Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/matthewye/opencode-toolbox/agents-mdgit clone --depth 1 https://github.com/MatthewYe/opencode-toolboxWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01096 | $0.01096 |
| Opus 5 | $0.00548 | $0.00548 |
| Sonnet 5 | $0.00219 | $0.00219 |
| Haiku 4.5 | $0.00110 | $0.00110 |
Grade A, and why
opencode-toolbox AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 106 lines — stays where its author put it; the contents beside it link to each section on GitHub.
opencode-toolbox
OpenCode plugin — skills, agents, commands, and docs for an autopilot (autonomous) development workflow. Published as @matthewye/opencode-toolbox.
Quick start
Runtime: Bun (not npm/node). bun.lock exists.
bun install # install deps
bun run build # compile src/index.ts → dist/
bun run dev # watch mode
Entry point (for npm consumers): dist/index.js. dist/ is gitignored — must build before publish. For local install (git clone → path in opencode.jsonc), run bun run build after bun install to generate dist/index.js.
No test, lint, or typecheck commands exist. tsconfig.json is for editor support only.
Architecture
The plugin reads .md files at runtime via gray-matter (YAML frontmatter), then injects them into OpenCode's config hook (src/index.ts:65-91):
| Source dir | Injected as |
|---|---|
agents/*.md |
config.agent (implementer, reviewer, argus) |
commands/*.md |
config.command (autopilot) |
skills/ |
config.skills.paths |
upstream/skills/engineering/ |
config.skills.paths |
upstream/skills/productivity/ |
config.skills.paths |
Only skill paths need code-level registration. Agent/command registration is automatic from .md frontmatter.
Upstream skills (git subtree)
upstream/ is a squashed import of mattpocock/skills. To sync:
git subtree pull --prefix=upstream/ mattpocock-skills main --squash
Do not modify files in upstream/ directly. Changes will be clobbered on next sync. Local skills go in skills/ (e.g., skill-creator/, opencode-plugin-scaffold/).
Autopilot workflow
/autopilot scans .scratch/*/issues/*.md for Status: ready-for-agent, dispatches implementer → reviewer, retries up to 3 rounds. Pass a specific directory to process one: /autopilot .scratch/feat/issues/01-add-login.
Issue structure
.scratch/<feature>/issues/<NN-slug>/
├── issue.md # Has `Status: ready-for-agent` (or `in-progress`, `resolved`, `needs-info`)
└── AGENT-BRIEF.md # Acceptance Criteria + Out of scope — THE contract
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 106 lines · 1,096 tokens per session scan A 1c5c84cb2217
opencode-toolbox AGENTS.md is an instructions file published in the GitHub repository MatthewYe/opencode-toolbox (5 stars, last pushed 2mo ago), licensed MIT. It adds 1,096 tokens to every session, about $0.0055 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
buildNext
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
next.js AGENTS.md
Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
spec-kit AGENTS.md
Instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
langchain AGENTS.md
Instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.