Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/styrene-lab/lipstyk/agents-mdgit clone --depth 1 https://github.com/styrene-lab/lipstykWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01432 | $0.01432 |
| Opus 5 | $0.00716 | $0.00716 |
| Sonnet 5 | $0.00286 | $0.00286 |
| Haiku 4.5 | $0.00143 | $0.00143 |
Grade A, and why
lipstyk AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 174 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AGENTS.md
lipstyk is a static analysis tool that detects machine-generated code patterns. Deterministic rules, no ML. Rust codebase, edition 2024.
Build
cargo build --release # CLI only
cargo build --release --features agent # CLI + MCP/Omegon agent
cargo build --release --features lsp # CLI + LSP server
cargo test # 87 integration tests
CI runs cargo clippy -- -D warnings. Fix all warnings before opening
a PR.
Architecture
src/
rules/ # Rust-specific rules (AST via syn)
ts/ # TypeScript/JavaScript rules (AST via oxc + text)
python/ # Python rules (AST via tree-sitter + text)
golang/ # Go rules (AST via tree-sitter + text)
html/ # HTML/CSS rules (tag parser)
java/ # Java rules (text)
shell/ # Shell rules (text)
docker/ # Dockerfile rules (text)
devops/ # Kubernetes + CI/CD YAML rules (content-sniffed)
markdown/ # Markdown rules (text)
common/ # Shared analysis utilities
lint.rs # Linter core — rule registration and dispatch
source_rule.rs # SourceRule trait, Lang enum, SourceContext
diagnostic.rs # Diagnostic, Severity, SlopScore
config.rs # .lipstyk.toml loading
diff.rs # --diff mode (changed-lines filtering)
report.rs # Output formatting (JSON, SARIF, Markdown, summary)
main.rs # CLI entry point
agent.rs # MCP/Omegon entry point (behind `agent` feature)
lsp.rs # LSP server (behind `lsp` feature)
Adding a rule
1. Pick the right trait
Rust rules implement Rule (uses syn AST):
pub trait Rule: Send + Sync {
fn name(&self) -> &'static str;
fn check(&self, file: &syn::File, ctx: &LintContext) -> Vec<Diagnostic>;
}
LintContext carries filename, source, and exclude_tests.
All other languages implement SourceRule:
pub trait SourceRule: Send + Sync {
fn name(&self) -> &'static str;
fn langs(&self) -> &[Lang];
fn check(&self, ctx: &SourceContext) -> Vec<Diagnostic>;
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 174 lines · 1,432 tokens per session scan A f60f9807929d
lipstyk AGENTS.md is an instructions file published in the GitHub repository styrene-lab/lipstyk (11 stars, last pushed 22d ago), licensed MIT. It adds 1,432 tokens to every session, about $0.0072 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
next.js AGENTS.md
Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.