Borrowing it
Nothing to install: this file belongs to AryanBV/pdf-edit-mcp. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/AryanBV/pdf-edit-mcp/main/CLAUDE.mdgit clone --depth 1 https://github.com/AryanBV/pdf-edit-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/aryanbv/pdf-edit-mcp/claude-md)<a href="https://agentmods.dev/instructions/aryanbv/pdf-edit-mcp/claude-md"><img src="https://agentmods.dev/badge/instructions/aryanbv/pdf-edit-mcp/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.01156 | $0.01156 |
| Opus 5 | $0.00578 | $0.00578 |
| Sonnet 5 | $0.00231 | $0.00231 |
| Haiku 4.5 | $0.00116 | $0.00116 |
Grade A, and why
pdf-edit-mcp CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 95 lines — stays where its author put it; the contents beside it link to each section on GitHub.
pdf-edit-mcp
MCP server for format-preserving PDF text editing, powered by
pdf-edit-engine (Python). As of
v0.2.0 this is a single-process Python (FastMCP) server — the engine is
imported in-process. (The v0.1.x TypeScript server + bridge.py subprocess are
gone; see git history / CHANGELOG.)
Architecture
Claude / AI Agent
↓ MCP protocol (stdio)
pdf_edit_mcp (FastMCP server, this package)
↓ in-process import
pdf-edit-engine (Python library: pikepdf + fonttools + pdfminer)
Module layout (dependency order)
__init__.py __version__
app.py FastMCP `mcp` instance + `engine_lock` ← dependency LEAF
constants.py input bounds (single source of truth)
validation.py path_safety_error + PdfPath/OutputPath/DirPath + BBox/EditItem/BlockReplacement
serialize.py serialize_edit_result + aggregate_fidelity (exact wire shapes)
_runtime.py engine_guard (lock + error translation), READ_ONLY/WRITE annotations, page_count
tools_read.py 9 read tools tools_edit.py 7 edit tools
tools_sections.py 3 section tools tools_document.py 15 document tools
tools_annotations.py 5 annotation tools prompts.py 3 prompts
server.py version gate + main(); imports the tool/prompt modules to register them
Import-cycle rule: mcp and engine_lock live in app.py (a leaf). Tool
modules import them from app, never from server. server imports the tool
modules at the bottom for decorator side-effects. Do not move mcp/engine_lock
back into server — that reintroduces the server → tools_* → _runtime → server
cycle.
Critical rules
- stdout is the MCP transport — never
print()to stdout; diagnostics go tostderr(the engine version gate already does this). - The engine is NOT thread-safe — every engine call goes through
_runtime.engine_guard(), which holds the module-levelengine_lock. New tools must wrap their engine work inwith engine_guard():. - Path validation is a security boundary — path parameters use the
PdfPath/OutputPath/DirPathvalidated types fromvalidation.py(absolute,.pdf, no..traversal, no control chars, no Windows reserved/truncated basenames). Never accept a barestrfor a path. - Error model — engine
PDFEditErrorsubclasses are translated byengine_guardintoToolErrorwith a classified message + recovery hint. RaisePDFEditErrorfor in-tool validation; do not leak raw pikepdf exceptions. - Engine version gate —
server._check_engine_version()exits non-zero if the installedpdf-edit-engine < 0.2.0(relies on thepassword=kwargs,fit=, and the 30-kind degradation taxonomy). - mypy --strict + ruff clean —
mypy src/pdf_edit_mcpandruff check src/ tests/must pass.server.pyhas a per-file E402 ignore (intentional bottom-of-file registration imports).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 95 lines · 1,156 tokens per session scan A defd0c0352b7
pdf-edit-mcp CLAUDE.md is an instructions file published in the GitHub repository AryanBV/pdf-edit-mcp (1 stars, last pushed 1mo ago), licensed MIT. It adds 1,156 tokens to every session, about $0.0058 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.