Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/gitguardian/ggmcp/agents-mdgit clone --depth 1 https://github.com/GitGuardian/ggmcpWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01135 | $0.01135 |
| Opus 5 | $0.00567 | $0.00567 |
| Sonnet 5 | $0.00227 | $0.00227 |
| Haiku 4.5 | $0.00113 | $0.00113 |
Grade A, and why
ggmcp AGENTS.md scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
- Incorrect: `requests.get(...)` Copies of this mod
1 near-identical copy found in the catalogue:
- ggmcp AGENTS.md — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 145 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Project structure, technologies and architecture conventions
Technologies used
- uv - Fast Python package installer and resolver
- Python 3.13 - Modern Python with type hints and performance improvements
- FastMCP - MCP server implementation
- Pytest - Testing framework with fixtures and plugins
- Pydantic - Data validation using Python type annotations
- Structlog - Structured logging for better observability
Dependencies Management
-
Use pyproject.toml with uv
- Use
pyproject.tomlfor dependency management, not requirements.txt - Works well with
uvfor fast, reliable package management - Properly specify dependencies with version constraints
- Use
uv syncto install dependencies
- Use
-
Example pyproject.toml
[build-system] requires = ["setuptools>=42", "wheel"] build-backend = "setuptools.build_meta" [project] name = "my-mcp-server" version = "0.1.0" description = "My MCP server" requires-python = ">=3.9" dependencies = [ "mcp>=0.2.0", "requests>=2.28.0", ]
Server Implementation Guidelines
-
Do NOT use uvicorn or fastapi with MCP/FastMCP
- MCP has its own server implementation
- FastMCP/MCP can run directly using
mcp.run()with no need for external web servers - Avoid adding uvicorn or fastapi to dependencies
- Do not use
uvicorn.run(...)in code
-
Use the correct server method
- Use
mcp.run()to start the server (no additional parameters needed for stdio transport) - Example:
mcp.run()instead ofuvicorn.run(mcp.app, ...)
- Use
-
Dependencies
- Only include required dependencies
- For basic MCP implementation, only
mcporfastmcpand possiblyrequestsare needed - Do not include web server packages unnecessarily
Code Organization and Imports
- Use
srcas the root code directory- Ensure all code is placed within the
srcdirectory - Handle imports accordingly by using the appropriate package path
- Example:
from src.gitguardian.your_module import YourClass
- Ensure all code is placed within the
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 145 lines · 1,135 tokens per session scan A b42a73c830f7
ggmcp AGENTS.md is an instructions file published in the GitHub repository GitGuardian/ggmcp (37 stars, last pushed 7d ago), licensed MIT. It adds 1,135 tokens to every session, about $0.0057 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
redmem CLAUDE.md
Instructions for tokligence/redmem, covering redmem — development guide, the one that will bite you first: the interpreter, running the tests, architecture: the dispatcher chain and the shield's data model.
kdbx AGENTS.md
Instructions for yarrasys/kdbx, covering agents.md, what this is, current status — read this first, golden rules and repository map.
kdbx CLAUDE.md
Instructions for yarrasys/kdbx, a project described as: Per-project secrets in local KeePassXC vaults, injected into commands without ever printing them. Agent-safe: PreToolUse guard hook + read-only MCP server. Single Go binary.
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.