Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/adobe-rnd/da-mcp/claude-mdgit clone --depth 1 https://github.com/adobe-rnd/da-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/adobe-rnd/da-mcp/claude-md)<a href="https://agentmods.dev/instructions/adobe-rnd/da-mcp/claude-md"><img src="https://agentmods.dev/badge/instructions/adobe-rnd/da-mcp/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01245 | $0.01245 |
| Opus 5 | $0.00622 | $0.00622 |
| Sonnet 5 | $0.00249 | $0.00249 |
| Haiku 4.5 | $0.00125 | $0.00125 |
Grade A, and why
da-mcp CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 92 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CLAUDE.md
This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.
Project Overview
DA MCP is a remote Model Context Protocol (MCP) server for Document Authoring (DA). It provides LLM assistants with direct access to DA management operations via Cloudflare Workers with streamable HTTP transport.
Architecture flow: MCP Client → Cloudflare Worker (17 tools) → DA Admin API (admin.da.live) or AEM (HLX6) Admin API (api.aem.live); legacy preview/publish calls go to the Helix admin API (admin.hlx.page) instead
Development Commands
npm run dev # Local development with hot reload (http://localhost:8787)
npm run lint # ESLint check
npm run test # Run Vitest tests
npm run test:watch # Run tests in watch mode
npm run type-check # TypeScript type checking without emit
npm run deploy # Deploy to production Cloudflare Workers
npm run deploy:ci # Deploy to CI environment with versioned config
npm run deploy:production # Deploy to production with versioned config
Local endpoints:
- Health:
http://localhost:8787/health - MCP:
http://localhost:8787/mcp
Test with MCP Inspector: Connect to http://localhost:8787/mcp with Authorization: Bearer YOUR_DA_TOKEN header.
Code Structure
src/
├── index.ts # Cloudflare Worker entry point, token extraction, health check
├── mcp/
│ ├── server.ts # McpServer factory with registerTool() + Zod schemas (one per tool)
│ └── handlers.ts # Tool implementation handlers (one per tool)
├── da-admin/
│ ├── client.ts # DA Admin API HTTP client with token pass-through
│ └── types.ts # TypeScript interfaces for API responses
└── utils/
└── path.ts # Path normalization utilities
Key Patterns
- Token pass-through: Authorization header extracted in
index.ts, passed toDAAdminClient, forwarded to DA Admin API - SDK transport:
WebStandardStreamableHTTPServerTransport(stateless, per-request) handles MCP protocol — freshMcpServer+ transport created per request - Tool registration: Each tool registered via
server.registerTool()with a ZodinputSchemainserver.ts; business logic lives inhandlers.ts - FormData for content: Create/update/copy/move operations use
FormDatawithBlobfor file content - Copy/move API: Endpoint is
/copy|move/{org}/{repo}/{sourcePath}; body is FormData withdestination=/{org}/{repo}/{destinationPath} - Empty responses:
client.tsreads body as text first; returns{}for empty/no-content responses (204 etc.) - 30-second timeout: All API requests have AbortController timeout
- Path normalization: All handlers normalize paths via
src/utils/path.tsbefore passing to client;.htmlextension auto-added where needed for source file operations, but stripped for preview/publish (see below) since those are page/URL paths, not source file paths - Preview/live on legacy DA:
admin.da.livehas no preview/live routes of its own —DAAdminClient.previewContent/unpreviewContent/publishContent/unpublishContentcall the Helix admin API (admin.hlx.page) directly via globalfetch()instead of thedaadminServicebinding, always targeting themainref. PreviewPOSTcalls additionally sendx-content-source-authorizationalongsideAuthorization. - Preview/live paths have no file extension: on both legacy and HLX6,
da_preview_content/da_unpreview_content/da_publish_content/da_unpublish_contentstrip any extension from the given path viastripFileExtension()(src/utils/path.ts) before calling the client — AEM Edge Delivery preview/live URLs are always extensionless page routes.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed · +6 lines · +299 tokens per session 42bf1e7e7f1b
- 5d ago First seen · 86 lines · 946 tokens per session scan A fa9633408aac
da-mcp CLAUDE.md is an instructions file published in the GitHub repository adobe-rnd/da-mcp (4 stars, last pushed 2d ago), licensed Apache-2.0. It adds 1,245 tokens to every session, about $0.0062 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).