Borrowing it
Nothing to install: this file belongs to osolmaz/slophammer. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/osolmaz/slophammer/main/AGENTS.mdgit clone --depth 1 https://github.com/osolmaz/slophammerWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/osolmaz/slophammer/agents-md)<a href="https://agentmods.dev/instructions/osolmaz/slophammer/agents-md"><img src="https://agentmods.dev/badge/instructions/osolmaz/slophammer/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00330 | $0.00330 |
| Opus 5 | $0.00165 | $0.00165 |
| Sonnet 5 | $0.00066 | $0.00066 |
| Haiku 4.5 | $0.00033 | $0.00033 |
Grade A, and why
slophammer AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
AGENTS.md
These instructions apply to this repository.
Agent Entrypoint
If you are applying Slophammer standards to this or another repository, start with Agent Entrypoint. It is the operational guide for turning an existing repo into one with enforceable quality gates.
Baseline Rules
- Keep generated code reviewable by humans.
- Prefer small, typed modules with fast unit tests.
- Do not add dependencies unless they remove real complexity.
- Do not hide uncertainty with weak types, broad casts, reflection, or dynamic shapes.
- Keep business rules independent from IO, frameworks, databases, queues, clocks, and network clients.
- Add or update the nearest tests when changing behavior.
- Run the relevant formatter, linter, type checker, and test command before finishing a change.
- Run
make check(or the per-language target such asmake check-go) from the repo root to run the same gates CI runs.
TypeScript
- Use
strict: true. - Do not use explicit
any. - Do not weaken types with unsafe assertions to bypass compiler or lint failures.
- Validate unknown external input at the boundary, then convert it to typed domain data.
Python
- Use type annotations for public functions and meaningful internal helpers.
- Do not use explicit
Anyunless the boundary is genuinely dynamic and localized. - Keep Ruff and mypy clean.
Go
- Keep package APIs small and explicit.
- Return errors with context.
- Do not use global mutable state for domain behavior.
- Keep interfaces near their consumers.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 41 lines · 330 tokens per session scan A a30b2bd9ae54
slophammer AGENTS.md is an instructions file published in the GitHub repository osolmaz/slophammer (21 stars, last pushed 12d ago), licensed MIT. It adds 330 tokens to every session, about $0.0016 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.