Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/balakumardev/perplexity-web-wrapper/claude-mdgit clone --depth 1 https://github.com/balakumardev/perplexity-web-wrapperWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/balakumardev/perplexity-web-wrapper/claude-md)<a href="https://agentmods.dev/instructions/balakumardev/perplexity-web-wrapper/claude-md"><img src="https://agentmods.dev/badge/instructions/balakumardev/perplexity-web-wrapper/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00935 | $0.00935 |
| Opus 5 | $0.00467 | $0.00467 |
| Sonnet 5 | $0.00187 | $0.00187 |
| Haiku 4.5 | $0.00093 | $0.00093 |
Grade C, and why
perplexity-web-wrapper CLAUDE.md scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Recursive force deletehighDestructive command
rm -rf with a variable or a broad path is one typo away from removing the wrong tree.
rm -rf dist && uv build Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
**Core** (published): `curl-cffi`, `mcp` How it starts
The opening of the file, as written. The whole thing — 81 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Perplexity Subscription MCP
Project Overview
PyPI package: perplexity-subscription-mcp (https://pypi.org/project/perplexity-subscription-mcp/)
Import name: perplexity_subscription_mcp
Console script: perplexity-mcp
Unofficial MCP server + Python client wrapping Perplexity AI's web interface using browser session cookies. No API key needed — uses the user's existing Perplexity subscription.
Project Structure
perplexity_subscription_mcp/ # Published package (PyPI)
├── __init__.py # Exports: Client, normalize_cookies, __version__
├── __main__.py # python -m support
├── client.py # Core Client class (curl_cffi, browser impersonation)
└── server.py # FastMCP server (search, follow_up, list_threads, get_thread)
api/ # REST API (NOT published, local dev only)
├── main.py # FastAPI app — imports from perplexity_subscription_mcp
└── utils.py # Response extraction + logging helpers
Key Architecture
- client.py:
Clientclass usescurl_cffiwith Chrome TLS fingerprint impersonation to call Perplexity's internal SSE API (/rest/sse/perplexity_ask). Authenticates via browser cookies. - server.py:
FastMCPserver exposes 4 tools over stdio transport. Lazy-loads the Client. Has its ownextract_response()to parse Perplexity's block-based response format. - Cookie resolution (in
get_client()):PERPLEXITY_COOKIES_PATHenv →PERPLEXITY_COOKIESenv (inline JSON) →~/.config/perplexity/cookies.json→./perplexity_cookies.json - Two cookie formats accepted: flat dict
{"name": "value"}or Cookie-Editor array[{"name": "...", "value": "..."}]
Build & Publish
- Build system: hatchling
- Package manager: uv
- Python:
>=3.10
CI/CD (automatic)
Every push to main/master triggers .github/workflows/publish.yml:
- Auto-bumps patch version (0.1.1 → 0.1.2)
- Updates version in
pyproject.tomland__init__.py - Commits
v0.1.2 [skip ci]and creates git tag - Builds and publishes to PyPI
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 81 lines · 935 tokens per session scan C a51081a346c3
perplexity-web-wrapper CLAUDE.md is an instructions file published in the GitHub repository balakumardev/perplexity-web-wrapper (20 stars, last pushed 5mo ago), licensed MIT. It adds 935 tokens to every session, about $0.0047 per session on Opus 5. A static security scan graded it C with 2 findings (recursive force delete, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
Browser4 CLAUDE.md
Claude Code instructions for platonai/Browser4, covering browser4 — project context for claude, architecture, key dispatch chain (cli → browser), batch commands and e2e test structure.
cc-websearch CLAUDE.md
Claude Code instructions for Djarvur/cc-websearch, covering project, constraints, technology stack, what not to add and conventions.
fix-quera AGENTS.md
Instructions for AlirezaKeshavarz83/fix-quera, covering agent guidance, project shape, visual style, quera page data findings and compatibility findings.
sniff AGENTS.md
AGENTS.md instructions for Aboudjem/sniff, covering agents.md: sniff, what this repo is, how an agent should use sniff, handling the playwright setup gate and finding output schema.
fast-browser CLAUDE.md
Claude Code instructions for m4ttstack/fast-browser, covering fast browser plugin, where a change belongs, fork branch: use fast-browser-runtime, releasing a new runtime and re-pinning this repo: use the script.
sendblue-browser-use AGENTS.md
Instructions for sendblue-api/sendblue-browser-use, covering agents.md — sendblue-browser-use, what this repo is, setup, common commands and health (no auth).