ai-agents: Instructions file for GitHub Copilot

.github/instructions/secret-redaction.instructions.md

ai-agents secret-redaction.instructions.md is an instructions file for GitHub Copilot from rjmurillo/ai-agents. It costs 650 tokens per session, scanned C, original, MIT.

Rules for removing credentials and personally identifying information before writing user or tool text into committed files or logs.

In plain words
What is it for?
Use them before saving free-text answers, evidence, session entries, retrospective notes, pull-request descriptions, or metrics.
Why use it?
They reduce the risk of permanently exposing secrets or private details through version history and diagnostic records.

Instructions file for GitHub Copilot

Written for GitHub Copilot: a Copilot instructions file. Also seen: reads .claude/ paths.

This is rjmurillo/ai-agents's own configuration. It tells GitHub Copilot how to work on ai-agents itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything ai-agents configures →

Needs its repository: it runs a file that does not travel with it, so clone the repository first. The line is python3 scripts/redact_secrets.py <file> # or pipe the text on stdin.

Reuse

Borrowing it

Nothing to install: this file belongs to rjmurillo/ai-agents. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/rjmurillo/ai-agents/main/.github/instructions/secret-redaction.instructions.md
Clone the repo
git clone --depth 1 https://github.com/rjmurillo/ai-agents

Made for: GitHub Copilot.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ai-agents secret-redaction.instructions.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/rjmurillo/ai-agents/secret-redaction.svg)](https://agentmods.dev/instructions/rjmurillo/ai-agents/secret-redaction)
Your own site
<a href="https://agentmods.dev/instructions/rjmurillo/ai-agents/secret-redaction"><img src="https://agentmods.dev/badge/instructions/rjmurillo/ai-agents/secret-redaction.svg" alt="Measured on agentmods" height="20"></a>
Per session 650 This file is loaded in full into every session.
When invoked 650 The same file — it is already loaded in full.
Security scan C 1 finding. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00650 $0.00650
Opus 5 $0.00325 $0.00325
Sonnet 5 $0.00130 $0.00130
Haiku 4.5 $0.00065 $0.00065

Measured 4d ago against content hash c9cf0f126591, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade C, and why

ai-agents secret-redaction.instructions.md scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Harvests environment variableshighData exfiltration

Enumerating or grepping the environment for keys collects credentials unrelated to what the mod says it does.

3. **State that the artifact is durable.** When you author a halt block, note in the surrounding prose that the block lands in git history, so the proposer knows not to paste live secrets into answers in the first place.
.github/instructions/secret-redaction.instructions.md · 36 lines

How it starts

The opening of the file, as written. The whole thing — 36 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Secret and PII Redaction Before Emit

Free-text that an agent writes into a durable artifact can carry a credential, token, or PII verbatim. Halt-block answer/evidence fields, session-log work entries, retro records, PR descriptions, and metric tallies all land in git. A proposer's answer like Alice@corp on prod-east-12.internal blocked on Bearer abc... is then disclosed for the life of the history. This is CWE-209 (information exposure through an error/diagnostic message) and CWE-532 (insertion of sensitive information into a log).

This rule applies when you emit free-text that originated from a user answer, an external paste, or tool output into any committed artifact: spec halt blocks (Step 0 answer, Step 0.5 evidence), session logs, retros, and PR descriptions.

MUST

  1. Redact before emit. Before writing a free-text field that may contain a credential or PII into a committed artifact, run it through the redactor and emit the redacted form:

    python3 scripts/redact_secrets.py <file>      # or pipe the text on stdin
    

    Or, in Python, from redact_secrets import redact; redact(text).text. Matched token shapes (private keys, GitHub/Stripe/AWS/Slack tokens, JWTs, Bearer headers, emails, hex secrets >= 32 chars) become [redacted: <reason>].

  2. Do not redact structured hex fields. A field whose contract is a git SHA or content hash (e.g. startingCommit, endingCommit) legitimately holds 40 or 64 hex chars. Pass include_hex=False for those, or do not run the redactor over them. Redacting a real SHA corrupts the record.

  3. State that the artifact is durable. When you author a halt block, note in the surrounding prose that the block lands in git history, so the proposer knows not to paste live secrets into answers in the first place. Redaction is a backstop, not a license to collect secrets.

MUST NOT

  1. MUST NOT emit a raw answer/evidence field that was copied from an untrusted paste without the redaction pass.
  2. MUST NOT treat redaction as scanning of committed code. Use CodeQL / the security-scan skill for repository secret scanning; this rule is only the emit-time backstop for agent-authored free-text.

Read the full file on GitHub · 36 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 36 lines · 650 tokens per session scan C c9cf0f126591

Subscribe to this mod's changes

ai-agents secret-redaction.instructions.md is an instructions file published in the GitHub repository rjmurillo/ai-agents (45 stars, last pushed yesterday), licensed MIT. It adds 650 tokens to every session, about $0.0032 per session on Opus 5. A static security scan graded it C with 1 finding (harvests environment variables). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other instructions, from other repositories

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,153 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens