patchwork-os CLAUDE.md

A repository instruction file for Patchwork OS, a single-workspace bridge connecting Claude Code with an integrated development environment. It defines which repository code belongs in scope and which separate multi-tenant system must remain separate.

In plain words
What is it for?
It guides changes to the single-tenant bridge while protecting privacy, identity, approval, dashboard and workspace boundaries.
Why use it?
It prevents contributors from adding hosted multi-user features to the wrong codebase and records important differences between related repositories.

Instructions file

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/oolab-labs/patchwork-os/claude-md
Clone the repo
git clone --depth 1 https://github.com/Oolab-labs/patchwork-os
Per session 30,476 This file is loaded in full into every session.
When invoked 30,476 The same file — it is already loaded in full.
Security scan B 2 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.30476 $0.30476
Opus 5 $0.15238 $0.15238
Sonnet 5 $0.06095 $0.06095
Haiku 4.5 $0.03048 $0.03048

Measured 2d ago against content hash e4dff6e29760, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

patchwork-os CLAUDE.md scanned grade B with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Reads agent configuration directoriesmediumAgent snooping

.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.

- `codex doctor [--config <path>] [--json]` — Diagnoses whether `~/.codex/config.toml` is correctly (and *currently*) wired up to this bridge: config file exists, has a `[mcp_servers.claude-ide-bridge]` entry, the entry'

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

- **VPS flags**: `--bind 0.0.0.0` exposes to all interfaces. `--vps` expands command allowlist (adds curl, systemctl, docker, etc.). `--fixed-token <uuid>` prevents token rotation on restart.
CLAUDE.md · 1,120 lines

How it starts

The opening of the file, as written. The whole thing — 1,120 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Claude IDE Bridge — Project Instructions

Repository Scope

This repo is the single-tenant Patchwork OS (one bridge, one workspace, one user's policy). The multi-tenant SaaS (self-service signup, container-per-tenant, control plane, reverse proxy) is a separate repo at ../patchwork-multitenant by explicit decision — never add multi-tenant / control-plane / per-tenant-container code here.

  • That repo forked this bridge's src/ (the tenant image builds COPY src/patchwork-multitenant/Dockerfile:23). It was described here as a verbatim vendored copy kept in file-for-file sync; it is not, and has not been for some time. Measured 2026-08-21: 145 shared files differ, 114 paths exist only here, 15 only there (1310 vs 1192 .ts files). Absent from the fork entirely: src/identity/, src/privacy/, src/runStore/, src/butler/, src/workspaceId.ts, src/approvalPersistence.ts, src/workers/{forbidPolicy,previewActions}.ts. Its dashboard login route is a 410 stub and memberAuth.ts does not exist there. ⇒ A fix landed here reaches zero hosted tenants, and the governance surfaces that read those modules would be structurally empty in a hosted deployment. Do not scope hosted work as though the two trees agree — verify against patchwork-multitenant/src/ first. The sync model is DECIDED — ADR-0023: the tenant image installs a pinned patchwork-os from npm instead of vendoring src/, the fork may add files but never edit package files, and the interim drift gate is transitional and must be deleted rather than silenced. Until that migration lands the trees still disagree, so treat "made here first, then snapshotted" as an aspiration rather than a description. Core features still stay tenant-agnostic (e.g. the recipe approval gate keys off the local bridge, not a tenant control plane).
  • Open-core boundary — ADR-0019. This repo is MIT and stays MIT. patchwork-multitenant is ALSO MIT, and its scope is frozen to infrastructure (tenant provisioning, proxy, container plumbing). Do not add governance features there — organisation identity, policy inheritance, retention, signed audit export and approval routing belong in the separate non-MIT patchwork-control-plane. This rule exists because the default is silently wrong: those features would ship MIT just by being built where they naturally fit, and a published MIT commit cannot be withdrawn. The architectural line: the open runtime emits evidence, only the control plane attests to it — the local JSONL ledgers stay open-format and fully usable standalone.
  • VPS/deploy scripts (redeploy.sh, .env.prod) live on the production box, not in either repo.

Read the full file on GitHub · 1,120 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 1,120 lines · 30,476 tokens per session scan B e4dff6e29760

Subscribe to this mod's changes

patchwork-os CLAUDE.md is an instructions file published in the GitHub repository Oolab-labs/patchwork-os (30 stars, last pushed 2d ago), licensed MIT. It adds 30,476 tokens to every session, about $0.1524 per session on Opus 5. A static security scan graded it B with 2 findings (reads agent configuration directories, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,345 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

next.js AGENTS.md

Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens