sweetpad CLAUDE.md

sweetpad CLAUDE.md is an instructions file for coding agents from sweetpad-dev/sweetpad. It costs 1,147 tokens per session, scanned A, original, MIT.

Project-specific instructions for Sweetpad, a Rust code workspace with a command-line tool and a Visual Studio Code extension. They describe CLI releases, option types, and changelog writing.

In plain words
What is it for?
They guide CLI version bumps, tests, lint checks, commits, tags, signing, notarization, GitHub releases, Homebrew updates, and related code or documentation changes.
Why use it?
They keep development and release work consistent with the project's documented rules and safety checks. They also explain that publishing a release makes it available to users through GitHub and Homebrew.

Instructions file

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/sweetpad-dev/sweetpad/claude-md
Clone the repo
git clone --depth 1 https://github.com/sweetpad-dev/sweetpad

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for sweetpad CLAUDE.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/sweetpad-dev/sweetpad/claude-md.svg)](https://agentmods.dev/instructions/sweetpad-dev/sweetpad/claude-md)
Your own site
<a href="https://agentmods.dev/instructions/sweetpad-dev/sweetpad/claude-md"><img src="https://agentmods.dev/badge/instructions/sweetpad-dev/sweetpad/claude-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 1,147 This file is loaded in full into every session.
When invoked 1,147 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01147 $0.01147
Opus 5 $0.00574 $0.00574
Sonnet 5 $0.00229 $0.00229
Haiku 4.5 $0.00115 $0.00115

Measured 4d ago against content hash 281989ec8275, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

sweetpad CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

CLAUDE.md · 92 lines

How it starts

The opening of the file, as written. The whole thing — 92 lines — stays where its author put it; the contents beside it link to each section on GitHub.

sweetpad

A Rust workspace (sweetpad-lib, sweetpad-core, sweetpad-cli, sweetpad-vscode/native) plus the VS Code extension. sweetpad-cli/CLI_DESIGN.md is the CLI's design record — grammar, output model, and the per-version feature sections (§9a onward), including directions that are written down but not scheduled. sweetpad-lib/CLAUDE.md covers the project-file and build-settings crate.

Releasing the CLI

sweetpad-lib/ci/release.sh 0.1.3 cuts a release: it bumps the [workspace.package] version, refreshes Cargo.lock, runs tests and clippy, commits Release CLI <version>, tags cli-v<version>, and pushes after an interactive confirm (--yes skips it). Guards refuse a dirty tree, a branch other than main, a main out of sync with origin, and a tag that already exists.

Pushing the tag is the publish step, and it is public and effectively irreversible. .github/workflows/cli-release.yaml builds a universal binary, signs it with the Developer ID, notarizes it with Apple, publishes a GitHub release, and pushes a formula bump to sweetpad-dev/homebrew-tap, which reaches everyone on brew upgrade. A bad release is superseded by the next version rather than retracted. The CLI ships through the tap on its own cadence; it is not bundled into the extension's VSIX.

The tag and the crate version must agree. The workflow names the release from the tag, while the binary's version is stamped from Cargo.toml. The Resolve version step fails the run when they differ, ahead of the signing and notarization legs, so a mismatch costs seconds instead of publishing a binary that contradicts its own formula.

Only a build made at the cli-v<version> tag reports the bare version. Anywhere else sweetpad --version stamps <version>-dev+<sha> (build.rs): the crate version alone cannot distinguish a build off main from the release sharing its number, so a bare version read off a local build is not evidence that a fix has shipped. release.sh compares only the part before the -, since it checks the binary before tagging.

Read the full file on GitHub · 92 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 92 lines · 1,147 tokens per session scan A 281989ec8275

Subscribe to this mod's changes

sweetpad CLAUDE.md is an instructions file published in the GitHub repository sweetpad-dev/sweetpad (1,874 stars, last pushed 8d ago), licensed MIT. It adds 1,147 tokens to every session, about $0.0057 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.