cap-agentic-engineered AGENTS.md

A project-specific AGENTS.md instruction file for an SAP sample repository. It defines coding style, development rules, available commands, and MCP usage.

In plain words
What is it for?
Use it when working on the SAP sample to guide conversational style, type usage, imports, keybindings, dependency fixes, and post-change checks.
Why use it?
It gives an agent the repository's local rules, reducing inconsistent code and unsafe or disallowed development steps.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/sap-samples/cap-agentic-engineered/agents-md
Clone the repo
git clone --depth 1 https://github.com/SAP-samples/cap-agentic-engineered

Made for: Codex, OpenCode.

Per session 1,133 This file is loaded in full into every session.
When invoked 1,133 The same file — it is already loaded in full.
Security scan C 2 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01133 $0.01133
Opus 5 $0.00566 $0.00566
Sonnet 5 $0.00227 $0.00227
Haiku 4.5 $0.00113 $0.00113

Measured 2d ago against content hash 5101e69d8232, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade C, and why

cap-agentic-engineered AGENTS.md scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Downloads and executes remote codehighSupply chain

curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.

- Never use `curl | bash`, `npx`, `pnpm dlx`, `uvx`, `pipx`, `cargo install`, `go install`, or any remote install one-liner without an exact pinned version and explicit approval

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

- Never use `curl | bash`, `npx`, `pnpm dlx`, `uvx`, `pipx`, `cargo install`, `go install`, or any remote install one-liner without an exact pinned version and explicit approval
AGENTS.md · 73 lines

How it starts

The opening of the file, as written. The whole thing — 73 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Conversational Style

  • Keep answers short and concise
  • No emojis in commits, PR comments, or code
  • Technical prose only
  • No fluff or filler text

Code Quality

  • No any types unless absolutely necessary
  • Check node_modules for external API type definitions instead of guessing
  • NEVER use inline imports - no await import("./foo.js"), no import("pkg").Type in type positions, no dynamic imports for types. Always use standard top-level imports.
  • NEVER remove or downgrade code to fix type errors from outdated dependencies; upgrade the dependency instead
  • Always ask before removing functionality or code that appears to be intentional
  • Do not preserve backward compatibility unless the user explicitly asks for it
  • Never hardcode key checks with, eg. matchesKey(keyData, "ctrl+x"). All keybindings must be configurable. Add default to matching object (DEFAULT_EDITOR_KEYBINDINGS or DEFAULT_APP_KEYBINDINGS)

Commands

  • After code changes (not documentation changes): npm run check (get full output, no tail). Fix all errors, warnings, and infos before committing.
  • Note: npm run check does not run tests.
  • NEVER run: npm run dev, npm run build, npm test
  • Only run specific tests if user instructs: npx tsx ../../node_modules/vitest/dist/cli.js --run test/specific.test.ts
  • Run tests from the package root, not the repo root.
  • If you create or modify a test file, you MUST run that test file and iterate until it passes.
  • When writing tests, run them, identify issues in either the test or implementation, and iterate until fixed.
  • For packages/coding-agent/test/suite/, use test/suite/harness.ts plus the faux provider. Do not use real provider APIs, real API keys, or paid tokens.
  • Put issue-specific regressions under packages/coding-agent/test/suite/regressions/ and name them <issue-number>-<short-slug>.test.ts.
  • NEVER commit unless user asks

Development Rules

MCP Servers: Query Before Writing SAP Code

Before writing, modifying, or fixing any SAP-specific code, query the relevant MCP server. Do not rely on training knowledge alone. If MCP guidance conflicts with general knowledge, follow MCP.

Read the full file on GitHub · 73 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 73 lines · 1,133 tokens per session scan C 5101e69d8232

Subscribe to this mod's changes

cap-agentic-engineered AGENTS.md is an instructions file published in the GitHub repository SAP-samples/cap-agentic-engineered (12 stars, last pushed 3mo ago), licensed Apache-2.0. It adds 1,133 tokens to every session, about $0.0057 per session on Opus 5. A static security scan graded it C with 2 findings (downloads and executes remote code, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.