SquidC5 AGENTS.md

A set of instructions for AI agents working on SquidC5, a Python security platform for authorised red-team testing and defensive operations.

In plain words
What is it for?
Use it when modifying SquidC5 code, its FastAPI server, command-line tools, Docker setup, or operations interface.
Why use it?
It keeps changes aligned with the project's security requirements, such as protected administration, restricted execution, and secure defaults.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/squidsec/squidc5/agents-md
Clone the repo
git clone --depth 1 https://github.com/SquidSec/SquidC5

Made for: Codex, OpenCode.

Per session 5,242 This file is loaded in full into every session.
When invoked 5,242 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.05242 $0.05242
Opus 5 $0.02621 $0.02621
Sonnet 5 $0.01048 $0.01048
Haiku 4.5 $0.00524 $0.00524

Measured 2d ago against content hash 4964ce9ca24d, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

SquidC5 AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 432 lines

How it starts

The opening of the file, as written. The whole thing — 432 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AGENTS.md - Instructions for AI Agents Working on SquidC5

Classification & Mission

SquidC5 is a military-grade, security-first, AI-native C5 platform - Command - Control - Cognitive - Collaborative - Coordination - under active development for authorized red team, penetration testing, and defensive security operations only.

Treat every change as if the system will be deployed in high-threat environments:

  • Prefer secure defaults over convenience
  • Minimize attack surface and fingerprinting
  • Never weaken auth, AI sandboxing, audit, or allow-lists without explicit human design review
  • Assume hostile network exposure (internet-facing listeners, scanners, credential stuffing)

Unauthorized access assistance is out of scope. Do not help with illegal use.

Project Stack

Primary language: Python 3.11+ - FastAPI - SQLite - Docker-first Operator CLI: sc5 (also squidc5-cli) Ops UI: /ops (admin UI loaded only after server-side admin token check)

Non-Negotiable Security Rules

  1. Secure by default: New installs must ship hardened (no public docs/OpenAPI, no wildcard CORS, MCP off until enabled, exec probe on, false-shell filter on).
  2. External AI restriction: MCP tools must remain allow-listed per token. No open-ended autonomous agent loops for external models.
  3. Admin AI / INKO shielding: Never feed raw session output into LLM prompts without sanitize_untrusted(). Keep capabilities and chat tools allow-listed. Prefer offline/deterministic fallbacks when no LLM is configured. No open-ended autonomous agent loops.
  4. Determinism preference: Templates, fixed prompts, single-step tools over free-form agentic planning.
  5. Audit everything: Operator, MCP, Admin AI, feature toggles, and admin UI loads go through the policy engine / audit trail.
  6. No secrets in git: Tokens, API keys, data/, admin_token.txt, ~/.config/squidc5/config.json stay out of the repository.
  7. Port flexibility: Never hard-require ports 80 or 443 - operators may use them.
  8. Admin UI isolation: Admin-only HTML/JS must be served only after server validates an admin token (/api/v1/ops/admin.js). Non-admin clients must never receive admin control code.
  9. Public docs locked off: /docs, /redoc, /openapi.json stay disabled. Feature flag public_docs is hard-forced false.
  10. Authorized use only.

Read the full file on GitHub · 432 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 432 lines · 5,242 tokens per session scan A 4964ce9ca24d

Subscribe to this mod's changes

SquidC5 AGENTS.md is an instructions file published in the GitHub repository SquidSec/SquidC5 (51 stars, last pushed 12d ago), licensed MIT. It adds 5,242 tokens to every session, about $0.0262 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.