Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/safetymp/autonomous-ehs-management/agents-mdgit clone --depth 1 https://github.com/SafetyMP/Autonomous-EHS-ManagementWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01009 | $0.01009 |
| Opus 5 | $0.00504 | $0.00504 |
| Sonnet 5 | $0.00202 | $0.00202 |
| Haiku 4.5 | $0.00101 | $0.00101 |
Grade A, and why
Autonomous-EHS-Management AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 66 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Site contract
Gates
| Command | Purpose |
|---|---|
./scripts/verify.sh |
Functional and static acceptance |
./scripts/adversarial.sh |
Authorized local adversarial probes |
Record verification_scripts as site-relative scripts/harness (exactly verify.sh and adversarial.sh). Optional wrappers may remain at scripts/verify.sh / scripts/adversarial.sh for humans; they are outside the digest boundary.
The corporate handoff fixes scope. The site manager assigns ADRs; site specialists write; the root orchestrator dispatches nondelegating workers and runs gate commands; operations excellence reviews immutable root-produced evidence. Work in isolated roots, never edit corporate approval state, and never self-approve. A site role cannot return work to corporate design; that boundary requires an explicit user rework authorization.
Site id: ehs. Prior Cursor Harness v4 is under _archives/harness-v4/.
Contributor / CI gates
| Local | Mirrors |
|---|---|
npm run verify |
CI job verify (lint + tsc + Vitest) |
./scripts/verify.sh |
CI verify + threat-model check |
npm run verify:all |
verify + Playwright smoke (not full CI) |
./scripts/integration-e2e.sh |
Same smoke path as CI e2e-smoke (before adversarial) |
./scripts/adversarial.sh |
CI e2e-smoke adversarial step (needs a running app URL) |
CI workflow .github/workflows/ci.yml runs three required jobs (pin in rulesets — see REPO_SETUP.md):
supply-chain-audit—npm audit --omit=dev --audit-level=highverify— lint,tsc, Viteste2e-smoke— Postgres migrate/seed, Playwright smoke, threat-model (PRs), adversarial probes
On trunk pushes, CI jobs release and publish run only after supply-chain-audit, verify, and e2e-smoke succeed (needs:). Production promote requires a full git SHA (not latest).
Smoke E2E (Playwright @smoke)
CI always runs signed-in smoke against service Postgres (db:migrate + db:seed:ci). Locally, signed-in specs skip unless PLAYWRIGHT_E2E_EMAIL / PLAYWRIGHT_E2E_PASSWORD are set against a migrated, seeded DB (see .env.example).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 66 lines · 1,009 tokens per session scan A 70a521f12843
Autonomous-EHS-Management AGENTS.md is an instructions file published in the GitHub repository SafetyMP/Autonomous-EHS-Management (5 stars, last pushed 2d ago), licensed Apache-2.0. It adds 1,009 tokens to every session, about $0.0050 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
openscreen AGENTS.md
Instructions for getopenscreen/openscreen, covering agents.md, setup commands, development principles, project layout and code style.
Claw3D AGENTS.md
Instructions for iamlukethedev/Claw3D, covering agent instructions, cursor cloud specific instructions, service overview, running the app and lint, typecheck, and tests.
claude-ads CLAUDE.md
Instructions for AgriciDaniel/claude-ads, covering claude ads repository instructions, architecture, development and verification.
openstatus AGENTS.md
AGENTS.md instructions for openstatusHQ/openstatus, covering agents.md, verify your change, toolchain, architecture and tests.
openstatus CLAUDE.md
Claude Code instructions for openstatusHQ/openstatus, covering claude.md and investigating production with polylane.
abap2UI5 CLAUDE.md
Instructions for abap2UI5/abap2UI5: All project guidance lives in AGENTS.md — the single source of truth for this repository (architecture and the layered design, the src/00-99 packages, the generated app/webapp mirror, the build and delivery pipeline, the CI gates and ABAP code style).