tfenv bash.instructions.md

A set of Bash coding rules for the tfenv repository, a tool that manages Terraform versions. It covers how scripts are structured, formatted, and written.

In plain words
What is it for?
Use it when creating or editing tfenv Bash scripts, especially scripts in its libexec directory.
Why use it?
It gives coding agents clear rules to check before changing shell scripts, reducing formatting and setup mistakes.

Instructions file for GitHub Copilot

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/tfutils/tfenv/bash
Clone the repo
git clone --depth 1 https://github.com/tfutils/tfenv

Made for: GitHub Copilot.

Per session 939 This file is loaded in full into every session.
When invoked 939 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00939 $0.00939
Opus 5 $0.00469 $0.00469
Sonnet 5 $0.00188 $0.00188
Haiku 4.5 $0.00094 $0.00094

Measured 2d ago against content hash c9a29f63457c, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

tfenv bash.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/instructions/bash.instructions.md · 103 lines

How it starts

The opening of the file, as written. The whole thing — 103 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Bash Coding Standards — tfenv

These standards apply to ALL bash scripts in the tfenv repository. Read this entire document BEFORE writing or modifying any bash code.

Mandatory Pre-Write Verification

Before writing ANY bash code, verify you understand these rules. Violations caught after writing waste time — get it right first.

Shell Setup

Every script in libexec/ contains its own boilerplate for resolving TFENV_ROOT and sourcing helpers. This is intentional — each script must be executable in isolation. Do NOT refactor this into a shared loader.

#!/usr/bin/env bash
set -uo pipefail;
  • Shebang: #!/usr/bin/env bash (exact format)
  • Strict mode: set -uo pipefail; — NEVER use set -e
  • The project does NOT use shellcheck — this is a deliberate choice

Indentation and Formatting

  • 2-space indentation throughout (no tabs)
  • Terminate ALL statements with a semicolon (;) where syntactically correct
  • Include vim modeline at end of new scripts: # vim: set syntax=bash tabstop=2 softtabstop=2 shiftwidth=2 expandtab smarttab :

Variables

  • ALL variable references use braces: ${variable} (never $variable)
  • Script-local variables use lowercase: ${version}, ${remote}
  • Environment variables use UPPERCASE: ${TFENV_ROOT}, ${TFENV_ARCH}
  • Always quote variable expansions: "${variable}"
  • Quote entire strings containing variables: "${dir}/file" NOT "${dir}"/file
  • Use ${var:-default} for optional variables (scripts run with set -u)

Quoting

  • Single-quote strings unless variable expansion is needed
  • Double-quote strings that contain variable expansion
  • NEVER use unescaped ! inside double-quoted strings (bash history expansion)

Command Substitution

  • Use $(...) NOT backticks

Error Handling

  • NEVER use set -e — handle errors explicitly
  • Use the project's existing error patterns:
    • error_and_die for fatal errors (available via lib/helpers.sh)
    • Inline || pattern for simple cases:
      some_command || error_and_die "Failed to do thing";
      
  • Note: error_and_die does NOT exist in the test context — tests use error_and_proceed instead

Read the full file on GitHub · 103 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 103 lines · 939 tokens per session scan A c9a29f63457c

Subscribe to this mod's changes

tfenv bash.instructions.md is an instructions file published in the GitHub repository tfutils/tfenv (4,966 stars, last pushed 2mo ago), licensed MIT. It adds 939 tokens to every session, about $0.0047 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.