Report · marked 25 Aug 2026
minimaxir/big-list-of-naughty-strings
An agent will struggle here, mostly for fixable reasons.
Python · 47,710 stars · 16 files · branch master
Higher is better. Accent marks what is costing you most.
Fix these first
The full marking
Every deduction below names the file or setting it came from.
Instructions 3/27 F
Whether the repo tells an agent how to behave before it starts guessing.
Setup 6/14 C
Whether an agent can install the project and get it running without a human.
Verification loop 8/25 D
Whether an agent can check its own work. This is the category that most decides whether agent output is trustworthy.
Context economy 17/20 A
Whether the repo fits in a context window, or fights it.
Here is your AGENTS.md
Drafted from what is actually in this repository: the install
command from your lockfile, the commands you already declare, your real directory layout. Anything
marked TODO needs a person. Save it at the root as AGENTS.md.
# AGENTS.md The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data. ## Setup ``` npm install ``` ## Commands ``` # TODO: nothing declares a build or test command, so an agent has to guess. # This is the single most valuable section of this file. Fill it in. ``` ## Layout - `naughtystrings/` 4 source files - `scripts/` 2 source files ## Conventions - Tests live alongside the code they cover, following `naughtystrings/naughtystrings_test.go`. - TODO: add the two or three conventions a newcomer always gets wrong here. ## Gotchas - No lockfile is committed, so an install here may not match what CI produced. --- Drafted by agentreadme.com from what is in this repository. Everything marked TODO needs a human. Check it in as AGENTS.md at the root.
Open the raw markdown
or
curl -o AGENTS.md agentreadme.com/draft/minimaxir/big-list-of-naughty-strings.md
Show the mark
The badge re-checks daily, so it keeps up as the repository changes. Use mark again to force it now.
[](https://agentreadme.com/minimaxir/big-list-of-naughty-strings)Other Python repositories, marked
Think this mark is wrong?
Every deduction above names the file it came from, so this can be settled by looking. If a check missed something, that is a rule worth fixing.