saft-mcp CLAUDE.md

saft-mcp CLAUDE.md is an instructions file for coding agents from Bloomidea/saft-mcp. It costs 1,325 tokens per session, scanned A, original, MIT.

An MCP server for reading and analysing Portuguese SAF-T XML files. SAF-T is a standard electronic audit file that businesses provide to tax authorities, containing structured accounting and transaction data.

In plain words
What is it for?
Use it when parsing or analysing SAF-T files, implementing or changing the server’s 13 tools, validating accounting data, or running its test suite against real Portuguese exports.
Why use it?
It provides project-specific guidance for handling real exports, including the file format, encoding, data models, and authoritative technical requirements.

Instructions file

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/bloomidea/saft-mcp/claude-md
Clone the repo
git clone --depth 1 https://github.com/Bloomidea/saft-mcp

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for saft-mcp CLAUDE.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/bloomidea/saft-mcp/claude-md.svg)](https://agentmods.dev/instructions/bloomidea/saft-mcp/claude-md)
Your own site
<a href="https://agentmods.dev/instructions/bloomidea/saft-mcp/claude-md"><img src="https://agentmods.dev/badge/instructions/bloomidea/saft-mcp/claude-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 1,325 This file is loaded in full into every session.
When invoked 1,325 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01325 $0.01325
Opus 5 $0.00662 $0.00662
Sonnet 5 $0.00265 $0.00265
Haiku 4.5 $0.00133 $0.00133

Measured 4d ago against content hash 22157dd24818, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

saft-mcp CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

CLAUDE.md · 105 lines

How it starts

The opening of the file, as written. The whole thing — 105 lines — stays where its author put it; the contents beside it link to each section on GitHub.

SAF-T MCP Server

MCP server for parsing and analyzing Portuguese SAF-T (Standard Audit File for Tax Purposes) XML files. Fully implemented with 13 tools and 152 tests.

Documents

  • saft-mcp-prd-en.md -- Product requirements, tool specifications, business context
  • saft-mcp-technical-spec.md (v1.2) -- Authoritative implementation reference. Data models, architecture decisions, all design questions resolved. Models validated against real PHC exports.

When in doubt, the tech spec wins. It was updated after analyzing real SAF-T files and supersedes the PRD on any structural detail.

Real SAF-T Files

Located in Saft Josefinas 2025/. These are real exports from PHC Corporate for Bloomers S.A. (NIF 510803601).

  • 5108036012025_Completo.xml -- Full year, all sections (1.1 MB)
  • 5108036012025202502031408.xml -- Monthly export, January only (110 KB)
  • 11 other monthly files (Feb-Dec)

Encoding: Windows-1252 (declared in XML header). Not UTF-8. lxml handles this natively via the XML declaration.

Tech Stack

  • Python 3.11+, FastMCP (MCP SDK), lxml, Pydantic v2, pydantic-settings, chardet
  • Dev: pytest, pytest-asyncio, ruff, mypy

Project Structure

src/saft_mcp/
  server.py          # FastMCP entry point, registers all 13 tools
  config.py          # SaftMcpSettings (pydantic-settings)
  state.py           # SessionStore, SessionState
  exceptions.py      # SaftError hierarchy
  parser/
    detector.py      # Namespace detection, file type
    full_parser.py   # DOM parse (< 50 MB)
    encoding.py      # BOM stripping, charset detection
    models.py        # All Pydantic models
  tools/
    load.py          # saft_load
    validate.py      # saft_validate
    summary.py       # saft_summary
    query_invoices.py # saft_query_invoices
    query_customers.py # saft_query_customers
    query_products.py # saft_query_products
    get_invoice.py   # saft_get_invoice
    tax_summary.py   # saft_tax_summary
    anomaly_detect.py # saft_anomaly_detect
    compare.py       # saft_compare
    aging.py         # saft_aging
    export.py        # saft_export
    stats.py         # saft_stats
  validators/        # xsd_validator.py, business_rules.py, hash_chain.py, nif.py
  schemas/           # XSD files (saftpt1.04_01.xsd)
tests/               # Mirrors src/ structure (152 tests)

Read the full file on GitHub · 105 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 105 lines · 1,325 tokens per session scan A 22157dd24818

Subscribe to this mod's changes

saft-mcp CLAUDE.md is an instructions file published in the GitHub repository Bloomidea/saft-mcp (1 stars, last pushed 6mo ago), licensed MIT. It adds 1,325 tokens to every session, about $0.0066 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories