hardened-images: Instructions file for GitHub Copilot

.github/instructions/packer-shell.instructions.md

hardened-images packer-shell.instructions.md is an instructions file for GitHub Copilot from konstruktoid/hardened-images. It costs 970 tokens per session, scanned A, original, Apache-2.0.

Guidance for Packer templates and shell scripts that build and configure hardened computer images. Packer is a tool that automates the creation of machine images.

In plain words
What is it for?
Use it when writing or reviewing Packer files, shell provisioning scripts, build scripts, environment exports, and image-build handling for secrets.
Why use it?
It helps builds stop safely on errors, avoid shell-script mistakes, protect cloud credentials, and keep provisioning logic organized and reviewable.

Instructions file for GitHub Copilot

Written for GitHub Copilot: a Copilot instructions file.

This is konstruktoid/hardened-images's own configuration. It tells GitHub Copilot how to work on hardened-images itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything hardened-images configures →

Reuse

Borrowing it

Nothing to install: this file belongs to konstruktoid/hardened-images. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/konstruktoid/hardened-images/master/.github/instructions/packer-shell.instructions.md
Clone the repo
git clone --depth 1 https://github.com/konstruktoid/hardened-images

Made for: GitHub Copilot.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for hardened-images packer-shell.instructions.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/konstruktoid/hardened-images/packer-shell.svg)](https://agentmods.dev/instructions/konstruktoid/hardened-images/packer-shell)
Your own site
<a href="https://agentmods.dev/instructions/konstruktoid/hardened-images/packer-shell"><img src="https://agentmods.dev/badge/instructions/konstruktoid/hardened-images/packer-shell.svg" alt="Measured on agentmods" height="20"></a>
Per session 970 This file is loaded in full into every session.
When invoked 970 The same file — it is already loaded in full.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00970 $0.00970
Opus 5 $0.00485 $0.00485
Sonnet 5 $0.00194 $0.00194
Haiku 4.5 $0.00097 $0.00097

Measured 8d ago against content hash 00eb14372ee0, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-07, from the pricing page.

Security

Grade A, and why

hardened-images packer-shell.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/instructions/packer-shell.instructions.md · 76 lines

How it starts

The opening of the file, as written. The whole thing — 76 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Packer and Shell Provisioning Instructions

Apply these rules to Packer templates and the shell scripts that build and provision the hardened images.

Shell scripting requirements

  • Start scripts with set -euo pipefail (or equivalent explicit error handling) so failures during a build stop the pipeline rather than continuing silently.
  • Must pass shellcheck (enforced via .pre-commit-config.yaml, the shell job in .github/workflows/lint.yml, and build_box.sh itself); fix findings rather than disabling checks. When a suppression is genuinely correct, use a targeted # shellcheck disable=SCxxxx with a comment saying why.
  • azure_vars_export is sourced, not executed. It must not use set -e, which would terminate the caller's interactive shell; it handles errors explicitly and returns instead.
  • Quote variables and paths; avoid word-splitting/glob bugs on user-supplied input (e.g. -var overrides passed to build_box.sh).
  • Never persist Azure ARM_* credentials or other secrets to disk; only export them into the current shell's environment.

Packer template requirements

  • Keep *.pkr.hcl declarative — provisioning logic belongs in scripts/ or config/local.yml, not inline shell embedded in HCL.
  • Pin required_version for Packer core and every entry in required_plugins to an exact minor series (~> 1.1.6), mirroring the existing templates. A floating >= constraint is not a pin.
  • Templates must be packer fmt clean and must packer validate. Both are enforced by the packer job in .github/workflows/lint.yml, and build_box.sh runs packer validate before packer build.
  • Mark credential variables sensitive = true unless the value is a short common word, which Packer would then redact from unrelated build output. State the reason in a comment when leaving one unmarked.
  • Use variable ... validation blocks for values whose absence would otherwise produce a silently wrong build, such as the IP address that scopes the Azure build VM's inbound SSH rule.
  • Provisioner scripts are #!/bin/bash and rely on bash-only behaviour, so execute_command must invoke bash, not sh.

Read the full file on GitHub · 76 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 76 lines · 970 tokens per session scan A 00eb14372ee0

Subscribe to this mod's changes

hardened-images packer-shell.instructions.md is an instructions file published in the GitHub repository konstruktoid/hardened-images (90 stars, last pushed today), licensed Apache-2.0. It adds 970 tokens to every session, about $0.0049 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens