adrkit copilot-instructions.md

GitHub Copilot instructions for the adrkit repository, with shared project guidance in AGENTS.md and additional path-specific rules under .github/instructions. They also explain where Copilot agents and prompts come from and how to install the repository's plugin.

In plain words
What is it for?
Use them when GitHub Copilot works in adrkit, especially for following scoped rules, editing Spec Kit sources, or installing and developing the Copilot plugin.
Why use it?
They give Copilot the repository's central rules and ensure generated or path-specific instructions are changed at their correct source.

Instructions file for GitHub Copilot

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/mbeacom/adrkit/copilot-instructions
Clone the repo
git clone --depth 1 https://github.com/mbeacom/adrkit

Made for: GitHub Copilot.

Per session 310 This file is loaded in full into every session.
When invoked 310 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00310 $0.00310
Opus 5 $0.00155 $0.00155
Sonnet 5 $0.00062 $0.00062
Haiku 4.5 $0.00031 $0.00031

Measured 2d ago against content hash 29ce6345280a, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

adrkit copilot-instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/copilot-instructions.md · 28 lines

What it actually says

adrkit — GitHub Copilot

Project memory for this repository is host-neutral and lives in one file.

Read AGENTS.md before doing anything else. It carries the project overview, the distribution surfaces and their current evidence-ladder status, the Bun toolchain rules, and the agent working-directory rules — including the two that have been violated in practice, about never writing to the maintainer's main checkout and never deleting a branch on commit ancestry alone.

Nothing project-specific is duplicated here on purpose. A second copy costs context on every session and drifts from the first.

GitHub Copilot specifics

  • Path-scoped rules live in .github/instructions/ and apply automatically to the globs they declare — use-bun.instructions.md is the one that matters most here.
  • .github/agents/ and .github/prompts/ hold the Spec Kit agent and prompt files. They are generated by Spec Kit; edit the source under .specify/ rather than these copies.
  • This repository is also its own plugin marketplace: copilot plugin marketplace add mbeacom/adrkit, then copilot plugin install adrkit@adrkit. When developing that plugin, note that copilot plugin install reports only a skill count — "Installed 1 skill" does not mean the agent and commands were dropped. Verify in a fresh session.
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 28 lines · 310 tokens per session scan A 29ce6345280a

Subscribe to this mod's changes

adrkit copilot-instructions.md is an instructions file published in the GitHub repository mbeacom/adrkit (11 stars, last pushed 2d ago), licensed Apache-2.0. It adds 310 tokens to every session, about $0.0015 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.