career-engine: Instructions file for Claude Code

CLAUDE.md

career-engine CLAUDE.md is an instructions file for Claude Code from spinningrachel/career-engine. It costs 42,217 tokens per session, scanned B, original, MIT.

Repository instructions for maintaining the Career Engine plugin, including which files and skills own its data and how changes must be checked.

In plain words
What is it for?
Use them when editing, extending, renaming, or restructuring the plugin, especially when working with its external career-data skill and release checks.
Why use it?
They prevent personal data from being included in the shipped plugin and require a QA check after every edit.

Instructions file for Claude Code

Written for Claude Code: ${CLAUDE_PLUGIN_ROOT} variable. Also seen: reads .claude/ paths; mentions CLAUDE.md; mentions subagents.

This is spinningrachel/career-engine's own configuration. It tells Claude Code how to work on career-engine itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything career-engine configures →

Runs only inside a plugin — its command needs a path that Claude Code sets for a plugin’s own hooks and for nothing else, and the catalogue could not identify which plugin ships it.

Reuse

Borrowing it

Nothing to install: this file belongs to spinningrachel/career-engine. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/spinningrachel/career-engine/main/CLAUDE.md
Clone the repo
git clone --depth 1 https://github.com/spinningrachel/career-engine

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for career-engine CLAUDE.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/spinningrachel/career-engine/claude-md.svg)](https://agentmods.dev/instructions/spinningrachel/career-engine/claude-md)
Your own site
<a href="https://agentmods.dev/instructions/spinningrachel/career-engine/claude-md"><img src="https://agentmods.dev/badge/instructions/spinningrachel/career-engine/claude-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 42,217 This file is loaded in full into every session.
When invoked 42,217 The same file — it is already loaded in full.
Security scan B 1 finding. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.42217 $0.42217
Opus 5 $0.21108 $0.21108
Sonnet 5 $0.08443 $0.08443
Haiku 4.5 $0.04222 $0.04222

Measured 7d ago against content hash e0718938b566, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-07, from the pricing page.

Security

Grade B, and why

career-engine CLAUDE.md scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Asks the agent to reveal its instructionsmediumSystem prompt leakage

Directions to print, repeat or translate the system prompt extract configuration the operator did not intend to expose.

**Placeholder resolution.** The plugin's instruction files keep `{{...}}` placeholders literally — they are NOT substituted at install, because substituting them would personalize the shared build. Agents resolve them at
CLAUDE.md · 337 lines

How it starts

The opening of the file, as written. The whole thing — 337 lines — stays where its author put it; the contents beside it link to each section on GitHub.

CLAUDE.md — Career Engine Plugin

Working instructions for Claude when editing, extending, or maintaining this plugin.


⛔ MANDATORY STOP — READ BEFORE DOING ANYTHING ELSE

You are not done with any plugin edit session until the QA agent has run and passed. No exceptions.

This means: after completing any set of changes — no matter how small — you MUST invoke the QA agent (agents/qa-plugin.md) before telling the user the work is complete. This is not optional and cannot be skipped because the changes "seem clean" or because you "already checked manually." Manual checking is how drift accumulates silently.

The plugin is a single build. There is no second personalized copy to keep in sync: the user's personal data lives entirely in the external career-data skill (see Data layer below), which the plugin never contains. QA validates the one shipped artifact and confirms it holds zero personal data.

How to invoke: Spawn the QA agent by reading agents/qa-plugin.md and following its instructions. Pass it the repo path and the built .plugin.

This gate applies to: any content edit, any rename, any new file, any property name change, any structural change, any cross-version sync. If you edited even one file, run QA.

⛔ NO SILENT CAPABILITY REMOVAL — every removal needs a quoted user instruction

Removing, disabling, or substituting-away any capability the user relies on — an input an agent reads (a file, an archive, a database property), an output an agent produces, a pipeline step, a quality pass, or a read of the user's own material — requires the user's explicit instruction, quoted in the commit message and the changelog entry. "This new mechanism makes the old read unnecessary," "this is now redundant," "the consolidated file covers it" are NOT authorization — they are exactly how the incident below happened. Additions and tightenings can ride on an agent's judgment; removals never can. If a change you're making seems to imply a removal, stop and ask — the user deciding "yes, remove it" costs one question; a silent removal cost weeks of degraded output.

Read the full file on GitHub · 337 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 7d ago First seen · 337 lines · 42,217 tokens per session scan B e0718938b566

Subscribe to this mod's changes

career-engine CLAUDE.md is an instructions file published in the GitHub repository spinningrachel/career-engine (4 stars, last pushed 26d ago), licensed MIT. It adds 42,217 tokens to every session, about $0.2111 per session on Opus 5. A static security scan graded it B with 1 finding (asks the agent to reveal its instructions). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens