Borrowing it
Nothing to install: this file belongs to cyanheads/mcp-ts-core. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/cyanheads/mcp-ts-core/main/AGENTS.mdgit clone --depth 1 https://github.com/cyanheads/mcp-ts-coreWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/cyanheads/mcp-ts-core/agents-md)<a href="https://agentmods.dev/instructions/cyanheads/mcp-ts-core/agents-md"><img src="https://agentmods.dev/badge/instructions/cyanheads/mcp-ts-core/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.10822 | $0.10822 |
| Opus 5 | $0.05411 | $0.05411 |
| Sonnet 5 | $0.02164 | $0.02164 |
| Haiku 4.5 | $0.01082 | $0.01082 |
Grade A, and why
mcp-ts-core AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- mcp-ts-core CLAUDE.md — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 603 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Developer Protocol
Package: @cyanheads/mcp-ts-core
Version: 0.12.5
Engines: Bun ≥1.3.0, Node ≥24.0.0
MCP SDK: @modelcontextprotocol/server ^2.0.0 (protocol revisions 2026-07-28 and 2025-*)
Zod: ^4.5.4
GitHub: cyanheads/mcp-ts-core
npm: @cyanheads/mcp-ts-core
Docker: ghcr.io/cyanheads/mcp-ts-core
Developer note: Never assume. Read related files and docs before making changes. Read full file content for context. Never try to edit a file before reading it.
Consumers
This package serves two consumer paths. When making changes, know which audience your change affects:
| Path | On-ramp | Affected by changes to |
|---|---|---|
| Direct package import — existing project pulls in the package | bun add @cyanheads/mcp-ts-core → import { createApp, tool, z } from '@cyanheads/mcp-ts-core' |
Public API surface (src/) — existing consumers feel changes immediately on upgrade |
| Init-scaffolded server — fresh project bootstrapped from this repo's templates | bunx @cyanheads/mcp-ts-core init [name] copies templates/ into the new directory |
templates/ — only affects newly scaffolded servers, not existing ones |
Both paths share the same public API. Init copies starter package.json, configs (tsconfig, biome.json, vitest.config.ts, devcheck.config.json, bunfig.toml), .env.example, Dockerfile, LICENSE, .gitattributes, CLAUDE.md/AGENTS.md, .github/ (issue forms, CONTRIBUTING.md, CODE_OF_CONDUCT.md, SECURITY.md), example definitions and tests, framework scripts/, and external-audience skills/. _-prefixed files (e.g. _.gitignore) drop the prefix on copy. Existing files are never overwritten; init without a name scaffolds in place (upgrade flow). After init, consult the setup skill.
Core Rules
- Logic throws, framework catches. Pure, stateless
handlerfunctions, notry/catch. PlainErrorworks — framework catches, classifies, formats. UseMcpError(code, message, data, options?)only when you need a specific JSON-RPC code or structured data; 4th arg{ cause }chains. - Full-stack observability. The framework automatically instruments every tool/resource call — OTel span, duration/payload/memory metrics, structured completion log. Use
ctx.logfor additional domain-specific logging within handlers (external API calls, multi-step operations, business events).requestId,traceId,tenantIdauto-correlated. Noconsolecalls. - Unified Context. Handlers receive
ctxwith logging (ctx.log), tenant-scoped storage (ctx.state), multi-round-trip input (ctx.requestInput/ctx.inputs), and cancellation (ctx.signal).Context extends RequestContext, soctxgoes straight into any service, storage, or logger call. - Decoupled storage.
ctx.statefor tenant-scoped KV. Never access persistence backends directly. - Canvas tokens are capabilities, not tenant-scoped state. A
canvasIdis a 10-char URL-safe token; possession grants full read/write/drop. Shareable between agents and across users in single-tenant deployments. Tools accept token ininput(omit to create fresh) and return inoutput; collaboration is opt-in via token exchange. - Runtime parity. All features work across
stdio/http/Worker. Guard non-portable deps viaruntimeCapsfrom/utils(isNode,isBun,isWorkerLike,hasBuffer,hasProcess, etc.). Prefer runtime-agnostic abstractions (Hono, Fetch APIs). - Definition linting is build-time only. Run
bun run lint:mcp(standalone) orbun run devcheck(gate). Not invoked at server startup — new lint rules are additive and never break deployed servers. Every diagnostic links to the rule reference inapi-linterskill; see that skill for the full rule catalog. - Ask for missing input by returning, not awaiting.
return ctx.requestInput({ inputRequests: … })suspends the handler; it is re-entered withctx.inputspopulated. One handler serves both protocol eras. - Close the loop on issues. When implementing work tracked by a GitHub issue, comment on the issue with what landed and close it. Do both — a comment without a close leaves stale issues open; a close without a comment leaves no record of what shipped. The comment is for future readers — state the concrete changes, not the conversation that produced them.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago Changed · +46 tokens per session 3196325a5080
- 6d ago First seen · 603 lines · 10,776 tokens per session scan A 052555f24b16
mcp-ts-core AGENTS.md is an instructions file published in the GitHub repository cyanheads/mcp-ts-core (150 stars, last pushed 3d ago), licensed Apache-2.0. It adds 10,822 tokens to every session, about $0.0541 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.