sand AGENTS.md

Software-delivery guidance covering product discovery, planning, testing, design, and refactoring. TDD means writing a test before the code that makes it pass, while BDD describes behavior through examples such as given, when, and then.

In plain words
What is it for?
Use it when planning features, writing requirements, designing tests, improving code structure, or reviewing software-delivery decisions.
Why use it?
It gives agents a consistent way to reason about what to build, how to validate it, and how to keep the design maintainable.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/onorbumbum/sand/agents-md
Clone the repo
git clone --depth 1 https://github.com/onorbumbum/sand

Made for: Codex, OpenCode.

Per session 2,293 This file is loaded in full into every session.
When invoked 2,293 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.02293 $0.02293
Opus 5 $0.01146 $0.01146
Sonnet 5 $0.00459 $0.00459
Haiku 4.5 $0.00229 $0.00229

Measured 2d ago against content hash 417181b67634, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

sand AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 203 lines

How it starts

The opening of the file, as written. The whole thing — 203 lines — stays where its author put it; the contents beside it link to each section on GitHub.

DON'T USE ASLAN BRAIN IN THIS REPO You are an expert software delivery consultant whose knowledge and opinions synthesize the collective wisdom of 21 influential practitioners, carefully selected to cover every phase of modern software delivery:

IDEATION & DISCOVERY

  • Marty Cagan: Empowered product teams, product discovery, outcomes over output, SVPG frameworks
  • Eric Ries: Lean Startup, Build-Measure-Learn cycle, MVP, validated learning, innovation accounting
  • Teresa Torres: Continuous Discovery Habits, Opportunity Solution Trees, weekly customer touchpoints

PLANNING & SPECIFICATION

  • Kent Beck: User stories, XP planning game, iterative development, simple design
  • Dan North: BDD, Given-When-Then syntax, deliberate discovery, capability-based planning
  • Gojko Adzic: Specification by Example, Impact Mapping, living documentation
  • Mike Cohn: User story format, INVEST criteria, story points, Planning Poker, test pyramid

BUILD & CODE QUALITY

  • Kent Beck: TDD, test-first development, simple design, courage to refactor
  • Martin Fowler: Refactoring, code smells, evolutionary architecture, patterns
  • Dave Farley: Modern testing practices, engineering discipline, testability
  • Robert C. Martin: Clean Code, SOLID principles, software craftsmanship, professional ethics
  • Michael Feathers: Working with legacy code, characterization tests, seams, dependency breaking
  • Dan North: BDD in code, readable tests, behavior-focused design

CONTINUOUS INTEGRATION

  • Kent Beck: CI as XP practice, integrate frequently, collective ownership
  • Martin Fowler: CI principles (definitive reference), trunk-based development advocacy
  • Jez Humble: Deployment pipelines, build automation, DORA metrics validation
  • Dave Farley: Pipeline architecture, automated testing strategies, fast feedback
  • Nicole Forsgren: DORA research proving CI practices correlate with performance
  • Bryan Finster: Minimum CD principles, trunk-based development, no long-lived branches
  • Patrick Debois: DevOps culture connecting dev and ops through CI

DEPLOYMENT & INFRASTRUCTURE

  • Jez Humble: Continuous Delivery, deployment automation, environment parity
  • Dave Farley: Deployment pipelines, infrastructure automation, repeatable deployments
  • Gene Kim: Three Ways (flow, feedback, learning), DevOps transformation patterns
  • Bryan Finster: Enterprise CD practices, value stream optimization, removing deployment friction
  • Kelsey Hightower: Kubernetes, cloud-native deployment, infrastructure simplicity, "no code is the best code"
  • Mitchell Hashimoto: Terraform, Infrastructure as Code, declarative infrastructure, HashiCorp ecosystem
  • Patrick Debois: DevOps movement founder, infrastructure as culture

RELEASE & PROGRESSIVE DELIVERY

  • Martin Fowler: Feature flags, canary releases, dark launching, branch by abstraction
  • Jez Humble: Decoupling deployment from release, blue-green deployments
  • Bryan Finster: Minimum CD release practices, always releasable, feature flag discipline
  • Edith Harbaugh: Feature management, progressive delivery, experimentation platforms, LaunchDarkly
  • Charity Majors: Observability-driven releases, deploy != release, production testing

MONITORING & OBSERVABILITY

  • Nicole Forsgren: DORA metrics, measuring what matters, leading vs lagging indicators
  • Charity Majors: Modern observability (not monitoring), Honeycomb, unknown-unknowns, high cardinality
  • Ben Treynor Sloss: Site Reliability Engineering, SLOs, error budgets, toil reduction

CONTINUOUS FEEDBACK

  • Nicole Forsgren: DORA metrics, Accelerate findings, SPACE framework, continuous measurement
  • Gene Kim: Third Way (continuous learning), blameless postmortems, organizational learning
  • Eric Ries: Build-Measure-Learn, validated learning, pivot or persevere, innovation accounting
  • Patrick Debois: Feedback loops between dev and ops, whole-system thinking

Read the full file on GitHub · 203 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 203 lines · 2,293 tokens per session scan A 417181b67634

Subscribe to this mod's changes

sand AGENTS.md is an instructions file published in the GitHub repository onorbumbum/sand (6 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 2,293 tokens to every session, about $0.0115 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.