Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/oolab-labs/patchwork-os/claude-mdgit clone --depth 1 https://github.com/Oolab-labs/patchwork-osWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.30476 | $0.30476 |
| Opus 5 | $0.15238 | $0.15238 |
| Sonnet 5 | $0.06095 | $0.06095 |
| Haiku 4.5 | $0.03048 | $0.03048 |
Grade B, and why
patchwork-os CLAUDE.md scanned grade B with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
- `codex doctor [--config <path>] [--json]` — Diagnoses whether `~/.codex/config.toml` is correctly (and *currently*) wired up to this bridge: config file exists, has a `[mcp_servers.claude-ide-bridge]` entry, the entry' Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
- **VPS flags**: `--bind 0.0.0.0` exposes to all interfaces. `--vps` expands command allowlist (adds curl, systemctl, docker, etc.). `--fixed-token <uuid>` prevents token rotation on restart. How it starts
The opening of the file, as written. The whole thing — 1,120 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Claude IDE Bridge — Project Instructions
Repository Scope
This repo is the single-tenant Patchwork OS (one bridge, one workspace, one user's policy). The multi-tenant SaaS (self-service signup, container-per-tenant, control plane, reverse proxy) is a separate repo at ../patchwork-multitenant by explicit decision — never add multi-tenant / control-plane / per-tenant-container code here.
- That repo forked this bridge's
src/(the tenant image buildsCOPY src/—patchwork-multitenant/Dockerfile:23). It was described here as a verbatim vendored copy kept in file-for-file sync; it is not, and has not been for some time. Measured 2026-08-21: 145 shared files differ, 114 paths exist only here, 15 only there (1310 vs 1192.tsfiles). Absent from the fork entirely:src/identity/,src/privacy/,src/runStore/,src/butler/,src/workspaceId.ts,src/approvalPersistence.ts,src/workers/{forbidPolicy,previewActions}.ts. Its dashboard login route is a 410 stub andmemberAuth.tsdoes not exist there. ⇒ A fix landed here reaches zero hosted tenants, and the governance surfaces that read those modules would be structurally empty in a hosted deployment. Do not scope hosted work as though the two trees agree — verify againstpatchwork-multitenant/src/first. The sync model is DECIDED — ADR-0023: the tenant image installs a pinnedpatchwork-osfrom npm instead of vendoringsrc/, the fork may add files but never edit package files, and the interim drift gate is transitional and must be deleted rather than silenced. Until that migration lands the trees still disagree, so treat "made here first, then snapshotted" as an aspiration rather than a description. Core features still stay tenant-agnostic (e.g. the recipe approval gate keys off the local bridge, not a tenant control plane). - Open-core boundary — ADR-0019. This repo is MIT and stays MIT.
patchwork-multitenantis ALSO MIT, and its scope is frozen to infrastructure (tenant provisioning, proxy, container plumbing). Do not add governance features there — organisation identity, policy inheritance, retention, signed audit export and approval routing belong in the separate non-MITpatchwork-control-plane. This rule exists because the default is silently wrong: those features would ship MIT just by being built where they naturally fit, and a published MIT commit cannot be withdrawn. The architectural line: the open runtime emits evidence, only the control plane attests to it — the local JSONL ledgers stay open-format and fully usable standalone. - VPS/deploy scripts (
redeploy.sh,.env.prod) live on the production box, not in either repo.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 1,120 lines · 30,476 tokens per session scan B e4dff6e29760
patchwork-os CLAUDE.md is an instructions file published in the GitHub repository Oolab-labs/patchwork-os (30 stars, last pushed 2d ago), licensed MIT. It adds 30,476 tokens to every session, about $0.1524 per session on Opus 5. A static security scan graded it B with 2 findings (reads agent configuration directories, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
next.js AGENTS.md
Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.