build-brief AGENTS.md

build-brief AGENTS.md is an instructions file for Codex, OpenCode from static-var/build-brief. It costs 396 tokens per session, scanned A, original, MIT.

A project instruction file for contributors working on the static-var/build-brief Go project. It records setup commands, code structure, testing requirements, and safety rules.

In plain words
What is it for?
Use it when changing build-brief code to find the right packages, run required checks, format files, and verify Go modules and diffs.
Why use it?
It gives coding agents and contributors the project's expected workflow instead of making them infer it from the repository.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/static-var/build-brief/agents-md
Clone the repo
git clone --depth 1 https://github.com/static-var/build-brief

Made for: Codex, OpenCode.

Per session 396 This file is loaded in full into every session.
When invoked 396 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00396 $0.00396
Opus 5 $0.00198 $0.00198
Sonnet 5 $0.00079 $0.00079
Haiku 4.5 $0.00040 $0.00040

Measured 3d ago against content hash 1393a022ce57, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

build-brief AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 23 lines

What it actually says

Contributor instructions

Setup and verification

  • Requires the Go version in go.mod (currently Go 1.26.1). Run go mod download; build with go build ./cmd/build-brief.
  • Before handing off code, run go test ./..., go vet ./..., and go test -race ./... when the platform supports it. Also use gofmt -w on changed Go files, go mod tidy -diff, go mod verify, and git diff --check.
  • CI runs tests on Linux, macOS, and Windows; Linux also runs the race detector. Its quality job enforces formatting, vet, module checks, shell syntax, and diff hygiene. Keep changes portable.

Architecture

  • cmd/build-brief: CLI entry point.
  • internal/app: argument parsing and orchestration; internal/gradle: command resolution/classification; internal/runner: process and raw-log capture.
  • internal/reducer, internal/output, internal/artifacts: summarize Gradle output and render results.
  • internal/config, internal/doctor, internal/rewrite, internal/install: configuration and auxiliary commands.
  • internal/tracking: local gains history. Local-only: gains history stays on this machine; no gains data is transmitted.
  • site/ is the static website; scripts/ and .github/workflows/ define release/CI operations; smoke/ holds Gradle smoke fixtures.

Safety

  • Preserve Gradle exit codes and raw-log behavior; do not change runtime behavior for documentation-only work.
  • Treat scripts/prepare-release.sh, artifact/formula scripts, and the Release workflow as release-only operations. Do not publish, merge, or release without explicit approval.
  • Keep this file concise; use README.md, tests, and current code as the detailed source of truth.
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 23 lines · 396 tokens per session scan A 1393a022ce57

Subscribe to this mod's changes

build-brief AGENTS.md is an instructions file published in the GitHub repository static-var/build-brief (20 stars, last pushed 1mo ago), licensed MIT. It adds 396 tokens to every session, about $0.0020 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.