Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/project-tharsis/claude-code-telegram-kit/agents-mdgit clone --depth 1 https://github.com/project-tharsis/claude-code-telegram-kitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00510 | $0.00510 |
| Opus 5 | $0.00255 | $0.00255 |
| Sonnet 5 | $0.00102 | $0.00102 |
| Haiku 4.5 | $0.00051 | $0.00051 |
Grade A, and why
claude-code-telegram-kit AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 41 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Working on this repository
This kit exists so that a model chooses nothing about Telegram delivery or session
control. Hooks and deterministic code decide; Claude only returns canonical Markdown.
Most changes that look like improvements erode that property. Read
docs/design-invariants.md before proposing one.
Do not
- Add a model-facing tool. Transport selection, quote target, fallback, reactions, artifact discovery, and disclosure redaction are deterministic and stay that way. Any new model-facing surface requires an explicit design-invariant change and security review before implementation.
- Retry an uncertain outcome, or convert one into a failure. A timeout, 429, 5xx, or
unknown response leaves state untouched and leaves
👀in place. Only proven local or permanent rejection may finalize👎. - Weaken a filesystem check. Preserve directory-FD anchoring, owner, mode, inode, and
link-count verification wherever the current boundary uses them. Do not replace those
checks with a bare path,
realpath, or a singlestat. - Give the unprivileged side privileged authority. It never executes
sudo,systemd-run, helper or config paths, unit names, or arbitrary argv. Privileged work crosses the peer-UID-checked broker socket and nothing else. - Commit real deployment identity. Paths, chat IDs, bot usernames, and tokens stay out
of the tree.
scripts/check_public_tree.pyis a backstop, not a substitute for care.
Do
- Run
bun run checkbefore claiming anything works. It covers tests, typecheck, Python compile and unit tests, the privacy scan, and version agreement. - Version each wire contract explicitly. A Broker Protocol request/response change must update the TypeScript client and root broker together; a Session Control Protocol or helper CLI contract change must update the broker capability expectation and helper together.
- Keep the two envelope parsers in sync through
packages/shared/fixtures/telegram-envelope-cases.json. The command guard must never allow a direct control envelope that the strict TypeScript parser accepts to fall through to the model. - Change release versions in one operation. Four
package.jsonfiles,bun.lock, and bothsrc/server.tsidentities must match;scripts/check_versions.pyenforces the source identities.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 41 lines · 510 tokens per session scan A 863c86914b19
claude-code-telegram-kit AGENTS.md is an instructions file published in the GitHub repository project-tharsis/claude-code-telegram-kit (0 stars, last pushed 5d ago), licensed Apache-2.0. It adds 510 tokens to every session, about $0.0026 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
fff AGENTS.md
AGENTS.md instructions for dmtrKovalenko/fff, covering to clankers, development commands, building, testing and development tools and code quality.
bunqueue CLAUDE.md
Instructions for egeominotti/bunqueue, covering bunqueue, test isolation rules, architecture flow, directory structure and code guidelines.
gini-agent AGENTS.md
AGENTS.md instructions for Open-Curiosity/gini-agent, covering gini agent instructions, shape, adrs, boundaries and branches.
pi-coding-agent-forge AGENTS.md
Instructions for Firstp1ck/pi-coding-agent-forge, covering repository documentation rules, documentation goal, required documentation layers, readme.md — human guide and technical.md — advanced user reference.
rosetta pr-review-bots.instructions.md
How Copilot and CodeRabbit reviews manifest on a rosetta PR, why each looks different from a gh point of view, and what 'wrapping a PR' actually requires.
agentconfig.org AGENTS.md
Instructions for agentconfig/agentconfig.org, covering agent instructions for agentconfig.org, project overview, target audience, site structure and tech stack.