Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/tallclub/matimo/claude-mdgit clone --depth 1 https://github.com/tallclub/matimoWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/tallclub/matimo/claude-md)<a href="https://agentmods.dev/instructions/tallclub/matimo/claude-md"><img src="https://agentmods.dev/badge/instructions/tallclub/matimo/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00873 | $0.00873 |
| Opus 5 | $0.00436 | $0.00436 |
| Sonnet 5 | $0.00175 | $0.00175 |
| Haiku 4.5 | $0.00087 | $0.00087 |
Grade A, and why
matimo CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 66 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Matimo OSS — CLAUDE.md
Policy-governed tool-execution SDK for AI agents. MIT licensed, dual TypeScript + Python implementation with feature parity. Part of the roaiq Matimo™ suite — see ../CLAUDE.md for how this fits with Matimo Workbench (Universal-AgentForge/).
What this is
Governance-first: every tool call (built-in, third-party, or agent-created) passes through a policy engine (risk classification low/medium/high/critical, 9 deterministic security rules, HITL quarantine) before executing. On top of that: 139+ tools across 10 provider packages (plus a governed 449-tool Composio catalog), 12 meta-tools for runtime self-extension (matimo_create_tool, matimo_create_skill, matimo_reload_tools, and 9 more), and one YAML tool definition that runs across TS, Python, LangChain, CrewAI, and MCP.
Layout
typescript/ pnpm workspace — packages/{core,cli,slack,github,gmail,notion,hubspot,postgres,twilio,mailchimp,microsoft,bruno,composio}
python/ uv workspace — packages/{core,cli,matimo,<same providers>} — mirrors typescript/ 1:1
docs/ full docs: getting-started, api-reference, architecture, tool-development, framework-integrations, mcp, skills
examples/ usage examples per integration pattern (factory, decorator, LangChain, MCP)
Commands
TypeScript (cd typescript):
pnpm install && pnpm build
pnpm test # jest; pretest runs build first
pnpm test:coverage
pnpm lint / lint:fix
pnpm validate-tools # validate all YAML tool definitions
Python (cd python):
make install # uv sync --all-extras --dev
make test / test-unit / test-integration / test-coverage
make lint / format / typecheck
make validate-tools
Changelog (repo root): pnpm changelog (git-cliff, from cliff.toml).
Conventions
- Conventional Commits: feat/fix/docs/style/refactor/perf/test/chore/ci/revert/example — enforced by commitlint + husky pre-commit.
- TS: strict mode, ESM (
"type": "module"), Node ≥18, pnpm ≥8. - Python: version pinned in
.python-version; ruff for lint/format; mypy strict onpackages/core/src. - New provider package → mirror an existing one exactly (see
slackorgithub) in both languages — see root skillnew-matimo-provider. - Every tool needs a risk classification (low/medium/high/critical) — see
docs/api-reference/POLICY_AND_LIFECYCLE.md. - 3,700+ tests, 95%+ coverage target across TS + Python — don't drop coverage on new code.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 66 lines · 873 tokens per session scan A 86debfc63edd
matimo CLAUDE.md is an instructions file published in the GitHub repository tallclub/matimo (11 stars, last pushed 2d ago), licensed MIT. It adds 873 tokens to every session, about $0.0044 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.