forkable-mcp CLAUDE.md

forkable-mcp CLAUDE.md is an instructions file for coding agents from colinds/forkable-mcp. It costs 3,215 tokens per session, scanned A, original, MIT.

A development guide for forkable-mcp, a Bun and TypeScript server that lets an MCP client interact with Forkable. It documents the server layout, login and session handling, network behavior, and confirmation rules for changes.

In plain words
What is it for?
Use it when modifying the forkable-mcp server, its tools, authentication, session storage, network transport, order handling, or tests.
Why use it?
It tells coding agents which runtime contracts and safety checks they must preserve, including how pending confirmations and login data work.

Instructions file

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/colinds/forkable-mcp/claude-md
Clone the repo
git clone --depth 1 https://github.com/colinds/forkable-mcp

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for forkable-mcp CLAUDE.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/colinds/forkable-mcp/claude-md.svg)](https://agentmods.dev/instructions/colinds/forkable-mcp/claude-md)
Your own site
<a href="https://agentmods.dev/instructions/colinds/forkable-mcp/claude-md"><img src="https://agentmods.dev/badge/instructions/colinds/forkable-mcp/claude-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 3,215 This file is loaded in full into every session.
When invoked 3,215 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.03215 $0.03215
Opus 5 $0.01607 $0.01607
Sonnet 5 $0.00643 $0.00643
Haiku 4.5 $0.00321 $0.00321

Measured 3d ago against content hash 393908c3cc5f, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

forkable-mcp CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

CLAUDE.md · 275 lines

How it starts

The opening of the file, as written. The whole thing — 275 lines — stays where its author put it; the contents beside it link to each section on GitHub.

CLAUDE.md

Development guidance for forkable-mcp. User setup belongs in README.md; this file records implementation contracts that coding agents must preserve.

Runtime and layout

This is a Bun + TypeScript MCP server. The MCP client spawns it over stdio and owns its lifecycle. There is no HTTP server.

src/
  index.ts        CLI entry point
  server.ts       stdio lifecycle and keepalive
  tools.ts        MCP tools and Forkable request construction
  write-gate.ts   preview, confirmation, and mutation recovery
  net/            GraphQL transport and error mapping
  auth/           login, browser-cookie ingest, and session storage
  order/          domain types, selections, local guards, formatting, and status
tests/            Bun tests
scripts/smoke.ts  packed-install smoke test

The only durable runtime state is ~/.forkable-mcp/session.json (or FORKABLE_MCP_HOME/session.json). Pending confirmations are process-local and disappear on restart.

Keep one current MCP contract. Do not add legacy argument aliases, confirmation formats, session migrations, or response shims without a demonstrated need; agents can re-read tool schemas and adapt.

Authentication and session state

Forkable uses a Cookie header and CSRF token, not an API key. Sessions can come from email/password, an imported browser cookie, FORKABLE_COOKIE, or an auth file/stdin. Browser import uses @steipete/sweet-cookie on macOS, Linux, and Windows; Arc targeting is macOS-only, and Brave or Chromium on Linux or Windows may require an explicit profile path. Password input must remain hidden (--password-stdin or environment); never print credentials.

Session invariants:

  • The store directory is mode 0700; the session file is atomically written with mode 0600.
  • A usable session must contain a nonempty _easyorder_session cookie.
  • Set-Cookie response deltas are merged into the latest stored Cookie header. Do not persist a client's full stale jar over newer rotations.
  • In-process session writes are serialized. Cookie expiry and Max-Age are handled by auth/cookies.ts.
  • CSRF and cookie persistence failure is nonfatal after the in-memory client has accepted the response; emit a concise stderr warning and do not replay a mutation.
  • delegationSessionId: null is meaningful and must clear delegation rather than preserve an older value.
  • Redacted logging may include lengths and metadata, never cookie, CSRF, password, or confirmation token contents.

Read the full file on GitHub · 275 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 275 lines · 3,215 tokens per session scan A 393908c3cc5f

Subscribe to this mod's changes

forkable-mcp CLAUDE.md is an instructions file published in the GitHub repository colinds/forkable-mcp (2 stars, last pushed 9d ago), licensed MIT. It adds 3,215 tokens to every session, about $0.0161 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.