Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/mendix/web-widgets/copilot-instructionsgit clone --depth 1 https://github.com/mendix/web-widgetsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.03574 | $0.03574 |
| Opus 5 | $0.01787 | $0.01787 |
| Sonnet 5 | $0.00715 | $0.00715 |
| Haiku 4.5 | $0.00357 | $0.00357 |
Grade A, and why
web-widgets copilot-instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 327 lines — stays where its author put it; the contents beside it link to each section on GitHub.
GitHub Copilot – PR Review Instructions for Mendix Web Widgets
Use this guide to review both code and workflow. Focus on Mendix pluggable widget conventions, Atlas UI styling, React best practices, and our release process.
Repo context
- Monorepo with packages under
packages/:packages/pluggableWidgets/*-webpackages/modules/*packages/shared/*(configs, plugins)
- Stack: TypeScript, React, SCSS, Rollup via
@mendix/pluggable-widgets-tools, Jest/RTL, ESLint/Prettier. - Commands (root):
pnpm lint,pnpm test,pnpm build,pnpm -w changelog,pnpm -w version.
What to check on every PR
PR metadata and process
- Title format:
- If JIRA:
[XX-000]: description - Else: conventional commits (e.g.,
feat: ...,fix: ...).
- If JIRA:
- Template adherence (see
.github/pull_request_template.md):- Lint/test locally:
pnpm lint,pnpm test. - New tests for features/bug fixes (unit tests in
src/**/__tests__/*.spec.ts, E2E tests ine2e/*.spec.js). - Related PRs linked if applicable.
- If XML or behavior changes: ask for docs PR link in
mendix/docs.
- Lint/test locally:
- Multi-package PRs: Validate each changed package separately.
Versioning and changelog (per changed package)
- If runtime code, public API, XML schema, or behavior changes in a package:
- Require semver bump in that package's
package.json. - Require
CHANGELOG.mdupdate (Keep a Changelog, semver). - Suggest:
pnpm -w changelog(or update manually).
- Require semver bump in that package's
- If refactor/docs/tests-only: bump not required (ask author to confirm).
- Multiple changed packages: each needs its own bump and changelog entry.
Code quality – Mendix pluggable widgets and React
Mendix-specific
- XML ↔ TSX alignment: lowerCamelCase property keys; TS props/types updated with XML changes; unique widget ID; captions/descriptions/defaults valid.
- Mendix data API:
- Check
ActionValue.canExecutebeforeexecute(). - Use
EditableValue.setValue()for two-way binding. - Render loading/empty states until values are ready.
- Check
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 327 lines · 3,574 tokens per session scan A 040aca6506ce
web-widgets copilot-instructions.md is an instructions file published in the GitHub repository mendix/web-widgets (40 stars, last pushed today), licensed Apache-2.0. It adds 3,574 tokens to every session, about $0.0179 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-01.
Other instructions, from other repositories
prest copilot-instructions.md
Instructions for prest/prest, covering copilot instructions for prest go backend, project scope, core engineering principles, solid principles for go and s — single responsibility.
astron-agent AGENTS.md
Instructions for iflytek/astron-agent, covering agents.md, project overview, repository structure, console and core microservices.
erupt CLAUDE.md
Instructions for erupts/erupt, covering claude.md, build & test commands, build entire project, build a single module (and its dependencies) and skip tests for faster builds.
magic AGENTS.md
Instructions for polterguy/magic, covering agents.md, commands, backend — builds and starts api on http://localhost:5000, frontend — dev server on http://localhost:4201 and one plugin's tests.
nocobase AGENTS.md
AGENTS.md instructions for nocobase/nocobase, covering agents, personal local rules, project structure, code style rules and database & migrations.
easy-vibe CLAUDE.md
Claude Code instructions for datawhalechina/easy-vibe, covering claude.md, project overview, development commands, start local documentation server and build/run commands.