Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/srnichols/plan-forge/wafgit clone --depth 1 https://github.com/srnichols/plan-forgeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01489 | $0.01489 |
| Opus 5 | $0.00745 | $0.00745 |
| Sonnet 5 | $0.00298 | $0.00298 |
| Haiku 4.5 | $0.00149 | $0.00149 |
Grade A, and why
plan-forge waf.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 176 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Azure Well-Architected Framework (WAF)
Based on the Microsoft Azure Well-Architected Framework. The WAF is the workload quality layer — it governs individual service design decisions.
The 5 Pillars
| Pillar | Core Question |
|---|---|
| Reliability | Will it stay available when things go wrong? |
| Security | Is the workload protected end-to-end? |
| Cost Optimization | Are we paying for what we actually use? |
| Operational Excellence | Can we deploy, operate, and recover safely? |
| Performance Efficiency | Does it scale and respond well under load? |
Reliability
Key Controls
// ✅ Deploy across availability zones — never single-zone in production
resource appServicePlan 'Microsoft.Web/serverfarms@2023-01-01' = {
sku: { name: 'P1v3'; tier: 'PremiumV3'; capacity: 2 }
properties: {
zoneRedundant: true // ← required for zone-pinned AZ support
}
}
// ✅ Health probes on load balancers and App Gateway
// ✅ Auto-scale rules based on CPU + memory, not just time-based
// ✅ Azure backup enabled for databases and storage
// ✅ Soft-delete + point-in-time restore for all databases
Reliability Checklist
- Resources deployed across ≥ 2 availability zones in production
- Auto-scale configured with appropriate min/max and cool-down
- Health checks / probes on every outward-facing service
- Recovery Time Objective (RTO) and Recovery Point Objective (RPO) defined
- Azure Backup enabled for databases and critical storage
- Geo-redundant storage (GRS or RA-GRS) for critical data in production
- Azure Site Recovery evaluated for VM/stateful workloads
- Circuit breaker / retry policies in application code (not just infra)
Security
See
security.instructions.mdfor the detailed Azure IaC security patterns.
WAF Security Checklist
- Managed Identity for all service-to-service auth — no static credentials
- Key Vault for all secrets, certificates, and keys
- Private endpoints for all PaaS services in production
- Azure DDoS Protection Standard on public-facing VNets
- Azure Web Application Firewall (WAF) on Application Gateway or Front Door
- Defender for Cloud Standard tier enabled on all subscriptions
- Just-in-time (JIT) VM access enabled
- Azure AD Conditional Access policies configured
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 176 lines · 1,489 tokens per session scan A a550d9a31ee2
plan-forge waf.instructions.md is an instructions file published in the GitHub repository srnichols/plan-forge (5 stars, last pushed 22d ago), licensed MIT. It adds 1,489 tokens to every session, about $0.0074 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
maf-doctor maf-deployment.instructions.md
Always-loaded production-deployment patterns for MAF 1.3.0. Auto-applies to Program.cs, DI registration files, and infra config. Covers ManagedIdentityCredential, MaxTokens caps, secret handling, OpenTelemetry wiring, and the analyzer rules that catch regressions at write time.
dotnet-skills AGENTS.md
Instructions for managedcode/dotnet-skills, covering agents.md, purpose, solution topology, rule precedence and path and linking rules.
optio CLAUDE.md
Instructions for jonwiggins/optio, covering claude.md, what is optio?, architecture, pod-per-repo with worktrees and worktree lifecycle.
dotnet-skills copilot-instructions.md
Instructions for managedcode/dotnet-skills: Use AGENTS.md as the repository-wide source of truth for workflow, catalog structure, release policy, and skill maintenance rules.
apex-accelerator copilot-instructions.md
Instructions for jonathan-vella/apex-accelerator, covering apex - copilot instructions, azure defaults (canonical), default regions, required tags (azure policy enforced) and security baseline + avm mandate.
apex-accelerator iac-terraform-best-practices.instructions.md
Terraform-specific IaC best practices for Azure templates. AVM-first, CAF naming, security baseline, provider pins.