code_puppy AGENTS.md

Repository instructions for Code Puppy, a Python tool that can be extended with plugins. Plugins are small add-ons discovered from built-in, personal, or project folders.

In plain words
What is it for?
Use them when contributing to Code Puppy, creating project or personal plugins, adding callbacks, or working with available hooks and keyboard shortcuts.
Why use it?
They explain where new behavior belongs and how plugins are loaded, helping developers avoid changing core command-line code when a plugin is the intended extension point.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/mpfaffenberger/code_puppy/agents-md
Clone the repo
git clone --depth 1 https://github.com/mpfaffenberger/code_puppy

Made for: Codex, OpenCode.

Per session 2,824 This file is loaded in full into every session.
When invoked 2,824 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.02824 $0.02824
Opus 5 $0.01412 $0.01412
Sonnet 5 $0.00565 $0.00565
Haiku 4.5 $0.00282 $0.00282

Measured 2d ago against content hash c17488f7dc34, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

code_puppy AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 180 lines

How it starts

The opening of the file, as written. The whole thing — 180 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Contributing to Code Puppy

Golden rule: nearly all new functionality should be a plugin in the code_puppy_core_plugins repository that hooks into core via code_puppy/callbacks.py. Don't edit code_puppy/command_line/.

How Plugins Work

Plugins are discovered from three tiers, loaded in order:

Tier Location When to use
Builtin code_puppy_core_plugins/<name>/register_callbacks.py Official package discovered via Python entry points
User ~/.code_puppy/plugins/<name>/register_callbacks.py Personal plugins, applied to every project
Project <CWD>/.code_puppy/plugins/<name>/register_callbacks.py Repo-specific plugins, shared with your team via git

All three tiers use the same pattern — drop a register_callbacks.py in a named subdirectory:

from code_puppy.callbacks import register_callback

def _on_startup():
    print("my_feature loaded!")

register_callback("startup", _on_startup)

That's it. The plugin loader auto-discovers register_callbacks.py in subdirs.

Project Plugins

Project plugins live at <CWD>/.code_puppy/plugins/<name>/register_callbacks.py. This mirrors the project-level discovery already used by agents (<CWD>/.code_puppy/agents/) and skills (<CWD>/.code_puppy/skills/).

Key details:

  • Directory must be created intentionally. Code Puppy will never auto-create .code_puppy/plugins/ — your team opts in by creating it.
  • Disabled by default (trust gate). Project plugins run arbitrary repo code at import time, so none load until the user accepts them in the /plugins TUI ceremony (select → Enter → type trust); accepted plugins hot-load with no restart. Trust is a SHA-256 of the plugin dir, stored user-side in ~/.code_puppy/trusted_plugins.json and scoped to the project path — any file change reverts the plugin to untrusted, and everything else fails closed. /plugins revoke <name> removes trust. Full security model: code_puppy/plugins/trust.py.
  • Keep runtime state out of the plugin dir — writing state (SQLite, caches, logs) next to the code self-tampers the hash and demands re-acceptance every boot. Use ~/.code_puppy/ like builtin plugins do, or a dot-path (e.g. .state/), which is excluded from hashing.
  • Load order is builtin → user → project. Project plugins load last, giving them highest precedence for override-style hooks.
  • Project wins on name collision. If a project plugin shares a name with a user plugin, only the project copy loads (the user plugin is skipped). This matches how agents deduplicate — discover_json_agents() overwrites user agents with project agents of the same name. A warning is logged when a project plugin shadows a builtin.
  • Module namespace isolation. Project plugins use project_plugins.<name>.register_callbacks in sys.modules, so they never collide with user plugins at the import level.

Read the full file on GitHub · 180 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 180 lines · 2,824 tokens per session scan A c17488f7dc34

Subscribe to this mod's changes

code_puppy AGENTS.md is an instructions file published in the GitHub repository mpfaffenberger/code_puppy (803 stars, last pushed 2d ago), licensed MIT. It adds 2,824 tokens to every session, about $0.0141 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,345 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

next.js AGENTS.md

Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens