Borrowing it
Nothing to install: this file belongs to ayhammouda/gsc-seo-mcp. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/ayhammouda/gsc-seo-mcp/main/AGENTS.mdgit clone --depth 1 https://github.com/ayhammouda/gsc-seo-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/ayhammouda/gsc-seo-mcp/agents-md)<a href="https://agentmods.dev/instructions/ayhammouda/gsc-seo-mcp/agents-md"><img src="https://agentmods.dev/badge/instructions/ayhammouda/gsc-seo-mcp/agents-md/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/instructions/ayhammouda/gsc-seo-mcp/agents-md"><img src="https://agentmods.dev/badge/instructions/ayhammouda/gsc-seo-mcp/agents-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00824 | $0.00824 |
| Opus 5 | $0.00412 | $0.00412 |
| Sonnet 5 | $0.00165 | $0.00165 |
| Haiku 4.5 | $0.00082 | $0.00082 |
Grade A, and why
gsc-seo-mcp AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 53 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Repository Instructions
Build And Test
- Install:
npm install - Typecheck:
npm run typecheck - Lint:
npm run lint - Test:
npm test - Build:
npm run build - Package smoke:
npm pack
Conventions
- TypeScript ESM only.
- Source lives in
src/; tests live intests/. - Do not write logs to stdout from stdio server code.
- Tool inputs and outputs must remain Zod-typed and stable.
- Google API calls must use per-request timeout and
AbortSignal. - The versioned capability manifest is the only source of active tool names, schemas, MCP metadata, Google method/scope assumptions, and profile visibility.
- Every MCP registration and compatibility invocation must traverse the capability dispatcher; do not add handler-specific authorization, budget, execution, result, or logging paths.
- Keep semantic authorization rules (property containment, allowlist membership) out of the tool
inputSchema. The MCP SDK validates that schema before invoking the tool callback, so a rule placed there denies the call outside the kernel and emits no terminal audit event. Put such rules inselectResourceor the static policy port. - Core kernel modules must not depend on transport, CLI, OAuth, or concrete Google client modules.
- Use the shared branded resource parsers for Search Console properties, HTTP targets, sitemap targets, and calendar dates. Do not recreate authorization identity with raw string operations or
Date.parse. - Preserve the configured property
apiValuefor Google calls and usepolicyKeyonly for authorization, containment, collision checks, and concurrency keys.
Security Rules
- Default to
https://www.googleapis.com/auth/webmasters.readonly. - Require a non-empty exact property allowlist before MCP server startup.
- Keep the public MCP surface to the four approved manifest-defined direct read tools during containment.
- Accept only
GSC_SEO_MCP_MODE=read_only; reject operator, full-admin, unknown, and legacy write-enable configurations. - Require URL-prefix properties to include their trailing slash; reject normalization collisions in property allowlists.
- Keep property and URL identifiers within 8,192 UTF-8 bytes and allowlists within 1,000 entries.
- Keep Search Analytics requests within 1,000 rows, a 25,000-row pagination window, four filter groups of eight filters, and an inclusive 90-day calendar range.
- Reject unknown public input fields, including unknown nested filter fields.
- Require an explicit registry, deployment profile, context factory, policy, budget, executor, error, and audit port when constructing the dispatcher.
- Registration must obtain its visible capabilities from the same branded dispatcher binding; never pass a separate registry or profile into MCP registration.
- Static policy must permit the request before budget reservation, service-provider access, credential initialization, or Google calls.
- Keep raw input assertion, normalized reservation, lease-scoped gateway accounting, raw output preflight, and post-filter output assertion mandatory in dispatcher order.
- Production local stdio composition must use the deterministic in-memory budget controller, not the compatibility pass-through port.
- Keep stdio payload enforcement before UTF-8 decoding and JSON parsing, with a 262,144-byte payload ceiling.
- Keep Google attempt timeouts at or below 30 seconds and total local read deadlines at or below 45 seconds.
- Keep mutation and compound-derived capabilities in the unsupported ledger; do not expose a mutation method from the containment gateway.
- Never log access tokens, refresh tokens, authorization codes, or client secrets.
- Do not expose an MCP HTTP command until an authenticated HTTP profile and its threat controls are implemented.
- Keep the technical release freeze in place through WP-10 and until it is explicitly lifted.
- Keep
package.jsonprivate and omit registry install descriptors until a collision-free package identity is verified.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 53 lines · 824 tokens per session scan A 5e57095baa98
gsc-seo-mcp AGENTS.md is an instructions file published in the GitHub repository ayhammouda/gsc-seo-mcp (0 stars, last pushed 5d ago), licensed MIT. It adds 824 tokens to every session, about $0.0041 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
data-scientist copilot-instructions.md
Repository instructions for a data-science workflow in GitHub Copilot, covering datasets, statistics, and analysis files.
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.