Borrowing it
Nothing to install: this file belongs to CxMYu/CcGlanceLine. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/CxMYu/CcGlanceLine/main/CLAUDE.mdgit clone --depth 1 https://github.com/CxMYu/CcGlanceLineWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/cxmyu/ccglanceline/claude-md)<a href="https://agentmods.dev/instructions/cxmyu/ccglanceline/claude-md"><img src="https://agentmods.dev/badge/instructions/cxmyu/ccglanceline/claude-md/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/instructions/cxmyu/ccglanceline/claude-md"><img src="https://agentmods.dev/badge/instructions/cxmyu/ccglanceline/claude-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.01057 | $0.01057 |
| Opus 5 | $0.00528 | $0.00528 |
| Sonnet 5 | $0.00211 | $0.00211 |
| Haiku 4.5 | $0.00106 | $0.00106 |
Grade B, and why
CcGlanceLine CLAUDE.md scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
committed. `~/.claude/settings.json` and tokens live outside the repo — never How it starts
The opening of the file, as written. The whole thing — 92 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CLAUDE.md
Guidance for working in this repo. See docs/development.md (and its zh-CN
counterpart) for deeper build/test/cache internals.
What this is
@cxmyu/ccglance — a Claude Code status-line renderer. Claude Code pipes JSON on
stdin per redraw; dist/cli.js renders one line to stdout. Zero runtime
dependencies; the CLI is spawned fresh on every redraw, so cold-start latency
matters.
Core rules
src/is the only source of truth. Never hand-editdist/— it is gitignored and rebuilt bynpm run build(and bynpm civiaprepare).- Keep the style fixed and built-in: no user config loader, no external style file, no runtime style discovery.
- Keep runtime dependencies at zero. New deps must be build-time only.
- Verify local changes with
npm run preview/node dist/cli.js, never a bareccglance(that is the published global install on PATH).
Build / test
npm run typecheck # tsc --noEmit (strict)
npm run build # clean + compile src/ -> dist/
npm test # build + node:test (fixtures / snapshots / smoke)
npm run preview # render this repo's dist/
Tests and benchmarks isolate CLAUDE_CONFIG_DIR to a temp dir; they never touch
the real ~/.claude/ccglance/ cache.
Background refresh (Windows footgun)
Git/version refreshes queue during render and flush after stdout as a single
detached helper (dist/runtime/bg.js). On Windows the helper MUST be spawned as
spawn(node, [...], { detached: true, windowsHide: true }) — spawning Node
directly, never through a cmd/start trampoline. detached maps to
DETACHED_PROCESS (no console allocated → no black window flash); a cmd start
trampoline flashes a window on every cold refresh (the 1.1.0 regression fixed in
1.1.1). Dropping detached makes the helper die when the parent exits, so the
cache never gets written. See src/runtime/refresh.ts.
Release process (publish a new version)
Publishing is done through a GitHub Release, which triggers
.github/workflows/publish.yml (release: published). CI runs npm ci →
npm run typecheck → npm test → npm publish --provenance --access public
(OIDC provenance; NPM_TOKEN secret must bypass 2FA). Do not npm publish
locally.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 92 lines · 1,057 tokens per session scan B 33f7bb88fd3a
CcGlanceLine CLAUDE.md is an instructions file published in the GitHub repository CxMYu/CcGlanceLine (5 stars, last pushed 7d ago), licensed MIT. It adds 1,057 tokens to every session, about $0.0053 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
deepseek-harness AGENTS.md
AGENTS.md instructions for deepseek-ai/deepseek-harness, covering agents.md, pre-stable apis and released session data, repository layout, commands and host sandbox failures.