tabstack-cli AGENTS.md

A reference for controlling tabstack, a command-line tool, from an AI agent. It documents setup, commands, input and output formats, flags, and error codes.

In plain words
What is it for?
Use it to run tabstack commands, extract or generate JSON, automate tasks, and process research or automation output line by line.
Why use it?
It removes guesswork when automating tabstack, especially around authentication, machine-readable output, streamed results, and failed commands.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/mozilla-ocho/tabstack-cli/agents-md
Clone the repo
git clone --depth 1 https://github.com/Mozilla-Ocho/tabstack-cli

Made for: Codex, OpenCode.

Per session 2,600 This file is loaded in full into every session.
When invoked 2,600 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.02600 $0.02600
Opus 5 $0.01300 $0.01300
Sonnet 5 $0.00520 $0.00520
Haiku 4.5 $0.00260 $0.00260

Measured yesterday against content hash 1367e56af98d, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

tabstack-cli AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 225 lines

How it starts

The opening of the file, as written. The whole thing — 225 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Using tabstack from an AI agent

This document tells an LLM agent how to drive the tabstack CLI correctly. It is a reference, not a tutorial: every command, flag, input format, output shape, and failure mode is listed so you can call the tool without guessing.

TL;DR for agents

  • Always pass -o json so output is deterministic and parseable. Without it, output is pretty-printed on a TTY and only switches to JSON when piped.
  • Provide an API key via the TABSTACK_API_KEY env var (preferred for automation) or --api-key. Do not rely on an interactive auth login prompt.
  • Branch on the exit code, not on stderr text: 0 ok, 1 runtime/network, 2 bad input or missing key, 3 API error or task failure.
  • extract json / generate json return exactly the JSON shape your schema describes. Nothing is wrapped or reshaped. Validate your schema before calling; malformed schemas fail locally with exit 2.
  • automate and research stream. In -o json they emit NDJSON (one JSON object per line); read line by line, do not JSON.parse the whole output.

Setup

export TABSTACK_API_KEY="<key>"        # preferred for non-interactive use
# optional:
export TABSTACK_BASE_URL="<url>"       # override API root

Key resolution precedence (highest first): --api-key flag → TABSTACK_API_KEY → config file (~/.config/tabstack/config.toml). If no key is found, commands that hit the API exit 2 (non-retryable config error) with a clear message.

Global flags (valid on every command)

Flag Effect
-o, --output pretty|json Set json for agents. Default auto-detects (pretty on TTY, json when piped).
--api-key <key> API key, overrides env + config.
--base-url <url> API root, overrides env + config.
--no-color Disable ANSI colour (also honours NO_COLOR). Irrelevant under -o json.
--timeout <dur> Timeout for non-streaming calls only, e.g. 30s, 2m. Ignored by automate/research.

Read the full file on GitHub · 225 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 225 lines · 2,600 tokens per session scan A 1367e56af98d

Subscribe to this mod's changes

tabstack-cli AGENTS.md is an instructions file published in the GitHub repository Mozilla-Ocho/tabstack-cli (11 stars, last pushed 26d ago), licensed MIT. It adds 2,600 tokens to every session, about $0.0130 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

buildNext

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

next.js AGENTS.md

Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

spec-kit AGENTS.md

Instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,040 tokens

langchain AGENTS.md

Instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,345 tokens