Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/wlyaaaaa/ai-cli-profile-manager/agents-mdgit clone --depth 1 https://github.com/wlyaaaaa/ai-cli-profile-managerWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/wlyaaaaa/ai-cli-profile-manager/agents-md)<a href="https://agentmods.dev/instructions/wlyaaaaa/ai-cli-profile-manager/agents-md"><img src="https://agentmods.dev/badge/instructions/wlyaaaaa/ai-cli-profile-manager/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01730 | $0.01730 |
| Opus 5 | $0.00865 | $0.00865 |
| Sonnet 5 | $0.00346 | $0.00346 |
| Haiku 4.5 | $0.00173 | $0.00173 |
Grade A, and why
ai-cli-profile-manager AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 52 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AI CLI Profile Manager 项目规则
1. 事实源与工作阶段
- 默认使用简体中文。
- 维护与发布前读取
docs/maintainer/项目设计与实施归档.md;它是合并后的产品范围、决策、合同与实施事实源。 - 本机
docs/research-inputs/*.txt只是被 Git 排除的讨论输入,存在截断和过时信息,不能作为实现真相。 - 产品名 AI CLI Profile Manager、模块名和命令
aicli应集中定义;不要把品牌字符串散落在代码里。 - 阶段由用户指令决定。产品设计完成不自动授权创建远端、发布、推送或 Release。
2. 产品硬边界
- 只做 Windows 11、PowerShell 7。
- 这是原生 Codex CLI / Claude Code 的 Profile、启动、代理运维、Doctor、自检和中文手册层;不做 GUI、TUI、PTY 外壳、自研 Agent 或通用聊天历史库。Codex harness 允许维护最小、root-owned、不可变分段的 app-server 恢复账本,只用于证明同 thread exact resume,不保存任务正文、隐藏推理或工具载荷。
- 不汉化或修改上游 CLI 本体;原生终端交互、上下文和会话由上游负责。AICLI 的 Codex harness 对所有当前和未来模型统一固定原生
danger-full-access,不得按 Profile/Provider 降权或静默改写;交互式start仍由上游 Codex 权限界面负责。 - AICLI 的 Codex harness 对所有当前和未来模型默认注册受管
public_web_searchdynamic tool,不维护模型 allowlist;只允许固定 HTTPS RSS provider、拒绝重定向/任意 endpoint/Header/凭据,公开事件不得包含 query/result。必须保留显式--no-web-search,但关闭搜索不得改变danger-full-access权限。 - 所有 Codex harness Profile 必须共用持久恢复合同:只允许 app-server
thread/resume复用已记录的 exact thread/session,并回读同一 workspace、Profile 指纹、model/provider、requested/effective effort 和权限身份。新 thread、身份漂移、不可验证事件/receipt、迟到终态或重放覆盖必须失败关闭;禁止把旧上下文重提到新会话冒充恢复。 - Codex 公开第三方路径只接受上游已明确支持的 Responses Provider。Qwen 云端只开放两个隔离 exact Workspace paygo Profile:
codex-qwen3-7-max-paygo→qwen3.7-max-2026-06-08与codex-qwen3-8-max-paygo→qwen3.8-max。Qwen3.7 的通用 alias、05-20、preview、Plus、旧 Profile ID 与 native model/fallback 绕过继续退役;06-08 只能经新 exact Profile 进入。DeepSeek 只开放 exactdeepseek-v4-flash/DeepSeek-V4-Flash-0731与deepseek-v4-pro/DeepSeek-V4-Pro-0813两个隔离 Profile,禁止其他 V4 alias/version/reserved/fallback。不得把 Chat Completions 端点伪装成 Codex Responses。 - Claude Code 与 Open Interpreter 的公开 DeepSeek 模板只保留
deepseek-v4-flash;旧 Pro 验收记录不得跨当前 Profile 指纹复用。任何旧 Qwen3.7 用户 Profile、非 06-08 模型参数或生成物都必须失败关闭,不得自动迁移到新 Profile 或 Qwen3.8。 - 原生 ChatGPT/Codex 与官方 Claude Profile 是连续性基准,不附加第三方模型目录或压缩策略。第三方 Codex/Claude/OpenCode 的窗口与自动压缩仍以受管 catalog/modelMetadata 和客户端原生能力为准;未知第三方 Claude 模型不猜容量,并清除继承的窗口、提前压缩与禁压缩变量。不得关闭溢出保护。AICLI 的
aicli.third-party-continuity.v1契约要求有损压缩前把最小 checkpoint 写入项目已有状态,压缩后重读项目规则、状态文档与 diff,不建立第二事实源。 - 未完成当期 Windows 11 真实验证的 Provider 不得标成
可用。
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 52 lines · 1,730 tokens per session scan A ccbd8006f3c6
ai-cli-profile-manager AGENTS.md is an instructions file published in the GitHub repository wlyaaaaa/ai-cli-profile-manager (1 stars, last pushed 4d ago), licensed MIT. It adds 1,730 tokens to every session, about $0.0086 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
agency-orchestrator CLAUDE.md
Instructions for jnMetaCode/agency-orchestrator, covering agency orchestrator — project context, key commands, community templates (remote manifest), release pipeline (all automatic) and skills (methodology playbooks).
codexia AGENTS.md
AGENTS.md instructions for milisp/codexia, covering agents.md, project info, project tech, common commands and project structure.
ai4j AGENTS.md
AGENTS.md instructions for LnYo-Cly/ai4j, covering repository guidelines, project identity, monorepo scope, harness anything and hard rules.
ai4j CLAUDE.md
Claude Code instructions for LnYo-Cly/ai4j: 本项目以 AGENTS.md 作为 coding agent 指令的唯一权威入口。.
dev-flow AGENTS.md
Instructions for Innocent-children/dev-flow, covering dev flow repository instructions, authority, requirement scope, documentation and internationalization and product boundary.
dsh-codex-app-server AGENTS.md
Instructions for LyleMi/dsh-codex-app-server, covering repository guidelines, project structure & module organization, build, test, and development commands, coding style & naming conventions and testing guidelines.