openagents AGENTS.md

Repository instructions for AI agents working on the OpenAgents Rust CLI and related services. They define which parts of the repository are current, which are historical, and which language and documentation rules apply.

In plain words
What is it for?
Working on the Rust CLI, preserving the transcript archive, avoiding the historical web tree, and writing covered public documentation using the project's approved terminology.
Why use it?
They prevent agents from changing retired web code or adding TypeScript to a Rust-only repository. They also set a simplified-English standard for specified public documentation.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/openagentsinc/openagents/agents-md
Clone the repo
git clone --depth 1 https://github.com/OpenAgentsInc/openagents

Made for: Codex, OpenCode.

Per session 10,190 This file is loaded in full into every session.
When invoked 10,190 The same file — it is already loaded in full.
Security scan C 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.10190 $0.10190
Opus 5 $0.05095 $0.05095
Sonnet 5 $0.02038 $0.02038
Haiku 4.5 $0.01019 $0.01019

Measured 2d ago against content hash 3a324559dc2b, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade C, and why

openagents AGENTS.md scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Harvests environment variableshighData exfiltration

Enumerating or grepping the environment for keys collects credentials unrelated to what the mod says it does.

IPC results, and visible UI. Never extract credentials as a diagnostic. Use
AGENTS.md · 693 lines

How it starts

The opening of the file, as written. The whole thing — 693 lines — stays where its author put it; the contents beside it link to each section on GitHub.

OpenAgents Agent Contract

Scope

This repository owns the OpenAgents Rust CLI and retained supporting services, contracts, and tools. The separate OpenAgentsInc/openagents.com repository owns the sole current web application and backend, implemented in Phoenix. The apps/openagents.com tree here is historical and must not receive current web, API, or deployment work. It is deleted by the TypeScript-lane ledger (docs/refactor/2026-08-28-typescript-lane-deletion-plan.md).

This repository is Rust-only. Do not add TypeScript. Phoenix and Elixir live in OpenAgentsInc/openagents.com.

Preserve docs/transcripts/. It is the retained transcript archive from the previous repository shape.

Simplified Technical English

  • Use ASD-STE100 Issue 9 Simplified Technical English (STE) only for the public documentation paths defined in docs/ste/checker-config.v1.json.
  • Follow docs/ste/README.md for profiles, source data, inspections, migration states, and the exact publication boundary.
  • Use the approved OpenAgents terms in the versioned glossary.
  • Internal strategy, teardown, roadmap, audit, plan, specification, runbook, receipt, and agent working documents are outside STE governance. They can use the language and structure that best preserves technical meaning.
  • Use the agent compact profile only for governed public agent-facing text when its controlled extensions make that text faster or less ambiguous.
  • Do not apply the agent compact profile to public human-facing text.
  • Do not copy the ASD dictionary into the repository. Use an authorized local dictionary for strict lexical checks.
  • The completion gate does not run STE. Publication roots currently listed in docs/ste/checker-config.v1.json live under apps/openagents.com and leave with that tree. Phoenix owns live public docs.
  • Run the STE check only when a changed file is in the configured public scope and you are still in a wave that contains that tree. Do not add a structural defect to a governed file in migration.
  • Do not use an automatic text change for normative requirements, commands, identifiers, evidence values, or quoted source data.
  • Keep the technical meaning during a conversion. Record a semantic comparison for authority, safety, privacy, payment, release, and acceptance text.

Read the full file on GitHub · 693 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 693 lines · 10,190 tokens per session scan C 3a324559dc2b

Subscribe to this mod's changes

openagents AGENTS.md is an instructions file published in the GitHub repository OpenAgentsInc/openagents (446 stars, last pushed 2d ago), licensed Apache-2.0. It adds 10,190 tokens to every session, about $0.0509 per session on Opus 5. A static security scan graded it C with 1 finding (harvests environment variables). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.