Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/srnichols/plan-forge/azdgit clone --depth 1 https://github.com/srnichols/plan-forgeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01499 | $0.01499 |
| Opus 5 | $0.00749 | $0.00749 |
| Sonnet 5 | $0.00300 | $0.00300 |
| Haiku 4.5 | $0.00150 | $0.00150 |
Grade A, and why
plan-forge azd.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 215 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Azure Developer CLI (azd) Best Practices
Required Structure
Every azd-compatible project requires:
project-root/
├── azure.yaml ← service definition (required)
├── infra/ ← IaC files (default; change with infra.path)
│ ├── main.bicep ← or main.tf for Terraform
│ ├── main.parameters.json
│ └── modules/
├── .azure/ ← azd environment state (git-ignored)
└── src/ ← application source code (optional for pure infra)
azure.yaml
# azure.yaml — maps app services to provisioned Azure resources
name: myapp # must match infra resource naming
metadata:
template: [email protected] # optional: template origin tracking
# Infrastructure provider (default: bicep)
infra:
provider: bicep # bicep | terraform
path: infra # relative path to IaC files (default: infra)
module: main # root module filename without extension (default: main)
services:
api:
project: ./src/api # relative path to service source
language: dotnet # dotnet | js | ts | python | java
host: containerapp # appservice | containerapp | function | staticwebapp | aks
docker:
path: ./src/api/Dockerfile
context: ./src/api
web:
project: ./src/web
language: js
host: staticwebapp
dist: build # relative path to built artifacts
# Pipeline provider (default: github)
pipeline:
provider: github # github | azdo
Terraform Variant
name: myapp-terraform
infra:
provider: terraform
path: infra
services:
api:
project: ./src/api
language: dotnet
host: containerapp
Required Resource Tags for azd Auto-Discovery
When resourceName is NOT set in azure.yaml, azd discovers resources by tags:
// In your Bicep module — tag resources so azd can find them
resource containerApp 'Microsoft.App/containerApps@2024-03-01' = {
tags: union(commonTags, {
'azd-env-name': environmentName // ← required for azd discovery
'azd-service-name': 'api' // ← must match service key in azure.yaml
})
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 215 lines · 1,499 tokens per session scan A 3b0cdf5446a8
plan-forge azd.instructions.md is an instructions file published in the GitHub repository srnichols/plan-forge (5 stars, last pushed 22d ago), licensed MIT. It adds 1,499 tokens to every session, about $0.0075 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
maf-doctor maf-deployment.instructions.md
Always-loaded production-deployment patterns for MAF 1.3.0. Auto-applies to Program.cs, DI registration files, and infra config. Covers ManagedIdentityCredential, MaxTokens caps, secret handling, OpenTelemetry wiring, and the analyzer rules that catch regressions at write time.
dotnet-skills AGENTS.md
Instructions for managedcode/dotnet-skills, covering agents.md, purpose, solution topology, rule precedence and path and linking rules.
optio CLAUDE.md
Instructions for jonwiggins/optio, covering claude.md, what is optio?, architecture, pod-per-repo with worktrees and worktree lifecycle.
dotnet-skills copilot-instructions.md
Instructions for managedcode/dotnet-skills: Use AGENTS.md as the repository-wide source of truth for workflow, catalog structure, release policy, and skill maintenance rules.
apex-accelerator copilot-instructions.md
Instructions for jonathan-vella/apex-accelerator, covering apex - copilot instructions, azure defaults (canonical), default regions, required tags (azure policy enforced) and security baseline + avm mandate.
apex-accelerator iac-terraform-best-practices.instructions.md
Terraform-specific IaC best practices for Azure templates. AVM-first, CAF naming, security baseline, provider pins.