Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/mpfaffenberger/code_puppy/agents-mdgit clone --depth 1 https://github.com/mpfaffenberger/code_puppyWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.02824 | $0.02824 |
| Opus 5 | $0.01412 | $0.01412 |
| Sonnet 5 | $0.00565 | $0.00565 |
| Haiku 4.5 | $0.00282 | $0.00282 |
Grade A, and why
code_puppy AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 180 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Contributing to Code Puppy
Golden rule: nearly all new functionality should be a plugin in the
code_puppy_core_pluginsrepository that hooks into core viacode_puppy/callbacks.py. Don't editcode_puppy/command_line/.
How Plugins Work
Plugins are discovered from three tiers, loaded in order:
| Tier | Location | When to use |
|---|---|---|
| Builtin | code_puppy_core_plugins/<name>/register_callbacks.py |
Official package discovered via Python entry points |
| User | ~/.code_puppy/plugins/<name>/register_callbacks.py |
Personal plugins, applied to every project |
| Project | <CWD>/.code_puppy/plugins/<name>/register_callbacks.py |
Repo-specific plugins, shared with your team via git |
All three tiers use the same pattern — drop a register_callbacks.py in a named subdirectory:
from code_puppy.callbacks import register_callback
def _on_startup():
print("my_feature loaded!")
register_callback("startup", _on_startup)
That's it. The plugin loader auto-discovers register_callbacks.py in subdirs.
Project Plugins
Project plugins live at <CWD>/.code_puppy/plugins/<name>/register_callbacks.py.
This mirrors the project-level discovery already used by agents (<CWD>/.code_puppy/agents/)
and skills (<CWD>/.code_puppy/skills/).
Key details:
- Directory must be created intentionally. Code Puppy will never auto-create
.code_puppy/plugins/— your team opts in by creating it. - Disabled by default (trust gate). Project plugins run arbitrary repo
code at import time, so none load until the user accepts them in the
/pluginsTUI ceremony (select → Enter → typetrust); accepted plugins hot-load with no restart. Trust is a SHA-256 of the plugin dir, stored user-side in~/.code_puppy/trusted_plugins.jsonand scoped to the project path — any file change reverts the plugin to untrusted, and everything else fails closed./plugins revoke <name>removes trust. Full security model:code_puppy/plugins/trust.py. - Keep runtime state out of the plugin dir — writing state (SQLite,
caches, logs) next to the code self-tampers the hash and demands
re-acceptance every boot. Use
~/.code_puppy/like builtin plugins do, or a dot-path (e.g..state/), which is excluded from hashing. - Load order is builtin → user → project. Project plugins load last, giving them highest precedence for override-style hooks.
- Project wins on name collision. If a project plugin shares a name with a
user plugin, only the project copy loads (the user plugin is skipped). This
matches how agents deduplicate —
discover_json_agents()overwrites user agents with project agents of the same name. A warning is logged when a project plugin shadows a builtin. - Module namespace isolation. Project plugins use
project_plugins.<name>.register_callbacksinsys.modules, so they never collide with user plugins at the import level.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 180 lines · 2,824 tokens per session scan A c17488f7dc34
code_puppy AGENTS.md is an instructions file published in the GitHub repository mpfaffenberger/code_puppy (803 stars, last pushed 2d ago), licensed MIT. It adds 2,824 tokens to every session, about $0.0141 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
next.js AGENTS.md
Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.