Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/primax79/kilo-mcp/agents-mdgit clone --depth 1 https://github.com/primax79/kilo-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/primax79/kilo-mcp/agents-md)<a href="https://agentmods.dev/instructions/primax79/kilo-mcp/agents-md"><img src="https://agentmods.dev/badge/instructions/primax79/kilo-mcp/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01069 | $0.01069 |
| Opus 5 | $0.00535 | $0.00535 |
| Sonnet 5 | $0.00214 | $0.00214 |
| Haiku 4.5 | $0.00107 | $0.00107 |
Grade A, and why
kilo-mcp AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 71 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AGENTS.md — kilo-mcp
MCP server (server.py) that lets an orchestrating AI (Claude, Kilo, Roo
Code, any MCP client) delegate implementation work to Kilo Code, plus the
Kilo-specific architect-side/executor-side skill plugins. This is the
concrete Kilo binding of the protocol-agnostic pattern documented in
ai-architect-executor — see that repo's
AGENTS.md before editing methodology, not just tool names, here. Full
tool reference, config, and design rationale: README.md,
ARCHITECTURE.md. Part of the primax79/* family — see
the workspace root's AGENTS.md (one level up) for the sibling-repo map.
Layout
server.py— the MCP server itself. All tools (kilo_implement,kilo_task_progress,kilo_create_worktree, etc.) live here.test_server.py— pytest suite (fixtures isolateDATA_DIR/metrics intotmp_path, mock_run_kilofor subprocess-level tests).plugins/architect-side/,plugins/executor-side/— the concrete Kilo skills, most of which are generated, not hand-authored (see below).bindings/*.json— per-skill data (real tool names, concrete examples) fed into the template fromai-architect-executorto produce the bound skill.scripts/regenerate_bound_skills.py— regeneratesorchestration-methodology,headless-executor-contract,conflict-resolver,delegation-roi-analysisfromai-architect-executor's templates + this repo'sbindings/*.json.scripts/generate_skill_indices.py— regenerates everyindex.json.kilo-mcp.example.toml— documents every config key; the realkilo-mcp.tomlis gitignored per-checkout.
Mandatory rules
- Never hand-edit a bound skill's methodology directly.
orchestration-methodology,headless-executor-contract,conflict-resolver, anddelegation-roi-analysisare generated fromai-architect-executor'sSKILL.template.mdsources. If the methodology itself needs to change, edit it there and re-runscripts/regenerate_bound_skills.pyhere — a direct edit to the generated file will be silently overwritten on the next regen. Binding-specific detail (real tool names, this server's own parameters) lives inbindings/*.json, not in prose you'd hand-edit.task-spec-authoring,task-delegation,interactive-role-setup,mcp-orchestrator,mcp-metrics-analyst,kilo-mcp-conflict-resolver,kilo-mcp-headless-executor,kilo-mcp-rag-explorerhave no generated counterpart — edit those directly. - Adding/renaming a tool in
server.py(new@mcp.tool()) means updating: the tool's docstring (surfaced to the connected client), the relevantbindings/*.jsonentry if a skill references it by name, andREADME.md's "Exposed MCP Tools" section. - Run tests before claiming a server change works.
pytest test_server.pyfrom this directory (a.venvwithmcpinstalled is checked in at.venv/— activate it or useuv run --no-project --with "mcp>=2" pytest test_server.py). - Skill manifest. New/changed skills need valid YAML frontmatter
(
name,description) inSKILL.md. - Regenerate indices. After any skill add/remove/rename, run
python3 scripts/generate_skill_indices.pyand commit the result. - Concurrency safety in
server.pyis load-bearing, not incidental. Background tasks are launched fully detached (setsid, explicitstdin=DEVNULL, PID liveness reaped viawaitpidbeforekill(pid, 0)) specifically because three real hangs were found and fixed this way (see README "Reliability" section) — don't simplify this back to anasyncio.create_taskor drop the explicitstdinredirect without re-reading why it's there.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 71 lines · 1,069 tokens per session scan A 1131de0b5c3b
kilo-mcp AGENTS.md is an instructions file published in the GitHub repository primax79/kilo-mcp (0 stars, last pushed 16d ago), licensed MIT. It adds 1,069 tokens to every session, about $0.0053 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
next.js AGENTS.md
Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.