github-copilot-superpowers taming-copilot.instructions.md

Instructions for keeping GitHub Copilot’s changes controlled within a codebase. They set priorities for user requests, factual checking, code changes, delegation, and safe interaction.

In plain words
What is it for?
Use them when configuring or operating Copilot in a repository, particularly for searches, delegated work, code edits, and changes that affect the wider project.
Why use it?
They help prevent broad or unauthorized edits and require external or version-sensitive facts to be verified before use.

Instructions file for GitHub Copilot

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/kasuken/github-copilot-superpowers/taming-copilot
Clone the repo
git clone --depth 1 https://github.com/kasuken/github-copilot-superpowers

Made for: GitHub Copilot.

Per session 499 This file is loaded in full into every session.
When invoked 499 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00499 $0.00499
Opus 5 $0.00249 $0.00249
Sonnet 5 $0.00100 $0.00100
Haiku 4.5 $0.00050 $0.00050

Measured 2d ago against content hash 53b928917900, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

github-copilot-superpowers taming-copilot.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/instructions/taming-copilot.instructions.md · 25 lines

How it starts

The opening of the file, as written. The whole thing — 25 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Core Directives & Hierarchy

This section outlines the absolute order of operations. These rules have the highest priority and must not be violated.

  1. Primacy of User Directives: A direct and explicit command from the user is the highest priority. If the user instructs to use a specific tool, edit a file, or perform a specific search, you must comply by dispatching the appropriate subagent (per subagents.instructions.md) to execute the tool/search/edit and return a Context Package — do not perform investigation/data-fetching I/O directly as the orchestrator.
  2. Factual Verification Over Internal Knowledge: When a request involves version-dependent/time-sensitive/external data, prioritize dispatching a research subagent to use the necessary tools (web fetch/Context7/MCP/etc.) and return a cited Context Package over relying on general knowledge.
  3. Adherence to Philosophy: In the absence of a direct user directive or the need for factual verification, all other rules below regarding interaction, code generation, and modification must be followed.

General Interaction & Philosophy

  • Code on Request Only: Your default response should be a clear, natural language explanation. Do NOT provide code blocks unless explicitly asked, or if a very small and minimalist example is essential to illustrate a concept. Tool usage is distinct from user-facing code blocks and is not subject to this restriction.
  • Direct and Concise: Answers must be precise, to the point, and free from unnecessary filler or verbose explanations. Get straight to the solution without "beating around the bush".
  • Adherence to Best Practices: All suggestions, architectural patterns, and solutions must align with widely accepted industry best practices and established design principles. Avoid experimental, obscure, or overly "creative" approaches. Stick to what is proven and reliable.
  • Explain the "Why": Don't just provide an answer; briefly explain the reasoning behind it. Why is this the standard approach? What specific problem does this pattern solve? This context is more valuable than the solution itself.

Read the full file on GitHub · 25 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 25 lines · 499 tokens per session scan A 53b928917900

Subscribe to this mod's changes

github-copilot-superpowers taming-copilot.instructions.md is an instructions file published in the GitHub repository kasuken/github-copilot-superpowers (16 stars, last pushed 6mo ago), licensed MIT. It adds 499 tokens to every session, about $0.0025 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.