Borrowing it
Nothing to install: this file belongs to xxxoooxoxo/wiff. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/xxxoooxoxo/wiff/main/AGENTS.mdgit clone --depth 1 https://github.com/xxxoooxoxo/wiffWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/xxxoooxoxo/wiff/agents-md)<a href="https://agentmods.dev/instructions/xxxoooxoxo/wiff/agents-md"><img src="https://agentmods.dev/badge/instructions/xxxoooxoxo/wiff/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.01288 | $0.01288 |
| Opus 5 | $0.00644 | $0.00644 |
| Sonnet 5 | $0.00258 | $0.00258 |
| Haiku 4.5 | $0.00129 | $0.00129 |
Grade A, and why
wiff AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 37 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AGENTS.md
Instructions for coding agents. Two audiences: agents orchestrating with wiff from a harness, and agents working on this codebase.
Orchestrating with wiff (driving it from a harness)
wiff exposes five MCP tools through a disposable stdio bridge: workflow_start, workflow_status, workflow_wait, workflow_cancel, and workflow_models. The bridge auto-starts a detached local daemon that owns workflow execution, so runs survive the launching harness or MCP process exiting. You author a workflow as a plain JavaScript script and pass it to workflow_start with an absolute cwd; everything persists under ~/.wiff/runs/<runId>/.
Before authoring a script, read plugins/wiff/skills/workflow/references/api.md — it is the full script contract. Inside Codex the bundled $workflow skill loads it for you; from any other harness, read it (or copy the skill into your harness's skills directory).
Rules that catch agents out:
- Workflow code is sandboxed. No imports, filesystem, shell, network, time, or randomness inside the script — those all throw. Agents do the external work; the script only orchestrates.
- Give every
agent()call a stablekey. Keys are the resume/cache identity. A run resumed after a crash or script edit replays completed agents with unchanged(key, input)for free; without keys you re-pay for everything. parallel()takes thunks (() => agent(...)), not started promises, and preserves result order. Any rejection fails the workflow withAggregateError— that is deliberate (fail-hard). UseparallelSettled()only when the script explicitly handles per-item failure.- Defaults: model
gpt-5.6-sol, effortmedium, sandboxread-only, 10-minute execution timeout after queue admission. Seteffort: "low"for mechanical work andeffort: "high"for deep review or synthesis; raise the sandbox toworkspace-writeonly for agents that must edit files. - Concurrent writers need
isolation: "worktree". Each writing agent gets a fresh detached git worktree; clean ones vanish, dirty ones are kept and listed on the run for you to inspect or merge. Requirescwdto be inside a git repository. - Deterministic scripts resume. To pick up a dead or cancelled run:
workflow_startwith{ resumeFromRunId }. Completed agents replay from the journal; agents interrupted mid-turn re-run with a digest of their previous transcript injected. - Concurrency is capped at
min(16, max(2, cores − 2))running children (excess queue), and a run may request at most 1000 agents. - Personas (
agentType: "name") resolve from<cwd>/.codex/agents/<name>.md, then~/.codex/agents/<name>.md(CODEX_WORKFLOW_AGENTS_DIRoverrides). Editing a persona invalidates the cache of agents that use it. - Don't poll blindly.
workflow_waitblocks up to 55 s for a state change; loop on it rather than hammeringworkflow_status. - The parent may disconnect. Preserve the
runIdbefore ending the parent turn. A later MCP bridge can wait, inspect, or cancel the same daemon-owned run. Graceful daemon restarts resume durable active runs; abrupt daemon death leaves them safelyinterruptedfor explicit resume. - The first bridge supplies daemon environment. The daemon inherits that bridge's
PATH, backend credentials, and Wiff/Codex environment defaults until it restarts. If those values change, gracefully terminate the pid in~/.wiff/daemon.jsonor wait for idle shutdown before starting new work. - Inspect failures from disk.
~/.wiff/runs/<runId>/journal.jsonlrecords every phase/agent event with input hashes and token usage;agents/*.jsonlhold full per-child transcripts. Read those before re-running anything.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 37 lines · 1,288 tokens per session scan A fa35237d5245
wiff AGENTS.md is an instructions file published in the GitHub repository xxxoooxoxo/wiff (5 stars, last pushed 19d ago), licensed MIT. It adds 1,288 tokens to every session, about $0.0064 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.