DashClaw GEMINI.md

Repository instructions for coding agents working on DashClaw, infrastructure that checks AI-agent actions before they reach outside systems. It describes policy checks, human approvals, recorded evidence, monitoring, and decision-drift detection.

In plain words
What is it for?
Use them when developing or reviewing DashClaw features involving agent permissions, policy evaluation, approvals, action records, monitoring, or reliability.
Why use it?
They give an agent the project context needed to change governance code safely and consistently. They clarify how risky actions are evaluated, approved, blocked, and recorded.

Instructions file for Gemini CLI

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/ucsandman/dashclaw/gemini-md
Clone the repo
git clone --depth 1 https://github.com/ucsandman/DashClaw

Made for: Gemini CLI.

Per session 1,379 This file is loaded in full into every session.
When invoked 1,379 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01379 $0.01379
Opus 5 $0.00690 $0.00690
Sonnet 5 $0.00276 $0.00276
Haiku 4.5 $0.00138 $0.00138

Measured 3d ago against content hash a8c177344856, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

DashClaw GEMINI.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

GEMINI.md · 325 lines

How it starts

The opening of the file, as written. The whole thing — 325 lines — stays where its author put it; the contents beside it link to each section on GitHub.

DashClaw Development Context

This file provides operational context for AI coding agents working inside the DashClaw repository.

Agents must treat this repository as a production open source infrastructure project. All modifications should prioritize stability, developer clarity, and maintainability.

DashClaw is infrastructure software. Avoid introducing complexity unless it clearly improves reliability or developer experience.


Project Overview

DashClaw is a governance runtime for AI agent decisions.

It governs AI agents before they execute real world actions by introducing a policy evaluation and approval layer.

Core decision flow:

Agent intent -> policy evaluation -> approval or block -> execution -> decision evidence recorded

DashClaw acts as the decision governance layer between AI agents and external systems.

The platform allows developers and organizations to:

  • intercept risky agent actions
  • enforce policy checks
  • require human approval
  • record verifiable decision evidence
  • monitor agent behavior
  • detect decision drift

DashClaw enables permissioned autonomy for AI agents.


Core Product Primitives

These primitives define the DashClaw architecture.

Guard

Evaluates policies before an agent executes an action.

Example usage:

const decision = await claw.guard({ actionType: "deploy", riskScore: 85 })

Guard responses determine whether actions are:

  • allowed
  • blocked
  • escalated for approval

Action Records

Capture what the agent attempted to do.

Includes:

  • action type
  • parameters
  • reasoning
  • execution outcome

Assumptions

Tracks what the agent believed to be true when making a decision.

Used to detect decision drift and incorrect reasoning.


Approvals

Allows high risk actions to pause until a human operator approves or rejects them.


Evidence

Every governed decision produces verifiable evidence.

Evidence enables:

  • debugging agent behavior
  • compliance reporting
  • post incident analysis

Read the full file on GitHub · 325 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 325 lines · 1,379 tokens per session scan A a8c177344856

Subscribe to this mod's changes

DashClaw GEMINI.md is an instructions file published in the GitHub repository ucsandman/DashClaw (296 stars, last pushed 5d ago), licensed MIT. It adds 1,379 tokens to every session, about $0.0069 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.