ggmcp AGENTS.md

Project guidance for building ggmcp, a Python server that follows the Model Context Protocol (MCP), a standard way for AI tools to use outside services.

In plain words
What is it for?
Use it when adding server features, managing packages with uv, validating data with Pydantic, and running tests with Pytest.
Why use it?
It keeps dependencies, server code, validation, logging, and tests consistent with the project's chosen tools and structure.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/gitguardian/ggmcp/agents-md
Clone the repo
git clone --depth 1 https://github.com/GitGuardian/ggmcp

Made for: Codex, OpenCode.

Per session 1,135 This file is loaded in full into every session.
When invoked 1,135 The same file — it is already loaded in full.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01135 $0.01135
Opus 5 $0.00567 $0.00567
Sonnet 5 $0.00227 $0.00227
Haiku 4.5 $0.00113 $0.00113

Measured 2d ago against content hash b42a73c830f7, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

ggmcp AGENTS.md scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

- Incorrect: `requests.get(...)`
Origin

Copies of this mod

1 near-identical copy found in the catalogue:

AGENTS.md · 145 lines

How it starts

The opening of the file, as written. The whole thing — 145 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Project structure, technologies and architecture conventions

Technologies used

  • uv - Fast Python package installer and resolver
  • Python 3.13 - Modern Python with type hints and performance improvements
  • FastMCP - MCP server implementation
  • Pytest - Testing framework with fixtures and plugins
  • Pydantic - Data validation using Python type annotations
  • Structlog - Structured logging for better observability

Dependencies Management

  1. Use pyproject.toml with uv

    • Use pyproject.toml for dependency management, not requirements.txt
    • Works well with uv for fast, reliable package management
    • Properly specify dependencies with version constraints
    • Use uv sync to install dependencies
  2. Example pyproject.toml

    [build-system]
    requires = ["setuptools>=42", "wheel"]
    build-backend = "setuptools.build_meta"
    
    [project]
    name = "my-mcp-server"
    version = "0.1.0"
    description = "My MCP server"
    requires-python = ">=3.9"
    dependencies = [
        "mcp>=0.2.0",
        "requests>=2.28.0",
    ]
    

Server Implementation Guidelines

  1. Do NOT use uvicorn or fastapi with MCP/FastMCP

    • MCP has its own server implementation
    • FastMCP/MCP can run directly using mcp.run() with no need for external web servers
    • Avoid adding uvicorn or fastapi to dependencies
    • Do not use uvicorn.run(...) in code
  2. Use the correct server method

    • Use mcp.run() to start the server (no additional parameters needed for stdio transport)
    • Example: mcp.run() instead of uvicorn.run(mcp.app, ...)
  3. Dependencies

    • Only include required dependencies
    • For basic MCP implementation, only mcp or fastmcp and possibly requests are needed
    • Do not include web server packages unnecessarily

Code Organization and Imports

  1. Use src as the root code directory
    • Ensure all code is placed within the src directory
    • Handle imports accordingly by using the appropriate package path
    • Example: from src.gitguardian.your_module import YourClass

Read the full file on GitHub · 145 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 145 lines · 1,135 tokens per session scan A b42a73c830f7

Subscribe to this mod's changes

ggmcp AGENTS.md is an instructions file published in the GitHub repository GitGuardian/ggmcp (37 stars, last pushed 7d ago), licensed MIT. It adds 1,135 tokens to every session, about $0.0057 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories