Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/orbs-network/spot/copilot-instructionsgit clone --depth 1 https://github.com/orbs-network/spotWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00980 | $0.00980 |
| Opus 5 | $0.00490 | $0.00490 |
| Sonnet 5 | $0.00196 | $0.00196 |
| Haiku 4.5 | $0.00098 | $0.00098 |
Grade C, and why
spot copilot-instructions.md scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Downloads and executes remote codehighSupply chain
curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.
2. **Install Foundry**: `curl -L https://foundry.paradigm.xyz | bash && foundryup` Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
2. **Install Foundry**: `curl -L https://foundry.paradigm.xyz | bash && foundryup` How it starts
The opening of the file, as written. The whole thing — 89 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Spot DeFi Protocol - Limit Orders, TWAP, Stop-Loss
Spot is a Foundry-based Solidity project implementing a DeFi protocol for limit orders, TWAP (Time-Weighted Average Price), and stop-loss functionality on Ethereum and L2s.
Working Effectively
Bootstrap and Build Process
- Initialize Dependencies:
git submodule update --init --recursive - Install Foundry:
curl -L https://foundry.paradigm.xyz | bash && foundryup - Build:
forge build(Compiles with 0.8.20 and 1M runs) - Test:
forge test - Format Code:
forge fmt(Always run before committing)
Validation Scenarios
forge fmt && forge test
Always run the complete validation sequence after any changes.
Project Architecture
Core Components
- OrderReactor (
src/OrderReactor.sol): Order validation, epoch checking, min-out computation, and settlement. - RePermit (
src/RePermit.sol): Permit2-style EIP-712 signatures tying witness data to order hashes. - Executor (
src/Executor.sol): Whitelisted fillers running Multicall venue logic and handling surplus. - WM (
src/ops/WM.sol): Allowlist management for executors and admin functions. - Refinery (
src/ops/Refinery.sol): Utility for batching multicalls and sweeping balances by basis points. - Cosigner (
src/ops/Cosigner.sol): Attests to trigger and market prices.
Key Libraries (src/lib/)
- OrderLib.sol: Core order structure and validation.
- EpochLib.sol: Time-bucket controls for TWAP cadence.
- CosignatureLib.sol: Price attestation verification.
- ResolutionLib.sol: Order resolution and slippage computation.
- OrderValidationLib.sol: Order validation including chainid checks.
- SettlementLib.sol: Settlement logic for order execution.
Critical Security Boundaries
- Executors must be allowlisted via WM.
- Orders require cosigned prices within freshness windows.
- Epoch controls prevent duplicate/early fills.
- Slippage caps protect against extreme price movements (max 50%).
- RePermit ties spending allowances to exact order hashes.
- Chain ID validation prevents cross-chain replay attacks.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 89 lines · 980 tokens per session scan C ccfce68ce6e4
spot copilot-instructions.md is an instructions file published in the GitHub repository orbs-network/spot (2 stars, last pushed 7d ago), licensed MIT. It adds 980 tokens to every session, about $0.0049 per session on Opus 5. A static security scan graded it C with 2 findings (downloads and executes remote code, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
next.js AGENTS.md
Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.