feed-reader AGENTS.md

A project-specific instruction file for psg2/feed-reader, a feed-reading application with a web app, a macOS app, a database server, and an MCP endpoint.

In plain words
What is it for?
It is for working safely in the feed-reader codebase, including starting services, running development workflows, and understanding how its clients and server communicate.
Why use it?
It gives a coding agent the project’s architecture, development commands, environment rules, and file layout before it changes the code.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/psg2/feed-reader/agents-md
Clone the repo
git clone --depth 1 https://github.com/psg2/feed-reader

Made for: Codex, OpenCode.

Per session 1,578 This file is loaded in full into every session.
When invoked 1,578 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01578 $0.01578
Opus 5 $0.00789 $0.00789
Sonnet 5 $0.00316 $0.00316
Haiku 4.5 $0.00158 $0.00158

Measured yesterday against content hash cdb094c09eb4, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

feed-reader AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 90 lines

How it starts

The opening of the file, as written. The whole thing — 90 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Feed Reader — codebase guide

Single-user feed reader: TanStack Start web app on Vercel + Neon Postgres, a SwiftUI macOS client (macos/, see macos/README.md) and a remote MCP endpoint. The server is the source of truth; every client writes through to it.

Dev workflow

  • pnpm deps:up starts Postgres + pgweb in Docker and writes POSTGRES_URL / TEST_DATABASE_URL (Docker-assigned ports) into .env.docker. The dev, test and db scripts load it; never hardcode ports.
  • pnpm dev runs Vite behind portless at https://feedreader.localhost (apps/web/portless.json); worktrees get https://<branch>.feedreader.localhost. Escape hatch: cd apps/web && pnpm exec vite dev --port 3000.
  • A fresh clone runs with no .env.local (dev defaults in apps/web/lib/env.ts). .env.example lists every optional variable; docs/deploy.md explains them.

Stack

TanStack Start (Vite + Nitro, SSR) · TanStack Router (file-based) · TanStack Query + oRPC (contract-first) · BetterAuth (email/password, OTP, optional Google, API keys, OAuth 2.1 provider for the macOS app and MCP clients) · Postgres 17 + Drizzle · Tailwind v4 + shadcn/ui + Radix · Turborepo + pnpm · oxlint + oxfmt · Vercel. Sentry, PostHog and Axiom are wired but disabled without keys.

Commands

pnpm dev | build | preview
pnpm test                  # apps/web: vitest unit (real Postgres) + frontend (happy-dom)
pnpm test:db:migrate       # once after deps:up: migrate TEST_DATABASE_URL
pnpm test:e2e              # Playwright (apps/web/e2e)
pnpm lint | lint:fix | format | format:check | type-check | knip
pnpm db:generate | db:migrate | db:seed | db:reset | db:studio

Layout

apps/web/
  app/routes/        TanStack file routes (UI + /api/* server routes)
  app/server-fns/    createServerFn helpers (auth, instance config)
  components/        ui/ (shadcn), providers/, shared/
  hooks/, lib/       client + server utilities (env, auth, orpc, email, bearer)
  server/routes/     oRPC route wiring (base.ts: pub / authed middleware)
  server/usecases/   business logic + authorization (tests live here)
  server/repos/      pure Drizzle queries
  server/lib/        feed fetching/parsing, OPML, inbound e-mail, cron helpers
  server/mcp/        MCP server on top of the usecases
  tests/             setup (per-test rolled-back transaction), factories, fixtures
packages/db          Drizzle schema + migrations (drizzle/*.sql, committed)
packages/api         oRPC contract (@orpc/contract + zod)
packages/query       typed client + TanStack Query hooks (docs/patterns.md)
macos/               SwiftUI app, SQLite mirror, snapshot tests

Read the full file on GitHub · 90 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 90 lines · 1,578 tokens per session scan A cdb094c09eb4

Subscribe to this mod's changes

feed-reader AGENTS.md is an instructions file published in the GitHub repository psg2/feed-reader (0 stars, last pushed 7d ago), licensed MIT. It adds 1,578 tokens to every session, about $0.0079 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

buildNext

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

next.js AGENTS.md

Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

spec-kit AGENTS.md

Instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,040 tokens

langchain AGENTS.md

Instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,345 tokens