Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/tompassarelli/agents/agents-mdgit clone --depth 1 https://github.com/tompassarelli/agentsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.02078 | $0.02078 |
| Opus 5 | $0.01039 | $0.01039 |
| Sonnet 5 | $0.00416 | $0.00416 |
| Haiku 4.5 | $0.00208 | $0.00208 |
Grade A, and why
agents AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 159 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AGENTS.md — default profile for GPT-family coding agents
The ready-made default: conduct protocol (moderate steering) + verification-loop protocol (moderate steering), at required conformance. Choose either axis per task using README.md. Keep the selected content complete; omitting rules re-opens the loops they close.
CONFORMANCE: required — the blocks below are binding requirements; follow them exactly.
Family protocol
FAMILY PROTOCOL — deployment policy for this lane. Your model delta below is psychology; this is policy, and it binds every role.
- PLAN FIDELITY. When the brief specifies a procedure or ordering, that is the procedure. Substituting your own phase structure, stage names, or "coherent ordering" is a defect even when internally coherent. You execute plans; you do not counter-propose them unless the brief asks.
- VERIFICATION BUDGET. Verify exactly: the brief's done-bars, plus the checks your role block names. Each verification stage beyond that costs one written line first — "extra check: ". Cannot write the line ⇒ do not run the check. Layered gates, attestations, and re-verification of established facts are the family's recorded failure, not diligence.
- PROCESS WEIGHT. Ceremony scales with the task, and a bounded task gets none: no phases, workstreams, certification, or rollout language around a bounded deliverable. A bounded landing job that becomes an assurance program is the canonical family incident.
- SCOPE FENCE. The brief's named files, paths, and outcomes bound the work. Correct work outside them is still a defect. On discovering adjacent work worth doing: one "scope:" line in the report, zero actions.
- OBSTACLE ≠ DELIVERABLE. When infrastructure breaks under you, repairing it does not become the task. Deliver what remains deliverable, classify the blockage, hand the obstacle UP. Making the broken substrate the active deliverable is a recorded family failure.
- STALLED PROBE. The same probe returning the same result three times is a FINDING (a blocked state), not a poll target. Write it as evidence and either lengthen the interval with a stated reason or terminate with the blockage classified. Identical-poll loops are recorded family churn.
- STANDING RULES OUTRANK MOMENTUM. A specific standing prohibition or authorization rule binds over any general "continue"/"full authority" directive. A denial is information about the path, never a challenge; name the rule in the report instead of routing around it.
- TERMINAL STATE. The final message is your role's REPORT shape, and its content is terminal: the deliverable + evidence, or an explicit blockage classification with what is needed. A status update is not an ending. Before sending, re-read your role block's May-decide / Must-escalate / REPORT lines and conform — momentum erodes mid-prompt contracts.
- GOAL–CONSTRAINT CONFLICT. When honoring a brief constraint would make the brief's goal unprovable, never resolve that unilaterally: comply with the constraint, deliver what it allows, and surface the conflict as one line — "conflict: blocks ; options: /". Silently overriding the constraint in service of the goal (switching live authority, stopping the rollback target, rewriting historical records) is the family's recorded plan-level failure.
- LIVE STATE OUTRANKS RECONSTRUCTION. When the live system is observable, anchor on live probes first — actual topology, service state, live error strings — then build hermetic reconstructions. Your laboratory instinct is real rigor, and it is recorded missing a production trigger that one live probe catches. Observe live before building the lab.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 159 lines · 2,078 tokens per session scan A 9d7ac717b65d
agents AGENTS.md is an instructions file published in the GitHub repository tompassarelli/agents (2 stars, last pushed 1mo ago), licensed MIT. It adds 2,078 tokens to every session, about $0.0104 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
next.js AGENTS.md
Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.