Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/cacack/mcp-server-vyos/claude-mdgit clone --depth 1 https://github.com/cacack/mcp-server-vyosWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/cacack/mcp-server-vyos/claude-md)<a href="https://agentmods.dev/instructions/cacack/mcp-server-vyos/claude-md"><img src="https://agentmods.dev/badge/instructions/cacack/mcp-server-vyos/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00645 | $0.00645 |
| Opus 5 | $0.00322 | $0.00322 |
| Sonnet 5 | $0.00129 | $0.00129 |
| Haiku 4.5 | $0.00064 | $0.00064 |
Grade A, and why
mcp-server-vyos CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 49 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CLAUDE.md
Project Overview
Python MCP server wrapping the VyOS HTTPS REST API. Exposes VyOS router management (config, operational commands, system management) and VyOS documentation as MCP tools.
Commands
uv venv && source .venv/bin/activate
uv pip install -e ".[dev]"
pytest
ruff check .
python -m vyos_mcp # run server (stdio transport)
Architecture
src/vyos_mcp/server.py— MCP server, tool registration (FastMCP)src/vyos_mcp/client.py— VyOS REST API client (auth, TLS, form-encoded)src/vyos_mcp/docs.py— VyOS docs client (GitHub API, TTL cache)
Key Design Decisions
commit-confirmis the default for config changes (auto-rollback safety)- VyOS API uses form-encoded POST with
data(JSON) andkeyfields, NOT JSON body - Self-signed TLS certs common on VyOS — skip verification by default
- API key via
VYOS_API_KEY, router URL viaVYOS_URLenv vars - Docs fetched live from
vyos/vyos-documentationGitHub repo (branch:current)
VyOS API Quirks (validated against real router)
- All POST endpoints use
application/x-www-form-urlencodedwithdataandkeyfields - Configure operations are slow (10-20s) — client uses 30s timeout
confirmrequires{"op": "confirm", "path": []}— path field is mandatory, even emptycommit-confirmusesconfirm_timeas a field on the command dict, not a separate operationreboot/poweroffrequire"path": ["now"]/retrievesupports three ops:showConfig,returnValues,existsping/tracerouteare NOTshowsubcommands —/showrejects them./tracerouteis a dedicated endpoint taking{"op": "traceroute", "host": ...}and returns an mtr report indata. There is no/pingendpoint (absent from the API's OpenAPI schema)
Testing
- Use
.envfile withVYOS_URLandVYOS_API_KEYfor local testing (gitignored) - Use
commit-confirmwith short timeouts during testing to avoid persisting bad config
Releasing
- Merge PRs with
/cacack:merge, not rawgh pr merge --merge. The repo uses merge commits + release-please;gh pr mergedefaults the merge-commit body to the conventional PR title (feat: …), which release-please parses as a second commit and duplicates every CHANGELOG entry. The merge-commit body must be de-conventionalized prose (PR title with thetype(scope):prefix stripped). See #43.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 49 lines · 645 tokens per session scan A 25b09a2718e1
mcp-server-vyos CLAUDE.md is an instructions file published in the GitHub repository cacack/mcp-server-vyos (5 stars, last pushed 5d ago), licensed MIT. It adds 645 tokens to every session, about $0.0032 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
cml-mcp AGENTS.md
AGENTS.md instructions for xorrkaz/cml-mcp, covering agents.md — cml mcp server, project overview, compatibility goal, repository layout and tool modules (src/cmlmcp/tools/).
brilliant_sdk AGENTS.md
Instructions for brilliantlabsAR/brilliant_sdk, covering brilliant sdk — agent guide, how an app works (the pattern behind everything), minimal reading paths, verify without hardware and testing.
NeoMind CLAUDE.md
Claude Code instructions for camthink-ai/NeoMind, covering neomind — edge ai platform for iot, development commands, ecosystem repositories, extension package contract (.nep) and device type template contract (json).
cad-cae-copilot copilot-instructions.md
Copilot instructions for armpro24-blip/cad-cae-copilot, covering github copilot — aieng workspace and essentials.
phone-mcp CLAUDE.md
Claude Code instructions for premex-ab/phone-mcp, covering claude.md, project overview, build commands, architecture and module layout.
zmk-config AGENTS.md
AGENTS.md instructions for urob/zmk-config, covering customization guide, ground rules, how the multi-board layout works, adding a new board and where to change what.