fullstack-langgraph-nextjs-agent CLAUDE.md

Repository guidance for a Next.js AI chat application that uses LangGraph.js, MCP tool servers, Postgres for data, and MinIO for file storage.

In plain words
What is it for?
Use it when installing dependencies, starting local services, running the app, checking code, applying database migrations, or inspecting stored data.
Why use it?
It records the setup, development, database, and file-storage commands in one place, reducing guesswork when running or changing the project.

Instructions file

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/agentailor/fullstack-langgraph-nextjs-agent/claude-md
Clone the repo
git clone --depth 1 https://github.com/agentailor/fullstack-langgraph-nextjs-agent
Per session 1,842 This file is loaded in full into every session.
When invoked 1,842 The same file — it is already loaded in full.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01842 $0.01842
Opus 5 $0.00921 $0.00921
Sonnet 5 $0.00368 $0.00368
Haiku 4.5 $0.00184 $0.00184

Measured 2d ago against content hash 6971c4d88458, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

fullstack-langgraph-nextjs-agent CLAUDE.md scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

- Validate the spec: `curl /api/openapi -o openapi.json && npx @redocly/cli lint openapi.json` (config in `redocly.yaml` — disables `security-defined` since the template has no API auth)
CLAUDE.md · 165 lines

How it starts

The opening of the file, as written. The whole thing — 165 lines — stays where its author put it; the contents beside it link to each section on GitHub.

CLAUDE.md

This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.

Essential Development Commands

# Setup (requires Postgres and MinIO running)
docker compose up -d          # Start Postgres (5434) and MinIO (9000/9001)
pnpm install
pnpm prisma:generate
pnpm prisma:migrate

# Development
pnpm dev                      # Next.js with Turbopack
pnpm build                    # Production build
pnpm lint                     # ESLint
pnpm format                   # Prettier formatting
pnpm format:check             # Check formatting

# Database
pnpm prisma:generate          # After schema changes
pnpm prisma:migrate           # Create/apply migrations
pnpm prisma:studio            # Database UI

# File Storage
# MinIO Console: http://localhost:9001 (minioadmin/minioadmin)
# S3 API: http://localhost:9000

Architecture Overview

This is a Next.js 15 fullstack AI agent chat application using LangGraph.js with Model Context Protocol (MCP) server integration.

Core Agent System

  • Agent Builder: src/lib/agent/builder.ts - Creates StateGraph with agent→tool_approval→tools flow
  • MCP Integration: src/lib/agent/mcp.ts - Dynamically loads tools from MCP servers stored in Postgres
  • Persistent Memory: Uses LangGraph's Postgres checkpointer for conversation history
  • Tool Approval: Human-in-the-loop pattern with interrupts for tool execution approval

Data Flow

  1. User message → /api/agent/stream SSE endpoint → streamResponse() in agentService.ts
  2. Agent processes with tools from enabled MCP servers → streams incremental responses
  3. Frontend uses useChatThread() hook with React Query for optimistic UI and streaming
  4. Thread persistence via Prisma → Postgres (threads + MCP server configs)
  5. File uploads → /api/agent/upload → MinIO (S3-compatible storage) → returns file URLs

Key Components Structure

  • Context Providers: ThreadContext (active thread), UISettingsContext (UI state + model settings persisted to localStorage under agent_model_settings)
  • Custom Hooks: useChatThread, useMCPTools, useThreads for data domains
  • Message Components: Separate components for AI/Human/Tool/Error message types
  • Agent Services: src/services/agentService.ts handles streaming, src/services/chatService.ts manages UI state

Read the full file on GitHub · 165 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 165 lines · 1,842 tokens per session scan A 6971c4d88458

Subscribe to this mod's changes

fullstack-langgraph-nextjs-agent CLAUDE.md is an instructions file published in the GitHub repository agentailor/fullstack-langgraph-nextjs-agent (131 stars, last pushed 2mo ago), licensed MIT. It adds 1,842 tokens to every session, about $0.0092 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.