Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/srnichols/plan-forge/landing-zonegit clone --depth 1 https://github.com/srnichols/plan-forgeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/srnichols/plan-forge/landing-zone)<a href="https://agentmods.dev/instructions/srnichols/plan-forge/landing-zone"><img src="https://agentmods.dev/badge/instructions/srnichols/plan-forge/landing-zone.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.02228 | $0.02228 |
| Opus 5 | $0.01114 | $0.01114 |
| Sonnet 5 | $0.00446 | $0.00446 |
| Haiku 4.5 | $0.00223 | $0.00223 |
Grade A, and why
plan-forge landing-zone.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 258 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Azure Landing Zone Standards
Based on the Azure Landing Zone conceptual architecture. Landing Zones are the enterprise rulebook — the infrastructure baselines that every workload subscription must conform to before workload code is deployed.
Architecture Overview
┌──────────────────────────────────┐
│ Management Baseline │
│ Log Analytics · Automation · │
│ Backup · Update Mgmt · ASC │
└────────────────┬─────────────────┘
│ feeds
┌───────────────┐ ┌────────────────▼─────────────────┐ ┌──────────────────┐
│ Identity │ │ Security Baseline │ │ Network Baseline │
│ Baseline │──►│ Defender · Sentinel · JIT · │◄──│ Hub-Spoke · AFW │
│ AAD · PIM · │ │ SIEM · CVA · Secure Score │ │ NSG · UDR · DNS │
│ CA · MFA │ └────────────────┬─────────────────┘ └──────────────────┘
└───────────────┘ │ enforced by
┌────────────────▼─────────────────┐
│ Policy Baseline │
│ Initiatives · Deny · Audit · │
│ DeployIfNotExists · Remediation │
└────────────────┬─────────────────┘
│ governs
┌────────────────▼─────────────────┐
│ Workload Subscriptions │
│ (Corp · Online · Sandbox) │
└──────────────────────────────────┘
Identity Baseline
// ✅ User-assigned managed identity per workload (not system-assigned)
// ✅ No service principals with client_secret in production
// ✅ PIM for all Owner/Contributor role assignments (no standing access)
// PIM role assignment via Bicep (eligible, not active)
resource pimRoleEligibility 'Microsoft.Authorization/roleEligibilityScheduleRequests@2022-04-01-preview' = {
name: guid(subscription().id, principalId, contributorRoleId)
properties: {
principalId: principalId
roleDefinitionId: subscriptionResourceId('Microsoft.Authorization/roleDefinitions', contributorRoleId)
requestType: 'AdminAssign'
scheduleInfo: {
startDateTime: utcNow()
expiration: { type: 'NoExpiration' }
}
ticketInfo: {}
}
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 258 lines · 2,228 tokens per session scan A 073ddadb64b1
plan-forge landing-zone.instructions.md is an instructions file published in the GitHub repository srnichols/plan-forge (5 stars, last pushed today), licensed MIT. It adds 2,228 tokens to every session, about $0.0111 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
arai CLAUDE.md
Instructions for taniwhaai/arai, covering claude.md — arai, commands, architecture, prompt-collector module (src/promptcollector.rs) and extending the match pipeline.
ai-control-framework CLAUDE.md
Instructions for sgharlow/ai-control-framework, covering claude code configuration, framework status (v2.0) — verified 2026-07-18, ⚠️ critical: implementation required, mandatory session start procedure and hard stop conditions.
arai AGENTS.md
Instructions for taniwhaai/arai, covering agents.md — arai, core discipline (non-negotiable), taniwha / subagent rules, work style and tool usage.
skillfoundry copilot-instructions.md
Copilot instructions for samibs/skillfoundry, covering github copilot — skillfoundry project instructions, identity, non-negotiable rules, code quality and security.
skillfoundry AGENTS.md
AGENTS.md instructions for samibs/skillfoundry, covering what this is, philosophy, how to use skills, available skills by category and core workflow.
skillfoundry CLAUDE.md
Claude Code instructions for samibs/skillfoundry, covering claude.md — skillfoundry framework project instructions, philosophy, mandatory production rules, ui/layout rules and documentation rules.