Borrowing it
Nothing to install: this file belongs to shlokkhemani/rabbithole. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/shlokkhemani/rabbithole/main/AGENTS.mdgit clone --depth 1 https://github.com/shlokkhemani/rabbitholeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/shlokkhemani/rabbithole/agents-md)<a href="https://agentmods.dev/instructions/shlokkhemani/rabbithole/agents-md"><img src="https://agentmods.dev/badge/instructions/shlokkhemani/rabbithole/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00616 | $0.00616 |
| Opus 5 | $0.00308 | $0.00308 |
| Sonnet 5 | $0.00123 | $0.00123 |
| Haiku 4.5 | $0.00062 | $0.00062 |
Grade A, and why
rabbithole AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 53 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Notes for agents working in this repo
If you were sent here to install Rabbithole for a user, stop — you don't
need to clone or build anything. Follow the Quick start in README.md
(one claude mcp add / codex mcp add line). This file is for agents
developing the repo.
What this is
An MCP server (stdio) that opens a branching-document canvas in the browser. Plain ES modules, a small esbuild-based browser build, and script-driven tests.
bin/mcp-server.js— entry; just importssrc/node/mcp/server.jssrc/core/— host-independent document engine, renderer, artifacts, and contractssrc/ui/— browser runtime shared by live pages and frozen snapshotssrc/node/— MCP wiring (server namerabbithole), filesystem storage, sessions, local HTTP/SSE transport, and Node PDF ingestionsrc/web/— static BYOK browser host, provider adapters, and IndexedDB storesrc/core/html/— shared self-contained shell, tokens, and stylesheet sourcesrc/core/html/icons.js— canonical repository for all product-owned SVG icons and brand marksdist/— committed live and frozen UI bundles; regenerate after UI changestest/— capability-oriented suites documented indocs/testing.mdwebsite/public/— live public assets copied bybuild:publish
Run / debug
npm install
RABBITHOLE_NO_BROWSER=1 node bin/mcp-server.js # speaks MCP on stdio
npm run build # regenerate committed bundles
npm test # deterministic default suite
Storage is JSON files under ~/.rabbithole/ (RABBITHOLE_DIR overrides).
Logs go to stderr — stdout is reserved for the MCP protocol; never print to
stdout.
Conventions
- The product name is Rabbithole — one word, no space, in all copy.
- Node ≥ 18, ES modules everywhere.
- The canvas page must stay fully self-contained (one HTML response, no external assets) — that constraint is load-bearing for export/snapshots.
- stdout is reserved for MCP protocol messages; application logs go to stderr.
- Preserve old
.rabbitholefiles and snapshots according todocs/compatibility.md; future formats must fail clearly rather than truncate. - Put every product-owned SVG icon or brand mark in
src/core/html/icons.jsand render it withiconSvg(). Do not add inline icon geometry to shell, UI, web, settings, or website files. Structural/document SVG (for example the canvas edge layer or user-authored content) is not an icon and remains at its owning trust boundary.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 53 lines · 616 tokens per session scan A 46eb67800d1c
rabbithole AGENTS.md is an instructions file published in the GitHub repository shlokkhemani/rabbithole (310 stars, last pushed 4d ago), licensed MIT. It adds 616 tokens to every session, about $0.0031 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.