soia-open-skills: Instructions file for Codex

AGENTS.md

soia-open-skills AGENTS.md is an instructions file for Codex, OpenCode from soia-team/soia-open-skills. It costs 2,034 tokens per session, scanned A, original, MIT.

Repository-specific instructions for soia-team/soia-open-skills, a project that publishes shared resources for AI-agent skills. They describe the repository's purpose, safety rules, validation, and Git workflow.

In plain words
What is it for?
Use them when editing that repository, especially when adding or changing skills, documentation, catalog tools, routing data, or other published files.
Why use it?
They help an agent avoid committing private credentials, machine-specific paths, or unrelated project content. They also clarify which files belong in this repository and how changes should be checked.

Instructions file for CodexOpenCode

Written for Codex and OpenCode: reads ~/.codex or $CODEX_HOME, but also the file is AGENTS.md. Also seen: mentions AGENTS.md; mentions Codex.

This is soia-team/soia-open-skills's own configuration. It tells Codex and OpenCode how to work on soia-open-skills itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything soia-open-skills configures →

Reuse

Borrowing it

Nothing to install: this file belongs to soia-team/soia-open-skills. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/soia-team/soia-open-skills/main/AGENTS.md
Clone the repo
git clone --depth 1 https://github.com/soia-team/soia-open-skills

Made for: Codex, OpenCode.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for soia-open-skills AGENTS.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/soia-team/soia-open-skills/agents-md/github.svg)](https://agentmods.dev/instructions/soia-team/soia-open-skills/agents-md)
Your own site
<a href="https://agentmods.dev/instructions/soia-team/soia-open-skills/agents-md"><img src="https://agentmods.dev/badge/instructions/soia-team/soia-open-skills/agents-md/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for soia-open-skills AGENTS.md

Your own site · 80×15
<a href="https://agentmods.dev/instructions/soia-team/soia-open-skills/agents-md"><img src="https://agentmods.dev/badge/instructions/soia-team/soia-open-skills/agents-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 2,034 This file is loaded in full into every session.
When invoked 2,034 The same file — it is already loaded in full.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.02034 $0.02034
Opus 5 $0.01017 $0.01017
Sonnet 5 $0.00407 $0.00407
Haiku 4.5 $0.00203 $0.00203

Measured 2d ago against content hash 5d9dc60fdd5c, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade A, and why

soia-open-skills AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 99 lines

How it starts

The opening of the file, as written. The whole thing — 99 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AGENTS.md - soia-open-skills

Rules for all AI agents editing this repository.

规则适用与任务完成

  • 宿主实际加载的全局规则、父目录规则与本文件共同适用;本文件补充本仓事实和边界,不把共享贡献手册的旧示例当作新的授权。遇到无法按层级消解的实质冲突,指出具体条款,仅暂停受影响动作。
  • 解释、诊断或审阅只读取相关规则与证据,不自动授权修复、安装或发布;明确要求实施且范围已清楚时,完成修改、适度验证和结果交付,不只返回计划。
  • 已批准范围内的常规补丁、相关只读检查和验证连续推进;只在缺少会实质改变结果的信息、重叠改动无法安全保留,或下一步超出授权时询问。已确认且目标与影响未变的计划不重复确认。
  • 未提交改动属于原作者;不清理、不混入提交、不覆盖。无关脏文件不阻断可隔离工作,真实重叠只暂停冲突部分。
  • 不因仓名或“完整交付”默认启动多模型、子 Agent、全生态扫描、全量安装或产品治理流程;仅在用户要求、适用项目角色规则或任务风险明确需要时采用对应流程。
  • 提交、远端写入、合并、部署、发布、发送消息、权限变更、凭据操作及重要数据删除仍遵守各自授权门;本地修改完成不代表这些后续动作已获授权。
  • 交付说明实际改动、验证结果、未验证项及阻塞。要求实施的任务应做到授权边界内可验证的完成;区分本次已请求但待批的剩余步骤与未请求的后续动作;未请求的发布/安装不属于本次未完成工作。

Repository Purpose

soia-open-skills is the public SOIA Skills ecosystem portal and specification source of truth. It retains the soia-meta-* ecosystem skills (the generated catalog is the count source), the shared authoring/storage specifications and template, the canonical audit and catalog tooling, and the public cross-repository routing manifest. Domain skills are published from focused spoke repositories. Every committed artifact must be safe for users who do not share the maintainer's machine, vault layout, accounts, private data, or SOIA internal workspace.

Safety Rules

  • No real API keys, tokens, cookies, session strings, passwords, account ids, private config.yml, or .env files.
  • No maintainer-specific absolute paths such as /Users/<name>/....
  • No private family, home, health, finance, or learner profile context.
  • Put user-specific behavior behind CLI args, env vars, or skill-specific user-owned config files outside this repo: ~/.config/soia-skills/<skill-name>/config.yml. The former <repo>/<skill-type>/<skill-name>/ namespace is only a read-compatible v1 migration source; all new writes use the v2 skill-name directory.
  • Public examples must use placeholders such as <path>, <repo>, and <YOUR_KEY>.

Validation

日常验证按影响面选择:纯指令/文档修订先检查 diff、链接与条款一致性;脚本或技能行为变化运行受影响测试。涉及技能行为、脚本、依赖或公共工具的提交前执行以下完整门禁;纯指令/说明文档提交不机械套用全仓测试,但 CI/正式发布明确要求的检查不得省略:

Read the full file on GitHub · 99 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago Changed · +6 lines · +709 tokens per session 5d9dc60fdd5c
  2. 10d ago First seen · 93 lines · 1,325 tokens per session scan A a19d00dfdc2d

Subscribe to this mod's changes

soia-open-skills AGENTS.md is an instructions file published in the GitHub repository soia-team/soia-open-skills (5 stars, last pushed yesterday), licensed MIT. It adds 2,034 tokens to every session, about $0.0102 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,153 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

deepseek-harness AGENTS.md

AGENTS.md instructions for deepseek-ai/deepseek-harness, covering agents.md, pre-stable apis and released session data, repository layout, commands and host sandbox failures.

deepseek-ai/deepseek-harness · 3,735 tokens