Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/yankieldbc2/saas-cybersecurity/agents-mdgit clone --depth 1 https://github.com/YankielDBC2/saas-cybersecurityWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00335 | $0.00335 |
| Opus 5 | $0.00168 | $0.00168 |
| Sonnet 5 | $0.00067 | $0.00067 |
| Haiku 4.5 | $0.00034 | $0.00034 |
Grade A, and why
saas-cybersecurity AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Agent working agreement
Purpose
Maintain saas-cybersecurity as a portable, defensive Agent Skill for evidence-based SaaS security review and safe remediation.
Rules
- Keep
SKILL.mdconcise and route detailed material intoreferences/. - Preserve compatibility with Codex and Claude Code's filesystem-based Agent Skill format.
- Keep runtime scripts dependency-free on Node.js 18 or newer.
- Treat static matches as triage evidence, not confirmed vulnerabilities, unless the evidence is intrinsically conclusive.
- Never add real secrets, live targets, private reports, exploit payloads, destructive probes, or instructions for unauthorized access.
- Update the control catalog, platform compatibility guidance, tests, and documentation together when behavior changes.
- Run
npm test,npm run validate, and the upstream skill validator before release. - Do not publish or release without reviewing
git diff,git status, and a secret scan.
Repository map
SKILL.md: portable skill entrypoint and safety workflow.references/: detailed controls, platform routing, browser/runtime checks, safe hardening, and report format.scripts/audit.mjs: dependency-free static triage and platform detection.scripts/test-audit.mjs: deterministic behavior tests.scripts/validate-repository.mjs: package integrity and documentation validation.agents/openai.yaml: Codex UI metadata.docs/: maintainer-oriented architecture and project context.
Definition of done
Changes are scoped, documented, cross-platform where practical, tested, free of secrets, and do not turn uncertain evidence into false assurance.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 31 lines · 335 tokens per session scan A 56a4fcc6db80
saas-cybersecurity AGENTS.md is an instructions file published in the GitHub repository YankielDBC2/saas-cybersecurity (2 stars, last pushed 5d ago), licensed MIT. It adds 335 tokens to every session, about $0.0017 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
violin AGENTS.md
Instructions for Strategic-Automation/violin, covering strategic-automation/violin — ai developer guidance, 1. stack & setup, 2. mandatory verification commands, 3. code conventions & architecture and 4. git & branching strategy.
bv-mcp CLAUDE.md
Claude Code instructions for MadaBurns/bv-mcp, covering claude.md, what is this?, commands, tech and architecture.
Security Context
Use when performing security audits, reviewing code for vulnerabilities, triaging findings, or assessing OWASP compliance in this repository.
bv-mcp copilot-instructions.md
Copilot instructions for MadaBurns/bv-mcp, covering project guidelines, build and test, runtime and code style, architecture and project conventions.
Scan Orchestration
Use when modifying scandomain orchestration, maturity staging, post-processing adjustments, partial timeout handling, or scan report formatting in this repository.
MCP Tool Implementation
Use when adding or modifying MCP tools, DNS checks, schemas, handlers, scan orchestration, or scoring-related findings in this repository.