chrome-bookmarks-mcp: Instructions file for Claude Code

CLAUDE.md

chrome-bookmarks-mcp CLAUDE.md is an instructions file for Claude Code from caelum29/chrome-bookmarks-mcp. It costs 881 tokens per session, scanned A, original, MIT.

Repository instructions for a TypeScript Chrome bookmarks project that uses a pnpm workspace monorepo, meaning several related packages managed in one repository. They describe the package layout, rules, documentation, and commands.

In plain words
What is it for?
Use them when modifying the MCP server, Chrome extension, documentation, write tools, or development workflow for this project.
Why use it?
They help agents make safe changes while preserving project rules such as routing writes through the browser extension and keeping the MCP data stream separate from logs.

Instructions file for Claude Code

Written for Claude Code: the file is CLAUDE.md. Also seen: mentions CLAUDE.md; mentions subagents.

This is caelum29/chrome-bookmarks-mcp's own configuration. It tells Claude Code how to work on chrome-bookmarks-mcp itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything chrome-bookmarks-mcp configures →

Reuse

Borrowing it

Nothing to install: this file belongs to caelum29/chrome-bookmarks-mcp. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/caelum29/chrome-bookmarks-mcp/main/CLAUDE.md
Clone the repo
git clone --depth 1 https://github.com/caelum29/chrome-bookmarks-mcp

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for chrome-bookmarks-mcp CLAUDE.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/caelum29/chrome-bookmarks-mcp/claude-md/github.svg)](https://agentmods.dev/instructions/caelum29/chrome-bookmarks-mcp/claude-md)
Your own site
<a href="https://agentmods.dev/instructions/caelum29/chrome-bookmarks-mcp/claude-md"><img src="https://agentmods.dev/badge/instructions/caelum29/chrome-bookmarks-mcp/claude-md/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for chrome-bookmarks-mcp CLAUDE.md

Your own site · 80×15
<a href="https://agentmods.dev/instructions/caelum29/chrome-bookmarks-mcp/claude-md"><img src="https://agentmods.dev/badge/instructions/caelum29/chrome-bookmarks-mcp/claude-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 881 This file is loaded in full into every session.
When invoked 881 The same file — it is already loaded in full.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00881 $0.00881
Opus 5 $0.00441 $0.00441
Sonnet 5 $0.00176 $0.00176
Haiku 4.5 $0.00088 $0.00088

Measured 9d ago against content hash 3616fc325a7c, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade A, and why

chrome-bookmarks-mcp CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

CLAUDE.md · 49 lines

How it starts

The opening of the file, as written. The whole thing — 49 lines — stays where its author put it; the contents beside it link to each section on GitHub.

CLAUDE.md — chrome-bookmarks-mcp

pnpm workspace monorepo, TypeScript strict, Node ≥22.5. Public repo — no personal data, no real bookmark dumps in fixtures. English everywhere in the repo; conversation with Artem in Ukrainian.

  • packages/mcp-server — MCP server (stdio). SDK-free tool seam: only src/server.ts and src/run-stdio.ts import @modelcontextprotocol/*.
  • packages/extension — MV3 service worker, esbuild → dist/ (load unpacked). The only write path.

Where things are (read on demand, don't preload)

CONTEXT.md = vocabulary, facts · docs/adr/ = decisions, immutable · docs/milestones/ = the one active plan · docs/open-questions.md = unresolved · docs/blessed-paths/ = recipes for recurring task types (add tool, add bridge message, release) · docs/sessions/ = journal. Never cite a plan or open question as a fact.

Invariants (each one paid for — see the ADR)

  • Never write the Bookmarks file. Writes go through the extension via chrome.bookmarks (ADR-0002).
  • stdout is the MCP stream — log only to stderr via src/logging.ts.
  • Write tools: env-gated (BOOKMARKS_ENABLE_WRITE), dryRun default true, auto-snapshot, bounded sets; a dry run is a success result, not isError (ADR-0002).
  • Handlers return toolError(...), never throw for expected conditions; zod-coerce at the boundary; structured output on every tool; ≤ ~12 coarse tools (ADR-0003).
  • guid is the stable key; id is local. Timestamps are WebKit epoch at the boundary, Unix ms inside.
  • History DB is locked while Chrome runs — copy to temp, open read-only.

How

  • Verification: pnpm verify (typecheck + lint + test). The only accepted proof of "done".
  • Non-trivial task → plan + unresolved-questions list first; code after the plan is approved.
  • Add a tool / bridge message only via its blessed path.
  • Validate at system boundaries only (tool input, bridge messages, file/DB reads); trust internal code.
  • No features, refactors or abstractions beyond the task. When you have enough information to act, act.
  • Never delete, skip, weaken or rewrite a failing test to make the suite pass — it is information; if a test looks wrong, stop and say so.
  • Stop and ask only when: (a) the action is destructive/irreversible, (b) real scope change, (c) a domain decision only Artem can make. Otherwise continue. Unattended runs never end on a question.
  • Before any progress report, check each claim against a tool result of this session; the proof is the pnpm verify exit code. Failing → show output; skipped → say so; done → state it plainly.
  • Acceptance is by the fresh-context verifier subagent against the issue's VALIDATION — never self-accept.
  • Commits: type(scope): what (why); small, after every green step; end a session with a wip(...) → next commit if unfinished. Never push to main, never force-push, never amend pushed commits.

Read the full file on GitHub · 49 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 49 lines · 881 tokens per session scan A 3616fc325a7c

Subscribe to this mod's changes

chrome-bookmarks-mcp CLAUDE.md is an instructions file published in the GitHub repository caelum29/chrome-bookmarks-mcp (1 stars, last pushed 23d ago), licensed MIT. It adds 881 tokens to every session, about $0.0044 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,153 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

deepseek-harness AGENTS.md

AGENTS.md instructions for deepseek-ai/deepseek-harness, covering agents.md, pre-stable apis and released session data, repository layout, commands and host sandbox failures.

deepseek-ai/deepseek-harness · 3,735 tokens