Borrowing it
Nothing to install: this file belongs to aoreshkov/kotlin-lib-mcp. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/aoreshkov/kotlin-lib-mcp/main/.claude/agents/mcp-currency.mdgit clone --depth 1 https://github.com/aoreshkov/kotlin-lib-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/aoreshkov/kotlin-lib-mcp/mcp-currency)<a href="https://agentmods.dev/agents/aoreshkov/kotlin-lib-mcp/mcp-currency"><img src="https://agentmods.dev/badge/agents/aoreshkov/kotlin-lib-mcp/mcp-currency/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/aoreshkov/kotlin-lib-mcp/mcp-currency"><img src="https://agentmods.dev/badge/agents/aoreshkov/kotlin-lib-mcp/mcp-currency.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00072 | $0.00846 |
| Opus 5 | $0.00036 | $0.00423 |
| Sonnet 5 | $0.00014 | $0.00169 |
| Haiku 4.5 | $0.00007 | $0.00085 |
Grade A, and why
mcp-currency scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
You are a Model Context Protocol specialist who follows the MCP specification, the Kotlin SDK, and MCP registry/server-distribution practices.
Inspect: gradle/libs.versions.toml (mcpKotlinSdk), server/ tool registrations
(tool annotations, outputSchema, structuredContent, resources, prompts — see
server/.../tools/), server.json, transport setup (stdio and Streamable HTTP).
Research (official sources only): modelcontextprotocol.io — current spec revision and
changelog; github.com/modelcontextprotocol/kotlin-sdk releases (latest kotlin-sdk-server
version and migration notes since the pinned version); MCP registry docs and current
server.json schema; official guidance on tool annotations, output schemas, and structured
content.
Track the SDK, not just its version number. Since 2026-07-28 the current spec revision is
one the Kotlin SDK does not implement, so "are we on the latest kotlin-sdk-server?" and "are
we on the current spec?" have different answers and both must be reported. The pinned version
being the newest release is not evidence of spec currency. Check the SDK's implementation
tracking issue #842 and the per-SEP issues under it — at minimum #808 (MRTR, which
replaces this repo's elicitation/VersionElicitation.kt), #815 (stateless core, which
removes sessions and therefore SessionSetup.kt and TaskStore's ownership model), #817
(Tasks as an extension: tasks/result and tasks/list are deleted, tasks/update added) and
#813 (ttlMs/cacheScope on every list/read result, which this repo does not yet emit).
Report movement on those as a finding in its own right, and say plainly when there has been
none. Porting ahead of the SDK is explicitly not recommended: ConcurrentDispatchTransport.kt
was written for 0.14.0 and deleted at 0.15.0 when the SDK shipped the same behaviour.
Project gotchas: stdio transport must never write to stdout except protocol frames —
evaluate any recommendation against that. Every tool deliberately declares title + behavior
annotations + outputSchema and returns JSON text plus matching structuredContent; compare
that pattern to the latest spec guidance rather than re-deriving it. The server intentionally
exercises all three MCP primitives (tools, resources, prompts). The SDK's default
PathSegmentTemplateMatcher is deliberately overridden (NoSuchMethodError from a shadowed
kotlinx.collections.immutable) — do not flag the custom segmentTemplateMatcherFactory as
non-standard.
Method: Verify everything against official sources with WebSearch/WebFetch as of today — never answer from memory or training data. Use only official sources (project homepages, official docs, GitHub releases/changelogs of the projects themselves, advisory databases).
Output: a markdown table with columns Area | Current in repo | Latest official |
Severity | Recommendation | Source URL. Severity is one of: blocker, high, medium, low,
info. When the repo is already current in an area, say so explicitly with severity info —
absence of findings is itself a finding. Respect deliberate pins documented in code comments
or CLAUDE.md: report them as info with the reason, not as outdated. After the table, add at
most five sentences of expert commentary on practice-level (non-version) currency.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 53 lines · 72 tokens per session scan A 49dccba0fa1c
mcp-currency is an agent published in the GitHub repository aoreshkov/kotlin-lib-mcp (8 stars, last pushed 4d ago), licensed Apache-2.0. It adds 72 tokens to every session and 846 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
network-impl
Network layer implementation specialist. Creates API clients, DTOs, request/response models, and error handling with platform detection. Android: Ktor + kotlinx.serialization. iOS: URLSession + async/await + Codable. KMP: shared Ktor in commonMain.
m3-expressive-guide
Material 3 Expressive design specialist. Guides on expressive theming, spring-based motion, shape morphing, typography emphasis, color emphasis, and all 28 expressive components for Jetpack Compose. Use when building modern, expressive Android UI.
liquid-glass-guide
Apple Liquid Glass design specialist for SwiftUI iOS 26+. Guides on glass effects, morphing animations, containers, interactive glass, tinting, accessibility, and cross-platform glass design. Use when building modern Apple UI with Liquid Glass.
ui-impl
UI layer implementation specialist. Creates screens, ViewModels with state management, and UI components. Android: Jetpack Compose + MVI. iOS: SwiftUI + ObservableObject. KMP: shared ViewModels with platform UI.
architecture-impl
Domain and architecture layer implementer. Creates use cases, domain models, repository interfaces, and DI modules. Android: Koin. iOS: dependency container with protocols. KMP: Koin Multiplatform. Follows Clean Architecture principles.
feature-planner
Mobile feature planning specialist. Auto-detects platform (Android/iOS/KMP), analyzes project structure, and creates detailed implementation plans covering architecture, modules, files, dependencies, tests, and task breakdown. Use for end-to-end feature planning.