Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/sweetpad-dev/sweetpad/claude-mdgit clone --depth 1 https://github.com/sweetpad-dev/sweetpadWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/sweetpad-dev/sweetpad/claude-md)<a href="https://agentmods.dev/instructions/sweetpad-dev/sweetpad/claude-md"><img src="https://agentmods.dev/badge/instructions/sweetpad-dev/sweetpad/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01147 | $0.01147 |
| Opus 5 | $0.00574 | $0.00574 |
| Sonnet 5 | $0.00229 | $0.00229 |
| Haiku 4.5 | $0.00115 | $0.00115 |
Grade A, and why
sweetpad CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 92 lines — stays where its author put it; the contents beside it link to each section on GitHub.
sweetpad
A Rust workspace (sweetpad-lib, sweetpad-core, sweetpad-cli,
sweetpad-vscode/native) plus the VS Code extension. sweetpad-cli/CLI_DESIGN.md
is the CLI's design record — grammar, output model, and the per-version feature
sections (§9a onward), including directions that are written down but not
scheduled. sweetpad-lib/CLAUDE.md covers the project-file and build-settings
crate.
Releasing the CLI
sweetpad-lib/ci/release.sh 0.1.3 cuts a release: it bumps the
[workspace.package] version, refreshes Cargo.lock, runs tests and clippy,
commits Release CLI <version>, tags cli-v<version>, and pushes after an
interactive confirm (--yes skips it). Guards refuse a dirty tree, a branch
other than main, a main out of sync with origin, and a tag that already
exists.
Pushing the tag is the publish step, and it is public and effectively
irreversible. .github/workflows/cli-release.yaml builds a universal binary,
signs it with the Developer ID, notarizes it with Apple, publishes a GitHub
release, and pushes a formula bump to sweetpad-dev/homebrew-tap, which reaches
everyone on brew upgrade. A bad release is superseded by the next version
rather than retracted. The CLI ships through the tap on its own cadence; it is
not bundled into the extension's VSIX.
The tag and the crate version must agree. The workflow names the release
from the tag, while the binary's version is stamped from Cargo.toml. The
Resolve version step fails the run when they differ, ahead of the signing and
notarization legs, so a mismatch costs seconds instead of publishing a binary
that contradicts its own formula.
Only a build made at the cli-v<version> tag reports the bare version.
Anywhere else sweetpad --version stamps <version>-dev+<sha> (build.rs):
the crate version alone cannot distinguish a build off main from the release
sharing its number, so a bare version read off a local build is not evidence
that a fix has shipped. release.sh compares only the part before the -,
since it checks the binary before tagging.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 92 lines · 1,147 tokens per session scan A 281989ec8275
sweetpad CLAUDE.md is an instructions file published in the GitHub repository sweetpad-dev/sweetpad (1,874 stars, last pushed 8d ago), licensed MIT. It adds 1,147 tokens to every session, about $0.0057 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
best-claude-hud AGENTS.md
Instructions for GaoSSR/best-claude-hud, covering project agent instructions and release work.
vscode-gitlens CLAUDE.md
Claude Code instructions for gitkraken/vscode-gitlens, a project described as: Supercharge Git inside VS Code and unlock untapped knowledge within each repository — Visualize code authorship at a glance via Git blame annotations and CodeLens, seamlessly navigate and explore Git repositories, gain valuable insights via…
cetus AGENTS.md
Instructions for drewnekota/cetus, covering repository instructions and releases.
OpenMicro AGENTS.md
Instructions for stephenleo/OpenMicro, covering openmicro — project conventions and releases.
roamcode AGENTS.md
Instructions for burakgon/roamcode, covering repository instructions for coding agents, public-repository safety, stable release and ota contract, releasing a stable version and ota changes.
Product-Marketing-Skills CLAUDE.md
Instructions for stefanoskarakasis/Product-Marketing-Skills, covering claude.md, versioning & releases, release procedure (manual, until ci enforcement exists) and after any repo change.