bram AGENTS.md

Project instructions for Bram, a desktop app that displays structured content and input through XMLUI files. They explain the app's layout, editing workflow, and coordination rules.

In plain words
What is it for?
Use them when building tables, forms, selectors, workflows, or other structured screens in Bram.
Why use it?
They help an agent make changes in the files the app actually displays and follow its required work process.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/judell/bram/agents-md
Clone the repo
git clone --depth 1 https://github.com/judell/bram

Made for: Codex, OpenCode.

Per session 1,556 This file is loaded in full into every session.
When invoked 1,556 The same file — it is already loaded in full.
Security scan B 2 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01556 $0.01556
Opus 5 $0.00778 $0.00778
Sonnet 5 $0.00311 $0.00311
Haiku 4.5 $0.00156 $0.00156

Measured 2d ago against content hash 40acd3c99c52, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

bram AGENTS.md scanned grade B with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Reads agent configuration directoriesmediumAgent snooping

.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.

This repo is driven through Bram. The canonical worklist gate is carried by codex's `developer_instructions` (top-level in `~/.codex/config.toml`, installed by Bram Setup) and enforced at runtime by a `PreToolUse` hook i

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

- For Bram lifecycle calls (`approved:` / `drop:` turns) use the **filesystem channel**, not loopback curl — Codex's sandbox refuses loopback connections (#130). Write `resources/.worklist-intent.json` as `{"nonce":"<uni
AGENTS.md · 68 lines

How it starts

The opening of the file, as written. The whole thing — 68 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Bram

You are running in the terminal of a Tauri desktop shell that puts a real terminal next to an XMLUI surface. The user can see the target app while talking to you, so use it.

Target app

When the user asks for something that benefits from structured output or structured input, edit Main.xmlui or files under components/ so the target app renders it. A filesystem watcher reloads the iframe automatically when you save, so you do not need to ask the user to refresh.

Examples:

  • Show tables, lists, charts, or other structured results in the target app.
  • Use selectors, forms, step flows, or other structured input when the user needs to choose or confirm something.
  • Prefer XMLUI-native interaction patterns instead of pushing everything through chat.

Working In XMLUI Surfaces

Both panes here are XMLUI, and most edits land in .xmlui files.

  • Avoid raw browser JS in event handlers.
  • Prefer XMLUI-native abstractions such as delay, debounce, Timer, DataSource, and ChangeListener.
  • Read app/__shell/conventions.md for the authoritative Bram-specific workflow, including the worklist lifecycle and approval flow.
  • When editing Bram itself (this repo), also read docs/developing-bram.md — code organization (helpers.js / Globals.xs / window), the xs-engine failure modes, the post-edit error grep, push-over-polling, and the build vs. hot-reload boundary.
  • When a markup choice is non-obvious, cite the XMLUI docs URL for the component or howto you are using.

Worklist Coordination

resources/worklist.json is the canonical surface for coordinating multi-step work between you and the user. Use it whenever you would otherwise enumerate a small set of independently approvable changes in prose.

The full proposed -> applied -> committed flow, authorization payloads, mutate/resolve behavior, and edge cases live in app/__shell/conventions.md. Do not duplicate that whole policy here; treat it as the source of truth.

Files You Will Edit Most

Read the full file on GitHub · 68 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 68 lines · 1,556 tokens per session scan B 40acd3c99c52

Subscribe to this mod's changes

bram AGENTS.md is an instructions file published in the GitHub repository judell/bram (46 stars, last pushed 2d ago), licensed Apache-2.0. It adds 1,556 tokens to every session, about $0.0078 per session on Opus 5. A static security scan graded it B with 2 findings (reads agent configuration directories, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,345 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

next.js AGENTS.md

Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens