Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/pisberg/skill3/gemini-mdgit clone --depth 1 https://github.com/PIsberg/skill3What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01465 | $0.01465 |
| Opus 5 | $0.00732 | $0.00732 |
| Sonnet 5 | $0.00293 | $0.00293 |
| Haiku 4.5 | $0.00146 | $0.00146 |
Grade A, and why
skill3 GEMINI.md scanned grade A with 0 findings against 26 rules in 11 categories โ prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency โ measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing โ 63 lines โ stays where its author put it; the contents beside it link to each section on GitHub.
GEMINI.md
AI guardrails for Google Gemini, generated from source annotations by VibeTags. The region between the VIBETAGS-START and VIBETAGS-END markers is regenerated on every compile; never hand-edit inside it. Per-element detail lives in , indexed from the block below.
AUTO-GENERATED AI RULES
Generated by VibeTags | https://github.com/PIsberg/vibetags
Do not edit manually.
๐ PII / PRIVACY GUARDRAILS
The following elements handle Personally Identifiable Information (PII). NEVER include their runtime values in logs, console output, external API calls, test fixtures, mock data, or code suggestions.
se.deversity.skill3.llm.LocalLlmClient.apiKey: LLM provider API key โ never log, echo, or include in errors/fixturesse.deversity.skill3.pipeline.BraveSearchClient.apiKey: Brave Search subscription token โ never log, echo, or include in errors/fixtures
๐ง CORE FUNCTIONALITY (CHANGE WITH EXTREME CAUTION)
The following elements are well-tested core components. Make changes with extreme caution.
se.deversity.skill3.llm.SkillMdPostProcessor: Sensitivity: High. Note: Deterministically guarantees SKILL.md spec compliance; model output is never trusted. Changes risk emitting invalid frontmatter โ keep the parsing and frontmatter synthesis covered by SkillMdPostProcessorTest.se.deversity.skill3.llm.Verifier: Sensitivity: High. Note: Accuracy gate that re-grounds claims against the sources. Only worthwhile with a capable model โ a weak model rewrites rather than grounds. Keep the prompt strict about supported-claims-only and announced-vs-shipped.
๐ SECURITY-CRITICAL CODE
The following elements are security-critical. AI must not weaken security properties. Any change must be reviewed for security impact.
se.deversity.skill3.llm.AnthropicChatModel: Security-critical code [Anthropic API credential handling and hosted-provider network egress]. Do not weaken security properties. Flag any change for security review.se.deversity.skill3.llm.LlmProviderFactory: Security-critical code [LLM provider credential resolution and model selection]. Do not weaken security properties. Flag any change for security review.se.deversity.skill3.llm.LocalLlmClient: Security-critical code [outbound LLM-provider credential (Bearer token) handling]. Do not weaken security properties. Flag any change for security review.se.deversity.skill3.llm.NameSanitizer: Security-critical code [output sanitization: reserved-word stripping must never be weakened]. Do not weaken security properties. Flag any change for security review.se.deversity.skill3.pipeline.BraveSearchClient: Security-critical code [external-API credential handling and the only network egress with a secret token]. Do not weaken security properties. Flag any change for security review.se.deversity.skill3.pipeline.DiscoveryProvider: Security-critical code [forwards the Brave subscription token to the search client; must not log it]. Do not weaken security properties. Flag any change for security review.se.deversity.skill3.pipeline.HttpPageFetcher: Security-critical code [outbound page fetch egress for partly-untrusted URLs; SSRF guard must not be weakened]. Do not weaken security properties. Flag any change for security review.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen ยท 63 lines ยท 1,465 tokens per session scan A 8ca3e6dd1023
skill3 GEMINI.md is an instructions file published in the GitHub repository PIsberg/skill3 (5 stars, last pushed 6d ago), licensed Apache-2.0. It adds 1,465 tokens to every session, about $0.0073 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart โ add a new integration in 5 steps, integration architecture and integrationmanifest โ file tracking.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
next.js AGENTS.md
Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.