bnet_auth_tool AGENTS.md

Contributor instructions for a Python command-line tool that manages Battle.net software authenticators. It describes an encrypted vault, one-time codes, QR reconstruction, backup migration, and unverified online identity-service flows.

In plain words
What is it for?
Use it when developing or reviewing the tool's configuration, encryption, vault storage, file writes, authenticator codes, migrations, or Blizzard API integration.
Why use it?
It gives coding agents the project structure and safety limits needed to change authentication and encrypted-storage code without overstating what the online features support.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/nighthawk42/bnet_auth_tool/agents-md
Clone the repo
git clone --depth 1 https://github.com/Nighthawk42/bnet_auth_tool

Made for: Codex, OpenCode.

Per session 843 This file is loaded in full into every session.
When invoked 843 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00843 $0.00843
Opus 5 $0.00421 $0.00421
Sonnet 5 $0.00169 $0.00169
Haiku 4.5 $0.00084 $0.00084

Measured 2d ago against content hash b6393df0c120, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

bnet_auth_tool AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 64 lines

How it starts

The opening of the file, as written. The whole thing — 64 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AGENTS.md

Guidance for AI agents and human contributors working on bnet_auth_tool.

What this is

A Python CLI for managing Battle.net software authenticators. Two halves:

  • Offline (the important, fully-tested half): an encrypted vault of authenticator secrets, TOTP/QR reconstruction, and migration of legacy backups.
  • Online (unverified): attach/retrieve flows against Blizzard's identity API. These may be blocked by Blizzard at any time. Do not claim they are "fixed" — keep the tempered "unverified" framing in the README and --help/menu text.

Architecture

Source lives under src/bnet_auth_tool/ (a proper package; there is no top-level script).

Module Responsibility
config.py Load bundled settings.yaml + user override; resolve config/data dirs (platformdirs). Typed Settings/ApiConfig/CryptoConfig/TotpConfig.
crypto.py EncryptionManager: scrypt+AES‑256‑GCM encrypt; decrypt dispatches on a versioned header (scrypt / PBKDF2 600k / legacy PBKDF2 100k).
storage.py Vault: single encrypted file keyed by serial; add/list/get/remove.
fileio.py Atomic, 0600-hardened writes (atomic_write_bytes, _harden).
api.py BattleNetAuthenticator online client; leak-safe error handling.
totp.py hex→base32, otpauth:// URL builder, QR PNG.
migrate.py Discover + import legacy battlenet_authenticator_*.json files into the vault.
cli.py Interactive menu and argparse subcommands; main() is the entry point.
gui.py Optional Flet desktop GUI (bnet-auth-gui); imperative, same vault/crypto as the CLI. Behind the gui extra.
errors.py Exception hierarchy rooted at BnetAuthError.

settings.yaml is shipped inside the package and copied to the user's config dir on first run. Endpoints/KDF/TOTP params are config, not code — change them there.

Hard constraints (do not break)

  1. Legacy decryption must keep working. Files encrypted by v1.x — including pre‑v1.3 files with no kdf_iterations field — must still decrypt. Covered by tests/test_crypto.py.
  2. Secrets are sensitive. Never log raw device secrets, restore codes, session tokens, or full server error bodies. Vault/QR files are written 0600 and atomically.
  3. Online flows stay labelled unverified. No optimistic "it works now" claims.

Read the full file on GitHub · 64 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 64 lines · 843 tokens per session scan A b6393df0c120

Subscribe to this mod's changes

bnet_auth_tool AGENTS.md is an instructions file published in the GitHub repository Nighthawk42/bnet_auth_tool (45 stars, last pushed 2mo ago), licensed MIT. It adds 843 tokens to every session, about $0.0042 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,345 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

next.js AGENTS.md

Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens