mcp-revelor: Instructions file for Codex

AGENTS.md

mcp-revelor AGENTS.md is an instructions file for Codex, OpenCode from Webotvurci-s-r-o/mcp-revelor. It costs 3,493 tokens per session, scanned B, original, MIT.

A set of AGENTS.md instructions that tells AI assistants how to assess their abilities and guide users through installing an MCP server. MCP is a way for assistants to connect to external tools and services.

In plain words
What is it for?
Explaining installation steps for different assistant environments and handling the difference between tool-enabled agents and chat-only assistants.
Why use it?
It helps prevent assistants from claiming they can edit files or run commands when they cannot, and includes token-safety guidance.

Instructions file for CodexOpenCode

Written for Codex and OpenCode: the file is AGENTS.md. Also seen: mentions Claude Code; mentions AGENTS.md.

This is Webotvurci-s-r-o/mcp-revelor's own configuration. It tells Codex and OpenCode how to work on mcp-revelor itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything mcp-revelor configures →

Reuse

Borrowing it

Nothing to install: this file belongs to Webotvurci-s-r-o/mcp-revelor. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/Webotvurci-s-r-o/mcp-revelor/main/AGENTS.md
Clone the repo
git clone --depth 1 https://github.com/Webotvurci-s-r-o/mcp-revelor

Made for: Codex, OpenCode.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for mcp-revelor AGENTS.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/webotvurci-s-r-o/mcp-revelor/agents-md/github.svg)](https://agentmods.dev/instructions/webotvurci-s-r-o/mcp-revelor/agents-md)
Your own site
<a href="https://agentmods.dev/instructions/webotvurci-s-r-o/mcp-revelor/agents-md"><img src="https://agentmods.dev/badge/instructions/webotvurci-s-r-o/mcp-revelor/agents-md/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for mcp-revelor AGENTS.md

Your own site · 80×15
<a href="https://agentmods.dev/instructions/webotvurci-s-r-o/mcp-revelor/agents-md"><img src="https://agentmods.dev/badge/instructions/webotvurci-s-r-o/mcp-revelor/agents-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 3,493 This file is loaded in full into every session.
When invoked 3,493 The same file — it is already loaded in full.
Security scan B 2 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.03493 $0.03493
Opus 5 $0.01747 $0.01747
Sonnet 5 $0.00699 $0.00699
Haiku 4.5 $0.00349 $0.00349

Measured 11d ago against content hash da835fb57d1b, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade B, and why

mcp-revelor AGENTS.md scanned grade B with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Strips warnings and disclaimersmediumAnti-refusal

Omitting safety caveats hides risk from the user and is a common jailbreak preamble.

If user pastes a token in chat by mistake, **tell them to revoke it immediately** in the Revelor dashboard (and acknowledge the risk briefly, don't moralize).

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

bash <(curl -sSL https://raw.githubusercontent.com/Webotvurci-s-r-o/mcp-revelor/main/install.sh)
AGENTS.md · 315 lines

How it starts

The opening of the file, as written. The whole thing — 315 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AGENTS.md — Auto-setup guide for AI assistants

For AI agents (Claude, Cursor, Copilot, Claude Code...): if the user asks to install this MCP, follow this guide.

Ask for the minimum, do the rest yourself — IF you can.

Step 0 — Detect your own capabilities first

Before you start, honestly check what you can do:

Your environment Can you edit user's files? Can you run shell commands on user's machine? Follow Path
Claude Code (CLI) ✅ yes ✅ yes A — auto-install
Cursor with file tools ✅ yes ✅ yes (with permission) A — auto-install
Copilot agent / IDE with terminal ✅ yes ✅ yes A — auto-install
claude.ai web chat ❌ no — sandboxed ❌ no B — guide user
Claude Desktop chat window ❌ no — chat UI only ❌ no B — guide user
Any chat-only AI ❌ no ❌ no B — guide user

⚠️ Don't pretend you can do something you can't. If the user says "můžeš to udělat za mě / máš mé svolení" but you are a chat-only AI, explain that it's a capability issue, not a permissions issue: you have no channel to their filesystem.

Sample honest answer (in Czech):

„Není to permissions issue — je to capability issue. Já běžím v izolovaném prostředí, které nemá žádné spojení s tvým PC. Kdybys mi dal milion oprávnění, pořád nemám kanál k tvému disku. Ale projdu to s tebou krok po kroku — bude to rychlé."

Goal (both paths)

Add an entry to the user's MCP client config so it can talk to the user's Revelor instance.


🔐 Token safety — ALWAYS

Tokens (rvlr_*) are like passwords. NEVER:

  • Echo the user's token back in your response
  • Ask them to paste the token in chat — they should paste it directly into the config file
  • Suggest sending the token via email / Slack / chat

If user pastes a token in chat by mistake, tell them to revoke it immediately in the Revelor dashboard (and acknowledge the risk briefly, don't moralize).

Read the full file on GitHub · 315 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 11d ago First seen · 315 lines · 3,493 tokens per session scan B da835fb57d1b

Subscribe to this mod's changes

mcp-revelor AGENTS.md is an instructions file published in the GitHub repository Webotvurci-s-r-o/mcp-revelor (0 stars, last pushed 3mo ago), licensed MIT. It adds 3,493 tokens to every session, about $0.0175 per session on Opus 5. A static security scan graded it B with 2 findings (strips warnings and disclaimers, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,153 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,126 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens