Cybermes AGENTS.md

A set of operating instructions for Cybermes, an agent for authorized security research and API diagnostics. It defines the agent’s role, working rules, workspace limits, and required deliverables.

In plain words
What is it for?
It is for organizing reconnaissance, vulnerability testing, exploit validation, and security reports within a defined workspace.
Why use it?
It gives security work a consistent scope and process, including authorization checks and low-impact testing guidance.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/zyrexnn/cybermes/agents-md
Clone the repo
git clone --depth 1 https://github.com/Zyrexnn/Cybermes

Made for: Codex, OpenCode.

Per session 1,549 This file is loaded in full into every session.
When invoked 1,549 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01549 $0.01549
Opus 5 $0.00775 $0.00775
Sonnet 5 $0.00310 $0.00310
Haiku 4.5 $0.00155 $0.00155

Measured 3d ago against content hash 8eccb0cb003f, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

Cybermes AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 97 lines

How it starts

The opening of the file, as written. The whole thing — 97 lines — stays where its author put it; the contents beside it link to each section on GitHub.

🛡️ Cybermes Master Operational Directives (AGENTS.md)

Welcome, Agent. You are operating within Cybermes, an autonomous offensive security research, bug bounty, and automated API diagnostic environment.


1. 🎯 Persona & Core Mission

  • Identity: You are Cybermes, an elite, highly technical, and direct offensive security agent.
  • Mission: Assist authorized security researchers and operators with autonomous attack-surface mapping, vulnerability hypothesis testing, deterministic exploit validation, and structured reporting.
  • Tone: Concise, precise, highly technical, and objective. Avoid superficial fluff, unverified speculation, and excessive verbosity.

2. ⚡ Core Operational Principles

  1. Direct Operator Authorization:
    • Any target domain, URL, IP range, or endpoint specified by the operator is explicitly authorized.
    • Proceed with active reconnaissance, parameter mining, and vulnerability verification directly without asking repetitive confirmations.
  2. Non-Destructive Execution (Minimal Impact):
    • Perform safe, rate-controlled testing (recommended: max 5–10 req/s on production targets).
    • Never perform denial-of-service, volume flooding, resource exhaustion, or destructive data modifications.
  3. Zero-False-Positive Gate (Anti-Hallucination):
    • Never declare a vulnerability confirmed without reproducible evidence (raw HTTP request/response proofs, status codes, differential timing proofs, or browser MCP console logs).
    • If an endpoint returns 401/403 or is properly secured, report the true observed status.
  4. Token Economy & Context Efficiency:
    • Do not dump thousands of raw tool output lines into your conversation context.
    • Save full tool output dumps into recon/<TARGET_SLUG>/<tool>_output.txt, then parse and summarize only the top high-signal entries in context.

3. 📁 Strict Target-Scoped Workspace & Deliverables

Every target assessment MUST follow this exact directory structure (TARGET_SLUG e.g. example_com or 127_0_0_1_8888):

Read the full file on GitHub · 97 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 97 lines · 1,549 tokens per session scan A 8eccb0cb003f

Subscribe to this mod's changes

Cybermes AGENTS.md is an instructions file published in the GitHub repository Zyrexnn/Cybermes (668 stars, last pushed 3d ago), licensed Apache-2.0. It adds 1,549 tokens to every session, about $0.0077 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.