ck CLAUDE.md

ck CLAUDE.md is an instructions file for coding agents from BeaconBay/ck. It costs 1,059 tokens per session, scanned A, original, Apache-2.0.

Development and release instructions for the ck codebase, including its version tags, pre-commit checks, and changelog process. The codebase is a Rust workspace containing several related packages.

In plain words
What is it for?
Use it when preparing a release, changing the version, tagging a release, updating the changelog, or running the required formatting, linting, and test checks before committing.
Why use it?
It prevents agents from using outdated tag formats or forgetting checks that should pass before a commit. It also explains how to update versions consistently across the packages.

Instructions file

About the project

ck is a local code-search tool that finds source code by meaning as well as by exact text, combining semantic search with grep-style and hybrid searches. It is for developers and AI clients that need to locate relevant code in a repository, with an interactive terminal interface and MCP integration. The catalogue instruction connects coding agents to ck's search capabilities.

BeaconBay/ck · 1,717 stars · on GitHub

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/beaconbay/ck/claude-md
Clone the repo
git clone --depth 1 https://github.com/BeaconBay/ck

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ck CLAUDE.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/beaconbay/ck/claude-md.svg)](https://agentmods.dev/instructions/beaconbay/ck/claude-md)
Your own site
<a href="https://agentmods.dev/instructions/beaconbay/ck/claude-md"><img src="https://agentmods.dev/badge/instructions/beaconbay/ck/claude-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 1,059 This file is loaded in full into every session.
When invoked 1,059 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01059 $0.01059
Opus 5 $0.00530 $0.00530
Sonnet 5 $0.00212 $0.00212
Haiku 4.5 $0.00106 $0.00106

Measured 4d ago against content hash 56fb1278dc42, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

ck CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

CLAUDE.md · 108 lines

How it starts

The opening of the file, as written. The whole thing — 108 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Claude Development Guide

This file contains project-specific instructions for Claude and other AI agents working on the ck codebase. Whenever you actually use ck and it does something unexpected, jot it down in a file could UNEXPECTED.md - supply what you ran, what you expected to happen, what happened instead.

Release Process

Version Tagging Convention

IMPORTANT: Tags follow the format X.Y.Z (NO v prefix) to match current standard:

# Correct format (current standard since 0.3.8+)
git tag 0.4.1
git tag 0.3.9

# Old format (deprecated, do not use)
git tag v0.3.4

Always check existing tags first: git tag --sort=-version:refname

Pre-Commit Quality Checks

ALWAYS run these commands in order before any commit:

  1. Linting: cargo clippy - Fix all warnings
  2. Formatting: cargo fmt - Format all code
  3. Testing: cargo test - Ensure all tests pass

Version Bump Process

All eight crates ship in lockstep. To bump from OLD to NEW:

  1. Workspace Cargo.toml — update two places:
    • [workspace.package] version = "NEW"
    • The seven ck-* = { path = "...", version = "NEW", ... } lines under [workspace.dependencies]
  2. Update CHANGELOG.md with release notes (format below)
  3. Tag as X.Y.Z (no v prefix) — release.yml does the rest

That's it. Individual crate Cargo.toml files inherit the workspace version via version.workspace = true and depend on siblings via { workspace = true }.

You do NOT need to bump package.json. The publish-npm job in release.yml reads Cargo.toml's [workspace.package] version at publish time and stamps package.json to match before npm publish. The committed package.json version is informational — only the tag + Cargo.toml are the gate.

What release.yml does on tag push

When tag X.Y.Z is pushed:

  1. Create GitHub release (draft) and verify tag matches Cargo.toml
  2. Build binaries for 5 targets (linux x86_64, macos x86_64+arm64, windows x86_64+arm64), upload as .tar.gz/.zip assets
  3. Publish 8 crates to crates.io in dep order, with retry-on-"already-published" and verify-via-API (User-Agent required)
  4. Publish to npm as @beaconbay/ck-search — uses npm Trusted Publishing (OIDC); GitHub mints a short-lived id-token, npm validates it against the trusted-publisher config on the package, no long-lived secret. Tarball is published with SLSA provenance attestation (cryptographically tied to this workflow run + commit). The package's postinstall script downloads the platform binary from the GitHub release at user install time.
  5. Finalize GitHub release (out of draft)

Read the full file on GitHub · 108 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 108 lines · 1,059 tokens per session scan A 56fb1278dc42

Subscribe to this mod's changes

ck CLAUDE.md is an instructions file published in the GitHub repository BeaconBay/ck (1,717 stars, last pushed yesterday), licensed Apache-2.0. It adds 1,059 tokens to every session, about $0.0053 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.