spec-spine: Instructions file for Codex

AGENTS.md

spec-spine AGENTS.md is an instructions file for Codex, OpenCode from statecrafting/spec-spine. It costs 3,395 tokens per session, scanned A, original, Apache-2.0.

A repository instruction document that defines how coding agents should begin sessions and work through a governed backlog. It names the project’s required checks, files, tools, and workflow rules.

In plain words
What is it for?
It is for starting sessions, following specification-led implementation work, running the project’s validation commands, and applying repository governance rules.
Why use it?
It gives different coding agents one source of project rules, reducing inconsistent commands, skipped checks, and changes made outside the intended specification scope.

Instructions file for CodexOpenCode

Written for Codex and OpenCode: the file is AGENTS.md. Also seen: reads .claude/ paths; mentions CLAUDE.md; mentions subagents.

This is statecrafting/spec-spine's own configuration. It tells Codex and OpenCode how to work on spec-spine itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything spec-spine configures →

Reuse

Borrowing it

Nothing to install: this file belongs to statecrafting/spec-spine. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/statecrafting/spec-spine/main/AGENTS.md
Clone the repo
git clone --depth 1 https://github.com/statecrafting/spec-spine

Made for: Codex, OpenCode.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for spec-spine AGENTS.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/statecrafting/spec-spine/agents-md/github.svg)](https://agentmods.dev/instructions/statecrafting/spec-spine/agents-md)
Your own site
<a href="https://agentmods.dev/instructions/statecrafting/spec-spine/agents-md"><img src="https://agentmods.dev/badge/instructions/statecrafting/spec-spine/agents-md/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for spec-spine AGENTS.md

Your own site · 80×15
<a href="https://agentmods.dev/instructions/statecrafting/spec-spine/agents-md"><img src="https://agentmods.dev/badge/instructions/statecrafting/spec-spine/agents-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 3,395 This file is loaded in full into every session.
When invoked 3,395 The same file — it is already loaded in full.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.03395 $0.03395
Opus 5 $0.01698 $0.01698
Sonnet 5 $0.00679 $0.00679
Haiku 4.5 $0.00340 $0.00340

Measured today against content hash 9650ab4b3b0c, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

spec-spine AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 173 lines

How it starts

The opening of the file, as written. The whole thing — 173 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AGENTS.md: spec-spine

New Sessions

Run /init as the mandatory first action of every new session. The command reads this section to derive its execution plan dynamically: any item added here is automatically picked up on the next init. This file is the cross-agent authority (read by Claude Code, Codex CLI, Cursor, Copilot, and any future agent via the AAIF/Linux Foundation AGENTS.md standard).

Init protocol (executed by /init):

AGENTS.md is loaded implicitly as the protocol source: its contents are the protocol, so /init does not list AGENTS.md as a parallel identity read in Step 1 (avoiding the self-reference loop).

The protocol drives the library through its own built binary, target/release/spec-spine (dogfooding). If that binary is missing, build it first: cargo build --release -p spec-spine-cli. Do NOT reach for npx spec-spine here; the npm/py distributions are for adopters, the self-governance loop uses the in-tree binary.

  1. Load rules. Read .claude/rules/orchestrator-rules.md, .claude/rules/governed-artifact-reads.md, AND .claude/rules/adversarial-prompt-refusal.md (the three the library scaffolds for every adopter via spec-spine init, and which it carries for itself).
  2. Parallel reads. Dispatch the following simultaneously (nothing here mutates the working tree, so there is no required ordering):
    • CLAUDE.md: project overview and conventions
    • README.md: full project description
    • standards/spec/contract.md: normative spec-system summary
    • standards/spec/constitution.md: durable principles (tier 2)
    • spec-spine compile --check: freshness gate for the spec registry (non-fatal; see Registry freshness below)
    • spec-spine index check: staleness gate for the codebase index (non-fatal)
    • spec-spine index render: markdown projection of the committed index
    • spec-spine index coverage: which source files no spec specifically claims (spec 032; non-fatal, exit 2 if the index is stale)
    • spec-spine index diagnostics: the unresolved-unit diagnostics the committed index records (spec 050; non-fatal, empty output means none)
    • spec-spine registry status-report --json --nonzero-only: lifecycle counts per status
    • spec-spine registry plan: the ready set (spec 038): which specs can be worked on now and what blocks the rest; (nothing ready) in a finished corpus
    • spec-spine registry list --ids-only: spec id list (for latest-spec detection)
    • ls crates/: library crate layout
    • ls specs/: the spec corpus
    • ls docs/: docs surface (design notes, governance)
    • git log --oneline -10: recent history
    • git diff --stat HEAD~1: last change summary
  3. Emit the ## initialized: spec-spine summary block: a layer/crate overview, a ## lifecycle: sub-section populated from the registry status-report --nonzero-only output (with the registry plan ready/blocked line beneath it), the freshness verdicts, the unresolved-unit count from index diagnostics, recent activity, and a "ready to help with" line.

Read the full file on GitHub · 173 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. today Changed · +4 lines · +121 tokens per session 9650ab4b3b0c
  2. yesterday First seen · 169 lines · 3,274 tokens per session scan A 22aa33fc75ec

Subscribe to this mod's changes

spec-spine AGENTS.md is an instructions file published in the GitHub repository statecrafting/spec-spine (10 stars, last pushed today), licensed Apache-2.0. It adds 3,395 tokens to every session, about $0.0170 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-07.

Related

Other instructions, from other repositories

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,153 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens