tinysdlc: Instructions file for Claude Code

CLAUDE.md

tinysdlc CLAUDE.md is an instructions file for Claude Code, Codex from Minh-Tam-Solution/tinysdlc. It costs 4,544 tokens per session, scanned D, original, MIT.

Project instructions for TinySDLC, a small-team software-development process. SDLC means software development life cycle: the stages used to plan, design, build, and manage software.

In plain words
What is it for?
Use them when working on TinySDLC to follow its five active development stages, keep documents in the expected folders, and apply the project's required headers and standards.
Why use it?
They give an AI coding assistant the project's current stage, documentation rules, and required format for new documents. This reduces inconsistent work and misplaced or incomplete project records.

Instructions file for Claude CodeCodex

Written for Codex and Claude Code: runs codex exec, but also the file is CLAUDE.md. Also seen: mentions Claude Code; mentions AGENTS.md; mentions Codex.

This is Minh-Tam-Solution/tinysdlc's own configuration. It tells Claude Code and Codex how to work on tinysdlc itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything tinysdlc configures →

Reuse

Borrowing it

Nothing to install: this file belongs to Minh-Tam-Solution/tinysdlc. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/Minh-Tam-Solution/tinysdlc/main/CLAUDE.md
Clone the repo
git clone --depth 1 https://github.com/Minh-Tam-Solution/tinysdlc

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for tinysdlc CLAUDE.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/minh-tam-solution/tinysdlc/claude-md/github.svg)](https://agentmods.dev/instructions/minh-tam-solution/tinysdlc/claude-md)
Your own site
<a href="https://agentmods.dev/instructions/minh-tam-solution/tinysdlc/claude-md"><img src="https://agentmods.dev/badge/instructions/minh-tam-solution/tinysdlc/claude-md/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for tinysdlc CLAUDE.md

Your own site · 80×15
<a href="https://agentmods.dev/instructions/minh-tam-solution/tinysdlc/claude-md"><img src="https://agentmods.dev/badge/instructions/minh-tam-solution/tinysdlc/claude-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 4,544 This file is loaded in full into every session.
When invoked 4,544 The same file — it is already loaded in full.
Security scan D 3 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.04544 $0.04544
Opus 5 $0.02272 $0.02272
Sonnet 5 $0.00909 $0.00909
Haiku 4.5 $0.00454 $0.00454

Measured 8d ago against content hash 2879f75b0cce, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade D, and why

tinysdlc CLAUDE.md scanned grade D with 3 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Asks for rootmediumPrivilege escalation

A mod that escalates privileges can change anything on the machine, not only the project.

- `src/lib/shell-guard.ts` — 8 mandatory deny patterns for CLI spawn paths (rm -rf, fork bomb, mkfs, dd, device write, shutdown, chmod 777, curl|sh). `guardCommand()`, `isWithinWorkspace()`, `fullGuard()`.

Recursive force deletehighDestructive command

rm -rf with a variable or a broad path is one typo away from removing the wrong tree.

- `src/lib/shell-guard.ts` — 8 mandatory deny patterns for CLI spawn paths (rm -rf, fork bomb, mkfs, dd, device write, shutdown, chmod 777, curl|sh). `guardCommand()`, `isWithinWorkspace()`, `fullGuard()`.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

- `src/lib/shell-guard.ts` — 8 mandatory deny patterns for CLI spawn paths (rm -rf, fork bomb, mkfs, dd, device write, shutdown, chmod 777, curl|sh). `guardCommand()`, `isWithinWorkspace()`, `fullGuard()`.
CLAUDE.md · 296 lines

How it starts

The opening of the file, as written. The whole thing — 296 lines — stays where its author put it; the contents beside it link to each section on GitHub.

CLAUDE AI PROJECT CONTEXT — TinySDLC

Version: 0.1.0 Status: Active Last Updated: 2026-02-18


SDLC Compliance

This project follows MTS-SDLC-Lite v1.0.0 — the MIT-licensed community edition of SDLC methodology 6.1.0 — at LITE tier. All SDLC concepts (stages, roles, gates, teams, governance) are documented in MTS-SDLC-Lite. For enterprise tiers (STANDARD/PROFESSIONAL/ENTERPRISE) with enforced governance, audit trails, and policy-as-code, contact MTS.

Aspect Value
SDLC Methodology MTS-SDLC-Lite v1.0.0 (based on SDLC 6.1.0)
Tier LITE (1-2 developers)
Config .sdlc-config.json
Active Stages 00-foundation, 01-planning, 02-design, 03-integrate, 04-build
Current Gate G0.1
SDLC Reference MTS-SDLC-Lite (MIT, all concepts documented)

Documentation Standards

  • All docs follow the docs/NN-stage/ folder structure
  • Document names use kebab-case (no sprint numbers, dates, or versions in filenames)
  • Documents include SDLC headers (SDLC Version, Stage, Status, Authority)
  • See docs/README.md for full documentation index

When Creating New Documents

  1. Place in the correct stage folder (docs/00-foundation/ through docs/04-build/)

  2. Use feature-based naming: feature-description.md (kebab-case)

  3. Add the SDLC header template at the top:

    # TinySDLC - [Title]
    **SDLC Version**: 6.1.0
    **Stage**: NN - STAGE_NAME
    **Status**: Active
    **Authority**: CTO Approved
    
  4. Forbidden in filenames: sprint numbers, dates, versions, team names, person names


Project Overview

TinySDLC is a multi-agent, multi-team, multi-channel 24/7 AI assistant orchestrator that implements MTS-SDLC-Lite for AI+Human team governance. It runs AI agents (Claude Code CLI, OpenAI Codex CLI, or Ollama) organized into teams with 12 SDLC roles: 8 SE4A agents (Researcher, PM, PJM, Architect, Coder, Reviewer, Tester, DevOps), 3 SE4H advisors (CEO, CPO, CTO at STANDARD+), and 1 Router (Assistant). Messages arrive from Discord, WhatsApp, Telegram, Zalo OA, and Zalo Personal through a file-based queue system with atomic operations. Agents collaborate via [@teammate: message] tags, enabling chain execution and parallel fan-out within teams.

Read the full file on GitHub · 296 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 296 lines · 4,544 tokens per session scan D 2879f75b0cce

Subscribe to this mod's changes

tinysdlc CLAUDE.md is an instructions file published in the GitHub repository Minh-Tam-Solution/tinysdlc (10 stars, last pushed 6mo ago), licensed MIT. It adds 4,544 tokens to every session, about $0.0227 per session on Opus 5. A static security scan graded it D with 3 findings (asks for root, recursive force delete, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,153 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens