Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/oxc-project/oxc/copilot-instructionsgit clone --depth 1 https://github.com/oxc-project/oxcWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00130 | $0.00130 |
| Opus 5 | $0.00065 | $0.00065 |
| Sonnet 5 | $0.00026 | $0.00026 |
| Haiku 4.5 | $0.00013 | $0.00013 |
Grade A, and why
oxc copilot-instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Copilot Review Instructions
When reviewing pull requests in this repository:
- Treat files inside any
fixturesdirectories as test data, not production code. - Fixture files may intentionally contain buggy, unsafe, or syntactically invalid code to validate parser/linter/transformer behavior.
- Do not report normal code-quality or correctness issues for fixture files.
- You may report a fixture issue only when the test data appears incorrect or mislabeled:
- The folder or filename does not match what the test claims to cover.
- The fixture content does not actually test the described case.
- The fixture appears accidentally broken rather than intentionally crafted.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 12 lines · 130 tokens per session scan A beee4f8d88a6
oxc copilot-instructions.md is an instructions file published in the GitHub repository oxc-project/oxc (22,563 stars, last pushed 3d ago), licensed MIT. It adds 130 tokens to every session, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
biome AGENTS.md
Instructions for biomejs/biome, covering agent guidelines for contributing to biome, communication, before editing, implementation gate and final review.
fallow
Rust-native codebase analyzer for TypeScript and JavaScript projects.
biome CLAUDE.md
Instructions for biomejs/biome, a project described as: A toolchain for web projects, aimed to provide functionalities to maintain them. Biome offers formatter and linter, usable via CLI and LSP.
fallow CLAUDE.md
Claude Code instructions for fallow-rs/fallow, covering fallow repository adapter for claude, knowledge layers, workflow, trust boundary and generated surfaces.
js2 AGENTS.md
Instructions for loopdive/js2, covering agent instructions, claude memories, commit messages, commit attribution and codex session.
js2 CLAUDE.md
Instructions for loopdive/js2, covering js2wasm, answering style, running tests, dev scratch and working in worktrees.