Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/provos/ironcurtain/typesgit clone --depth 1 https://github.com/provos/ironcurtainWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00434 | $0.00434 |
| Opus 5 | $0.00217 | $0.00217 |
| Sonnet 5 | $0.00087 | $0.00087 |
| Haiku 4.5 | $0.00043 | $0.00043 |
Grade A, and why
ironcurtain types.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Types Review Rules
Types in this directory define security-critical contracts shared across the codebase.
Mandatory Checks
PolicyDecisionStatusmust remain a three-state union:allow | deny | escalate. Adding or removing states changes the security model.ArgumentRoleis a union type with a compile-time completeness check (_ROLE_COMPLETENESS_CHECK). Adding a new role requires updating: the union type, the registry map, the completeness check record, and any relevant tool annotations.resolveRealPath()inargument-roles.tsis the canonical path resolution function. It must tryrealpathSync()first (symlink resolution), then parent-based resolution, thenpath.resolve()fallback. Simplifying the fallback chain removes symlink protection.SANDBOX_SAFE_PATH_ROLEScontrols which path roles bypass compiled rule evaluation when all paths resolve inside the sandbox. The set includesread-path,write-path,delete-path,write-history, anddelete-history. The history roles are safe here because they only discharge the path component — git operations that also carry agit-remote-urlrole (e.g.,git_push) still require compiled rule evaluation for the URL role. Do not add non-path roles (likegit-remote-urlorgithub-repo) to this set.SessionIduses a branded type pattern. Do not remove the__brandproperty or accept plainstringwhereSessionIdis expected.RoleDefinition.serverNamescontrols which servers see a role in annotation prompts. Universal roles (noserverNames) appear for all servers. Accidental removal ofserverNameswould expose server-specific roles globally.resolveStoredAnnotation()inargument-roles.tsis the sole boundary where conditional role specs are resolved into plainArgumentRole[]. Conditional roles can only narrow from the default (subset invariant enforced by Zod). Do not add alternative resolution paths — all consumers must receive pre-resolvedToolAnnotation.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 18 lines · 434 tokens per session scan A c5e7ed9aea85
ironcurtain types.instructions.md is an instructions file published in the GitHub repository provos/ironcurtain (596 stars, last pushed 4d ago), licensed Apache-2.0. It adds 434 tokens to every session, about $0.0022 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
agentos CLAUDE.md
Claude Code instructions for rivet-dev/agentos, covering agentos, boundaries, security model, sqlite schema ownership and runtime and registry.
agent-sandbox AGENTS.md
Instructions for kubernetes-sigs/agent-sandbox, covering agents.md, project summary, repository layout, agent skills and build, test, lint.
agent-sandbox copilot-instructions.md
Instructions for kubernetes-sigs/agent-sandbox: Project Context & Architecture: Refer to AGENTS.md for full project background, module layout, toolchain versions, and core conventions.
mcp-server-starrocks CLAUDE.md
Instructions for StarRocks/mcp-server-starrocks, covering claude.md, project overview, development commands, run the server directly for testing and run with test mode to verify table overview functionality.
after-effects-mcp AGENTS.md
Instructions for JUNKDOGE-JOE/after-effects-mcp, covering repository development and delivery rules, 0.0 read the current architecture direction first, 0. user authorization is the scope boundary, 1. measure outcomes, not activity and 2. prioritize by dependency and user value.
Symbiont AGENTS.md
Instructions for ThirdKeyAI/Symbiont, covering symbiont — agent instructions, project structure, build and test, code style and commit guidelines.