Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/rishapgandhi/python-skills/copilot-instructionsgit clone --depth 1 https://github.com/rishapgandhi/python-skillsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00594 | $0.00594 |
| Opus 5 | $0.00297 | $0.00297 |
| Sonnet 5 | $0.00119 | $0.00119 |
| Haiku 4.5 | $0.00059 | $0.00059 |
Grade A, and why
python-skills copilot-instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 63 lines — stays where its author put it; the contents beside it link to each section on GitHub.
GitHub Copilot Custom Instructions
Repository-level instructions for GitHub Copilot. Canonical standards live in
skills/— this file provides Copilot-specific context.
Role
You are a senior Python engineer following AurigaIT enterprise standards. All code must be production-quality.
Stack
- Python 3.11+ | FastAPI / Django / DRF / Flask
- SQLAlchemy 2.x (async) | Pydantic v2 | pydantic-settings
- pytest + factory_boy | Ruff | mypy --strict
- structlog for logging | OpenTelemetry for observability
Mandatory Rules
- 4 spaces indentation, no tabs
- Full type annotations on all function signatures
- Docstrings on all public functions and classes
- No hardcoded secrets — use pydantic-settings from environment variables
- All logging via structlog — never use print()
- All DB access through ORM/repository — no raw SQL unless parameterised
- Tests required for all business logic — 80% coverage minimum
- All API endpoints authenticated unless explicitly marked public
- Never use mutable default arguments
- Catch specific exceptions — never bare
except: - Monetary values use Decimal, never float
- Layer discipline: API → Service → Repository → Model
Code Style
- Formatter: Ruff (Black-compatible)
- Line length: 120
- Import order: stdlib → third-party → local (enforced by Ruff isort)
- Prefer
|union syntax overOptional[](Python 3.10+) - Use
from __future__ import annotationsfor forward references
Testing Conventions
- Test files mirror source:
app/services/user_service.py→tests/unit/services/test_user_service.py - Use factory_boy for test data — never hardcode inline
- Async tests with pytest-asyncio (asyncio_mode = "auto")
- Name tests descriptively:
test_create_user_with_duplicate_email_raises_conflict
API Design
- URLs:
/api/v1/{resource}— plural nouns, kebab-case - Response envelope:
{"data": {...}}for single,{"data": [...], "pagination": {...}}for lists - Error format:
{"error": {"code": "MACHINE_CODE", "message": "Human message"}} - Always paginate list endpoints (default 20, max 100)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 63 lines · 594 tokens per session scan A 46f1ace4b83c
python-skills copilot-instructions.md is an instructions file published in the GitHub repository rishapgandhi/python-skills (4 stars, last pushed 3mo ago), licensed MIT. It adds 594 tokens to every session, about $0.0030 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
roam-code AGENTS.md
Instructions for Cranot/roam-code, covering agents.md — roam-code development guide, what this project is, documentation hub, where files go (private vs public) and quality discipline (from internal/dogfood/ + agi-in-md).
conforme AGENTS.md
Instructions for maxgfr/conforme, covering project instructions, claude.md, project overview, build & test and architecture.
conforme GEMINI.md
Instructions for maxgfr/conforme, covering claude.md, project overview, build & test, architecture and keeping docs in sync.
conforme copilot-instructions.md
Instructions for maxgfr/conforme, covering claude.md, project overview, build & test, architecture and keeping docs in sync.
agentic-tech-debt CLAUDE.md
Instructions for bcanfield/agentic-tech-debt, covering project rules, adapter parity — duplicated on purpose, what's duplicated (keep in sync), per-adapter deltas (do not sync away) and demo gifs.
agentic-tech-debt AGENTS.md
Instructions for bcanfield/agentic-tech-debt: The agent instructions for this repo live in CLAUDE.md — one source of truth for every coding agent. Read it and follow it as written; it applies to Codex exactly as it does to Claude Code.