-instructions.md
Instructions for event4u-app/agent-config, covering copilot repository instructions — event4u/agent-config, ✅ what this repo contains, ✅ scope control, ✅ portability rules for this package and ✅ editing .augment/ — source-of-truth rule.
M87-Spine-lite CLAUDE.md
Instructions for MacFall7/M87-Spine-lite, covering claude.md — spine lite governance, non-negotiables, required workflow (every session), scope boundaries and computer-use & mcp tool governance.
swarm-protocol CLAUDE.md
Instructions for phuryn/swarm-protocol, covering claude.md, project overview, philosophy & positioning, tech stack and build & development commands.