shortcuts-toolkit: Instructions file for Codex

AGENTS.md

shortcuts-toolkit AGENTS.md is an instructions file for Codex, OpenCode from moonhorsemmy/shortcuts-toolkit. It costs 1,351 tokens per session, scanned A, original, MIT.

Project instructions for shortcuts-toolkit, a command-line tool for creating and examining Apple Shortcuts files.

In plain words
What is it for?
Use them when generating or debugging Shortcuts actions, variables, loops, conditions, filters, or plist structure.
Why use it?
They reduce formatting errors by requiring the agent to check the project’s reference documents before editing Shortcut files.

Instructions file for CodexOpenCode

Written for Codex and OpenCode: the file is AGENTS.md. Also seen: mentions Claude Code; mentions AGENTS.md; mentions Codex.

This is moonhorsemmy/shortcuts-toolkit's own configuration. It tells Codex and OpenCode how to work on shortcuts-toolkit itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything shortcuts-toolkit configures →

Reuse

Borrowing it

Nothing to install: this file belongs to moonhorsemmy/shortcuts-toolkit. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/moonhorsemmy/shortcuts-toolkit/main/AGENTS.md
Clone the repo
git clone --depth 1 https://github.com/moonhorsemmy/shortcuts-toolkit

Made for: Codex, OpenCode.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for shortcuts-toolkit AGENTS.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/moonhorsemmy/shortcuts-toolkit/agents-md.svg)](https://agentmods.dev/instructions/moonhorsemmy/shortcuts-toolkit/agents-md)
Your own site
<a href="https://agentmods.dev/instructions/moonhorsemmy/shortcuts-toolkit/agents-md"><img src="https://agentmods.dev/badge/instructions/moonhorsemmy/shortcuts-toolkit/agents-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 1,351 This file is loaded in full into every session.
When invoked 1,351 The same file — it is already loaded in full.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.01351 $0.01351
Opus 5 $0.00675 $0.00675
Sonnet 5 $0.00270 $0.00270
Haiku 4.5 $0.00135 $0.00135

Measured 7d ago against content hash 3ce7193bf044, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-07, from the pricing page.

Security

Grade A, and why

shortcuts-toolkit AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 60 lines

How it starts

The opening of the file, as written. The whole thing — 60 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AGENTS.md — shortcuts-toolkit

给 AI agent(Claude Code / Codex / Copilot / Cursor / Kilo 等)的硬性约定。 这是代码项目src/shortcuts_toolkit/ 是 CLI 实现,reference/ 是格式参考,skill/SKILL.md 是 agent 调用说明。

核心约定:生成前必读 reference/

每次生成、改写、或排查快捷指令时,必须先查阅 reference/ 下的相关文档,确认格式无误后再动手。 禁止凭记忆盲写 plist——快捷指令内部格式苹果不公开,盲写极易产生「能签名但导入为空 / 动作不生效」的文件。

强制查阅顺序

  1. 任何生成动作前 → 读 reference/PLIST_FORMAT.md 确认根结构扁平WFWorkflowActions 在顶层,禁止WFWorkflow,否则导入为空)。
  2. 用具体动作时 → 查 reference/ACTIONS.md(427 个 WF*Action)或 reference/APPINTENTS.md(728 个 AppIntent)确认标识符与参数键名。
  3. 连接变量/输出时 → 查 reference/VARIABLES.md U+FFFC 占位 + attachmentsByRange + OutputUUID + WFSerializationType)。
  4. 用循环/条件/菜单时 → 查 reference/CONTROL_FLOW.mdGroupingIdentifier + WFControlFlowMode 整数 0/1/2)。
  5. 用查找/筛选时 → 查 reference/FILTERS.md
  6. 不确定参数类型时 → 查 reference/PARAMETER_TYPES.md

已踩的坑(务必避免)

  • ❌ 把动作包在 WFWorkflow 里 → shortcuts sign 仍签名成功,但导入为空快捷指令
  • WFControlFlowMode 写成字符串 → 控制流失效(必须 <integer>)。
  • ❌ 删除照片用 WFInput → 应该用 photos(小写)。
  • ❌ 截图筛选用 Media Type=Screenshot → 应该用 Is a Screenshot 布尔过滤。

⭐ 实测验证过的关键格式

  1. 根结构扁平WFWorkflowActions 在顶层,不包 WFWorkflow
  2. 带变量的文本动作WFTextActionText)必须用包裹格式 {Value:{string,attachmentsByRange},WFSerializationType:"WFTextTokenString"},否则运行时产出空文本。
  3. detect.dictionary + getvalueforkeyWFInputWFTextTokenAttachment 正常工作。
  4. file.append 的内容走 WFInput 且必须是 WFTextTokenString(把记录行内嵌),不是 WFTextTokenAttachment

工具运行规范

  • CLI 入口:shortcuts-toolkit <子命令>(开发时 uv run shortcuts-toolkit ...)。
  • 纯标准库,无运行时第三方依赖;开发依赖(pytest/ruff/mypy)用 uv + 国内源(清华,见 pyproject.toml [tool.uv])。
  • 签名:macOS 用 shortcuts sign --mode anyone;非 macOS 另用开源 shortcut-sign(本工具不含)。

构建 / 测试 / 质量门

uv sync                                    # 安装依赖
uv run pytest -q                           # 测试(24 用例)
uv run ruff check . && uv run ruff format --check . && uv run mypy   # 质量门
uv run shortcuts-toolkit self-test         # 端到端自测(含 macOS 签名)

Read the full file on GitHub · 60 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 7d ago First seen · 60 lines · 1,351 tokens per session scan A 3ce7193bf044

Subscribe to this mod's changes

shortcuts-toolkit AGENTS.md is an instructions file published in the GitHub repository moonhorsemmy/shortcuts-toolkit (4 stars, last pushed 1mo ago), licensed MIT. It adds 1,351 tokens to every session, about $0.0068 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens