Borrowing it
Nothing to install: this file belongs to karmacircleCommunity/KarmaCircle. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/karmacircleCommunity/KarmaCircle/main/CLAUDE.mdgit clone --depth 1 https://github.com/karmacircleCommunity/KarmaCircleWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/karmacirclecommunity/karmacircle/claude-md)<a href="https://agentmods.dev/instructions/karmacirclecommunity/karmacircle/claude-md"><img src="https://agentmods.dev/badge/instructions/karmacirclecommunity/karmacircle/claude-md/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/instructions/karmacirclecommunity/karmacircle/claude-md"><img src="https://agentmods.dev/badge/instructions/karmacirclecommunity/karmacircle/claude-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.04196 | $0.04196 |
| Opus 5 | $0.02098 | $0.02098 |
| Sonnet 5 | $0.00839 | $0.00839 |
| Haiku 4.5 | $0.00420 | $0.00420 |
Grade B, and why
KarmaCircle CLAUDE.md scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
- The CLI's `think.mode` proxy setting has no `ultra` level (only `compress | record | pixel`) and is enabled machine-wide via `~/.claude/settings.json`/`ANTHROPIC_BASE_URL` rerouting to `caveman-proxy` on `127.0.0.1:878 How it starts
The opening of the file, as written. The whole thing — 105 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Monorepo layout
This repo holds two independently deployed apps: apps/web (the frontend, karmacircle-frontend — React/Vite SPA) and apps/api (the backend, karmacircle-api — Express/TypeScript/MongoDB). They share this repo, CI, and top-level tooling (this file, AGENTS.md, the graphify graph), but each keeps its own package.json, its own docs/specs/ map, and its own deploy target. apps/api is the source of truth for the API contract; don't guess at a request/response shape beyond what apps/api/docs/specs/api-contract.md and the route code show. See AGENTS.md for the fuller agentic workflow around working across both.
graphify — check the knowledge graph first
This repo has a graphify knowledge graph at graphify-out/, built from the code (AST) across both apps/web and apps/api, plus every doc in docs/specs//apps/api/docs/specs/ and the top-level .md files. It exists so you don't have to guess what depends on what.
Before answering an architecture or "what impacts what" question, or before touching a feature:
- Read graphify-out/GRAPH_REPORT.md first — God Nodes (the most-connected concepts), Communities (2-5 word cluster names with their member nodes), Surprising Connections, and Suggested Questions. It's plain text, no tool needed.
- For a specific concept/file/function, use the graphify skill's traversal commands instead of grepping blind:
/graphify explain "NodeName"(everything connected to one node),/graphify query "<question>"(broad BFS context),/graphify path "A" "B"(how two concepts connect). graphify-out/graph.jsonis the raw graph if you need to query it programmatically;graphify-out/graph.htmlopens in a browser for the visual layout.- A
PreToolUsehook (.claude/settings.json) already reminds you of this before any Glob/Grep call, and a post-commit/post-checkout Husky hook (.husky/post-commit,.husky/post-checkout) auto-rebuilds the code side of the graph after every commit and branch switch — no LLM cost, AST only. Known limitation: that AST-only rebuild has no LLM step, so it resets every community's plain-language name back to generic "Community N" each time it runs. Live with it between real updates rather than trying to patch it back by hand. - Do not proactively run
/graphify . --update(orgraphify update .) after routine edits. It costs tokens and dispatches subagents, and Tamal does not want the graph refreshed on every small change. Only run a full semantic update when he explicitly asks for one (e.g. "update the graph" after finishing a feature) — the same applies to re-labeling communities. Reading the (possibly slightly stale) report is still always fine and expected; regenerating it is not something to do unprompted. - Same rule for
docs/specs/known-issues.md: if you fix something it calls out, update that file per "Keep the specs honest" below, but don't also trigger a graph update on your own — that happens the next time Tamal asks for one.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 105 lines · 4,196 tokens per session scan B f79d146e157a
KarmaCircle CLAUDE.md is an instructions file published in the GitHub repository karmacircleCommunity/KarmaCircle (396 stars, last pushed yesterday), licensed MIT. It adds 4,196 tokens to every session, about $0.0210 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
deepseek-harness AGENTS.md
AGENTS.md instructions for deepseek-ai/deepseek-harness, covering agents.md, pre-stable apis and released session data, repository layout, commands and host sandbox failures.