Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/tkellogg/tupac/agents-mdgit clone --depth 1 https://github.com/tkellogg/tupacWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01498 | $0.01498 |
| Opus 5 | $0.00749 | $0.00749 |
| Sonnet 5 | $0.00300 | $0.00300 |
| Haiku 4.5 | $0.00150 | $0.00150 |
Grade A, and why
tupac AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 158 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Spec for “tupac” — a CLI MCP ↔ OpenAI Responses bridge (latest deps, quoting your brief)
“i want to build a CLI MCP client app. python, uv, FastMCP, typer, on the openai responses API”
-
Name the package tupac.
-
Latest libs (all installed with
uv add):openai@ latest (o-series ready)fastmcp@ latest — v 2.4.0 adds one-line Client(config) multi-server support ([gofastmcp.com][1])typer@ latest (>= 0.12)rich@ latest (for colour) ([typer.tiangolo.com][2])- Python ≥ 3.11
“the CLI takes a JSON file and a prompt. the JSON configures MCP servers and a system prompt. the app is a simple loop that…”
CLI (tupac run cfg.json "prompt"):
- Load config (
system_prompt,mcp_servers, model, etc.). - Construct
mcp_serversarray exactly as in Claude’s MCP connector docs ([docs.anthropic.com][3]). - Instantiate
fastmcp.Client(config)— passing the parsed MCP-server list straight in satisfies the new constructor signature; no manual tool mapping required. - Seed
messages = [{"role":"system","content":system_prompt}, {"role":"user","content":prompt}].
Loop:
while True:
resp = client.responses.create(
model=config.model,
input=messages,
mcp_servers=config.mcp_servers, # Claude-format JSON
stream=False
)
out = resp.output[0]
if out.type == "mcp_tool_use":
try:
result = await mcp.call_tool(out) # fastmcp handles dispatch
messages += [
out,
{"type":"mcp_tool_result",
"tool_use_id": out.id,
"is_error": False,
"content": result}
]
except Exception as exc:
messages += [
out,
{"type":"mcp_tool_result",
"tool_use_id": out.id,
"is_error": True,
"content": str(exc)}
]
continue # keep cycling
break # plain assistant text → done
Tool errors are surfaced to the model ( is_error=True ) so it can recover automatically.
“maps MCP tools to responses API … parameters are the complicated part”
FastMCP now exposes Tool.model_json_schema(); embed that JSON Schema untouched inside each tool definition so the Responses API can validate arguments itself ([gofastmcp.com][1]).
“handle all MCP data types properly…”
| MCP content | How tupac returns it |
|---|---|
TextContent |
inline text |
ImageContent, PdfContent, AudioContent, VideoContent, any BlobContent |
print only the generated file-name (e.g. out_2025-06-07T12-00-01.png) and tell the human “open this file to view”; save bytes to ./outputs/ |
The canonical list of binary types (images, PDFs, audio, video) is in the MCP Resources spec ([modelcontextprotocol.io][4]).
“for resources, maintain a cache… list of compact representations … cache misses include the full text”
Use an LRU keyed by uri.
Send two XML blocks (why XML? Anthropic’s prompt-engineering guide emphasises XML tags for structured context) ([docs.anthropic.com][5]):
<resources>
<resource uri="https://foo" title="Foo doc" type="text"/>
…
</resources>
<resource_details>
<resource uri="https://foo"><![CDATA[full text]]></resource>
</resource_details>
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 158 lines · 1,498 tokens per session scan A d5eeeb43b5b2
tupac AGENTS.md is an instructions file published in the GitHub repository tkellogg/tupac (11 stars, last pushed 11mo ago), licensed MIT. It adds 1,498 tokens to every session, about $0.0075 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
next.js AGENTS.md
Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.