vibetags: Instructions file for Gemini CLI

GEMINI.md

vibetags GEMINI.md is an instructions file for Gemini CLI from PIsberg/vibetags. It costs 1,244 tokens per session, scanned A, original, MIT.

Project instructions for VibeTags, a Java tool that generates AI rules from source-code annotations. They explain that GEMINI.md and related files are generated automatically and identify files that must not be edited.

In plain words
What is it for?
Use them when changing AI guardrails, running self-annotation builds, or working on VibeTags’ file-generation and transitive-discovery code.
Why use it?
They prevent changes from being lost during regeneration and help preserve build steps that are required for multi-module discovery. This avoids silently broken generated guidance.

Instructions file for Gemini CLI

Written for Gemini CLI: the file is GEMINI.md. Also seen: mentions Gemini CLI.

This is PIsberg/vibetags's own configuration. It tells Gemini CLI how to work on vibetags itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything vibetags configures →

Reuse

Borrowing it

Nothing to install: this file belongs to PIsberg/vibetags. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/PIsberg/vibetags/main/GEMINI.md
Clone the repo
git clone --depth 1 https://github.com/PIsberg/vibetags

Made for: Gemini CLI.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for vibetags GEMINI.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/pisberg/vibetags/gemini-md.svg)](https://agentmods.dev/instructions/pisberg/vibetags/gemini-md)
Your own site
<a href="https://agentmods.dev/instructions/pisberg/vibetags/gemini-md"><img src="https://agentmods.dev/badge/instructions/pisberg/vibetags/gemini-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 1,244 This file is loaded in full into every session.
When invoked 1,244 The same file — it is already loaded in full.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.01244 $0.01244
Opus 5 $0.00622 $0.00622
Sonnet 5 $0.00249 $0.00249
Haiku 4.5 $0.00124 $0.00124

Measured 3d ago against content hash 9eeef2217cc1, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-07, from the pricing page.

Security

Grade A, and why

vibetags GEMINI.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

GEMINI.md · 47 lines

How it starts

The opening of the file, as written. The whole thing — 47 lines — stays where its author put it; the contents beside it link to each section on GitHub.

GEMINI.md

AI guardrails for Google Gemini, generated from source annotations by VibeTags itself (dogfooding, mvn compile -Pself-annotate from vibetags/). The region between the VIBETAGS-START and VIBETAGS-END markers is regenerated on every self-annotate compile; never hand-edit inside it. Per-element detail lives in .gemini/rules/, indexed from the block below.

AUTO-GENERATED AI RULES

Generated by VibeTags | https://github.com/PIsberg/vibetags

Do not edit manually.

LOCKED FILES (DO NOT EDIT)

  • se.deversity.vibetags.processor.AIGuardrailProcessor.generateFiles(): Step order is load-bearing: fingerprint check → sidecar write → sidecar read → merge → file write → cache flush; reordering steps silently skips regeneration or corrupts multi-module output
  • se.deversity.vibetags.processor.internal.TransitiveManifest.RESOURCE_PACKAGE: Must stay a valid Java package name. javac's CLASS_PATH location skips archive directories that are not package identifiers, so moving these manifests under META-INF/ leaves Filer.getResource listing zero entries and transitive discovery fails silently while the conventional location looks correct. TransitiveManifestPathTest pins the working path.
  • se.deversity.vibetags.processor.model.GuardrailAnnotations.ALL: Append only. This order fixes the insertion order of every LinkedHashSet downstream, so reordering or removing an entry rewrites generated files in every consuming build, with nothing failing to name the cause. BuildFingerprint hashes in its own separately pinned order; the two are not the same list and must not be aligned.

🧠 CORE FUNCTIONALITY (CHANGE WITH EXTREME CAUTION)

The following elements are well-tested core components. Make changes with extreme caution.

  • se.deversity.vibetags.processor.AIGuardrailProcessor: Sensitivity: critical. Note: JSR 269 entry point; orchestrates annotation discovery, fingerprint short-circuit, sidecar aggregation, and all file writes
  • se.deversity.vibetags.processor.internal.GuardrailFileWriter: Sensitivity: high. Note: Atomic marker-aware file writer; invariant: hand-authored content outside VIBETAGS-START/END markers must never be overwritten or lost
  • se.deversity.vibetags.processor.internal.ModuleSidecar: Sensitivity: high. Note: Per-module sidecar for multi-module Maven/Gradle builds; the .vibetags-mod-* file format is shared across independently compiled modules — format changes break backward compatibility
  • se.deversity.vibetags.processor.internal.WriteCache: Sensitivity: high. Note: Per-file content cache backed by .vibetags-cache; false positives (wrongly treating stale output as unchanged) would silently corrupt generated files

Read the full file on GitHub · 47 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago Changed · +1 lines · +37 tokens per session 9eeef2217cc1
  2. 7d ago First seen · 46 lines · 1,207 tokens per session scan A e40f94125a45

Subscribe to this mod's changes

vibetags GEMINI.md is an instructions file published in the GitHub repository PIsberg/vibetags (15 stars, last pushed yesterday), licensed MIT. It adds 1,244 tokens to every session, about $0.0062 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens