mcp-clickhouse AGENTS.md

mcp-clickhouse AGENTS.md is an instructions file for Codex, OpenCode from ClickHouse/mcp-clickhouse. It costs 1,969 tokens per session, scanned A, original, Apache-2.0.

A set of instructions for coding agents working on a ClickHouse database connection. ClickHouse is a database commonly used for fast analysis of large datasets.

In plain words
What is it for?
Use it when modifying or reviewing the ClickHouse MCP server, its environment settings, query handling, authentication, health checks, pagination, or response formats.
Why use it?
It gives agents a project map and working rules so changes respect the repository’s documentation, security behavior, configuration, and tool contracts.

Instructions file for CodexOpenCode

About the project

ClickHouse MCP Server connects AI assistants to ClickHouse, a database system for querying and analyzing data. It exposes tools for running read-only SQL queries and inspecting databases and tables, and the catalogue entries help agents connect to and use that server.

ClickHouse/mcp-clickhouse · 866 stars · on GitHub

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/clickhouse/mcp-clickhouse/agents-md
Clone the repo
git clone --depth 1 https://github.com/ClickHouse/mcp-clickhouse

Made for: Codex, OpenCode.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for mcp-clickhouse AGENTS.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/clickhouse/mcp-clickhouse/agents-md.svg)](https://agentmods.dev/instructions/clickhouse/mcp-clickhouse/agents-md)
Your own site
<a href="https://agentmods.dev/instructions/clickhouse/mcp-clickhouse/agents-md"><img src="https://agentmods.dev/badge/instructions/clickhouse/mcp-clickhouse/agents-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 1,969 This file is loaded in full into every session.
When invoked 1,969 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.01969 $0.01969
Opus 5 $0.00984 $0.00984
Sonnet 5 $0.00394 $0.00394
Haiku 4.5 $0.00197 $0.00197

Measured today against content hash 45d4f955d37b, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

mcp-clickhouse AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 148 lines

How it starts

The opening of the file, as written. The whole thing — 148 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Agent Instructions

AGENTS.md is the canonical instruction file for AI agents working in this repository. If another agent-facing file disagrees with this one, this file wins.

Before making substantial changes, read README.md, pyproject.toml, and the relevant source and tests. The README is part of the user-facing contract because it documents tools, response shapes, security behavior, and every supported environment variable.

Role

Act like an experienced maintainer of a public Python MCP server and database integration.

  • Think about the MCP client experience, ClickHouse behavior, operational safety, and maintainability together.
  • Be opinionated and practical. Do not over-engineer.
  • Do not engage in sycophancy.
  • If an assumption could materially affect security, compatibility, or the public tool contract, verify it or call it out explicitly.

Project Map

  • mcp_clickhouse/mcp_server.py: FastMCP server construction, tool and prompt registration, ClickHouse and chDB execution, pagination, authentication, health checks, and response serialization.
  • mcp_clickhouse/mcp_env.py: environment-backed configuration and validation. Treat this as the source of truth for configuration semantics.
  • mcp_clickhouse/main.py: runtime entry point and transport startup.
  • mcp_clickhouse/mcp_middleware_hook.py: optional user-provided middleware loading.
  • mcp_clickhouse/chdb_prompt.py: the public chDB prompt content.
  • mcp_clickhouse/skills_advisor.py: server-level instructions advertised to MCP clients.
  • tests/: unit, integration, FastMCP client, pagination, auth, middleware, and optional-dependency coverage.
  • test-services/docker-compose.yaml: local ClickHouse service for integration tests.
  • .github/workflows/ci.yaml: authoritative CI commands and CI ClickHouse version.

Working Rules

  • Understand the full local context before changing code. Inspect the implementation, its callers, adjacent tests, and documented behavior.
  • Keep changes small, safe, and directly tied to the task.
  • Preserve backward compatibility by default. Tool names, tool arguments, JSON response shapes, prompt names, environment variables, defaults, and error behavior are public interfaces.
  • Do not add dependencies without a strong reason. Keep chDB optional.
  • Follow the surrounding style and write idiomatic Python compatible with Python 3.10 and later.
  • Use double quotes for new Python strings unless the surrounding syntax makes another choice clearer.
  • Place imports at the top of the file. The deliberate lazy chdb.session import is an exception and must remain lazy unless the optional-dependency design changes.
  • Prefer rg for repository search.
  • Use uv for dependency and command execution. Do not hand-edit uv.lock.
  • Do not modify unrelated user changes in a dirty worktree.

Read the full file on GitHub · 148 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. today Changed 45d4f955d37b
  2. 6d ago First seen · 148 lines · 1,969 tokens per session scan A 02016dbb2aa6

Subscribe to this mod's changes

mcp-clickhouse AGENTS.md is an instructions file published in the GitHub repository ClickHouse/mcp-clickhouse (866 stars, last pushed yesterday), licensed Apache-2.0. It adds 1,969 tokens to every session, about $0.0098 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.