vibing-steampunk copilot-instructions.md

Contributor instructions for vsp, a Go program that connects AI agents to SAP ABAP systems through SAP’s ADT web interface. It exposes operations through the Model Context Protocol, a standard way for AI tools to call external tools.

In plain words
What is it for?
Developing the vsp server, running unit or live-system integration tests, checking safety-related behavior, and managing its tool modes and groups.
Why use it?
They explain how to build, test, lint, and safely change a tool that can interact with SAP systems.

Instructions file for GitHub Copilot

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/oisee/vibing-steampunk/copilot-instructions
Clone the repo
git clone --depth 1 https://github.com/oisee/vibing-steampunk

Made for: GitHub Copilot.

Per session 1,439 This file is loaded in full into every session.
When invoked 1,439 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01439 $0.01439
Opus 5 $0.00720 $0.00720
Sonnet 5 $0.00288 $0.00288
Haiku 4.5 $0.00144 $0.00144

Measured 3d ago against content hash f566282d15ad, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

vibing-steampunk copilot-instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

Copies of this mod

1 near-identical copy found in the catalogue:

.github/copilot-instructions.md · 118 lines

How it starts

The opening of the file, as written. The whole thing — 118 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Copilot Instructions for vsp

Project

vsp is a Go-native MCP (Model Context Protocol) server that bridges AI agents to SAP ABAP systems via the ADT REST API. Single binary, 9 platforms, zero dependencies. It exposes 81 tools (focused mode) or 122 tools (expert mode) over JSON-RPC/stdio.

Build, Test, Lint

# Build
go build -o vsp ./cmd/vsp

# Run all unit tests
go test ./...

# Run a single test by name
go test -run TestSafetyReadOnly -v ./pkg/adt/

# Run a single package's tests
go test -v ./pkg/cache/

# Integration tests (require live SAP system via SAP_* env vars)
go test -tags=integration -v ./pkg/adt/

# Lint (golangci-lint with .golangci.yml config)
golangci-lint run ./...

# Format (gofumpt preferred, falls back to go fmt)
gofumpt -w .

Architecture

cmd/vsp/main.go            → CLI entry point (cobra + viper)
internal/mcp/
  server.go                → MCP server struct, initialization
  tools_register.go        → Tool registration logic (mode + group filtering)
  tools_focused.go         → Focused-mode tool whitelist
  tools_groups.go          → Disableable tool groups (5/U, T, H, D, C, G, R, I, X)
  handlers_*.go            → One file per tool category (20+ handler files)
pkg/adt/
  config.go                → ADT client config (functional options pattern)
  client.go                → Main client facade + read operations
  http.go                  → HTTP transport (CSRF token refresh, session management)
  crud.go                  → Lock → Update → Unlock → Activate lifecycle
  workflows.go             → High-level composite operations (GetSource, WriteSource)
  workflows_edit.go        → EditSource (find-replace with syntax check)
  safety.go                → Operation filtering and package restrictions
  features.go              → Runtime feature probing (auto/on/off)
  debugger.go              → External ABAP debugger (WebSocket via ZADT_VSP)
  xml.go                   → XML type definitions for ADT responses
pkg/dsl/                   → Fluent API for search, test, batch, YAML workflows
pkg/cache/                 → In-memory + SQLite caching
pkg/scripting/             → Lua scripting engine (40+ ADT bindings)

Read the full file on GitHub · 118 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 118 lines · 1,439 tokens per session scan A f566282d15ad

Subscribe to this mod's changes

vibing-steampunk copilot-instructions.md is an instructions file published in the GitHub repository oisee/vibing-steampunk (448 stars, last pushed 6d ago), licensed MIT. It adds 1,439 tokens to every session, about $0.0072 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.