Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/srnichols/plan-forge/daprgit clone --depth 1 https://github.com/srnichols/plan-forgeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.04968 | $0.04968 |
| Opus 5 | $0.02484 | $0.02484 |
| Sonnet 5 | $0.00994 | $0.00994 |
| Haiku 4.5 | $0.00497 | $0.00497 |
Grade A, and why
plan-forge dapr.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 672 lines — stays where its author put it; the contents beside it link to each section on GitHub.
.NET Dapr Patterns
Standard: Dapr v1.14+ with .NET Aspire / Docker Compose
Packages:Dapr.AspNetCore,Dapr.Client,Dapr.Workflow
Cross-ref:messaging.instructions.mdcovers pub/sub message schemas and CloudEvents in detail
Sidecar Architecture
Non-Negotiable Rules
- NEVER call external services directly — always go through the Dapr sidecar
- NEVER hardcode Dapr HTTP/gRPC ports — use
DAPR_HTTP_ENDPOINT/DAPR_GRPC_ENDPOINTenv vars - ALWAYS scope components to the services that need them
- ALWAYS use the typed
DaprClient— never raw HTTP tolocalhost:3500
DaprClient Registration
// Program.cs — register DaprClient with DI
var builder = WebApplication.CreateBuilder(args);
// Standard registration
builder.Services.AddDaprClient();
// NativeAOT-compatible registration (source-generated JSON)
builder.Services.AddDaprClient(clientBuilder =>
{
clientBuilder.UseJsonSerializationOptions(new JsonSerializerOptions
{
TypeInfoResolver = AppJsonContext.Default,
PropertyNamingPolicy = JsonNamingPolicy.CamelCase
});
});
var app = builder.Build();
app.MapSubscribeHandler(); // Required for pub/sub subscriptions
Docker Compose Sidecar Pattern
# Each service gets its own Dapr sidecar container
my-service:
build: ./MyService
environment:
- DAPR_HTTP_ENDPOINT=http://my-service-sidecar:3500
- DAPR_GRPC_ENDPOINT=http://my-service-sidecar:50001
my-service-sidecar:
image: daprio/daprd:1.14.4
command:
- ./daprd
- --app-id=my-service
- --app-port=8080
- --dapr-http-port=3500
- --dapr-grpc-port=50001
- --resources-path=/components
- --log-level=info
volumes:
- ./dapr/components:/components
network_mode: service:my-service # Share network namespace
# Placement service (required for actors/workflows)
dapr-placement:
image: daprio/dapr:1.14.4
command: ["./placement", "--port", "50006"]
State Management
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 672 lines · 4,968 tokens per session scan A ad7623919d62
plan-forge dapr.instructions.md is an instructions file published in the GitHub repository srnichols/plan-forge (5 stars, last pushed 22d ago), licensed MIT. It adds 4,968 tokens to every session, about $0.0248 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
maf-doctor maf-deployment.instructions.md
Always-loaded production-deployment patterns for MAF 1.3.0. Auto-applies to Program.cs, DI registration files, and infra config. Covers ManagedIdentityCredential, MaxTokens caps, secret handling, OpenTelemetry wiring, and the analyzer rules that catch regressions at write time.
dotnet-skills AGENTS.md
Instructions for managedcode/dotnet-skills, covering agents.md, purpose, solution topology, rule precedence and path and linking rules.
dotnet-skills copilot-instructions.md
Instructions for managedcode/dotnet-skills: Use AGENTS.md as the repository-wide source of truth for workflow, catalog structure, release policy, and skill maintenance rules.
apex-accelerator copilot-instructions.md
Instructions for jonathan-vella/apex-accelerator, covering apex - copilot instructions, azure defaults (canonical), default regions, required tags (azure policy enforced) and security baseline + avm mandate.
apex-accelerator iac-terraform-best-practices.instructions.md
Terraform-specific IaC best practices for Azure templates. AVM-first, CAF naming, security baseline, provider pins.
apex-accelerator iac-bicep-best-practices.instructions.md
Bicep-specific IaC best practices for Azure templates. Security baseline, naming, AVM mandate, anti-patterns.