Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/gtorreal/buda-mcp/agents-mdgit clone --depth 1 https://github.com/gtorreal/buda-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/gtorreal/buda-mcp/agents-md)<a href="https://agentmods.dev/instructions/gtorreal/buda-mcp/agents-md"><img src="https://agentmods.dev/badge/instructions/gtorreal/buda-mcp/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00922 | $0.00922 |
| Opus 5 | $0.00461 | $0.00461 |
| Sonnet 5 | $0.00184 | $0.00184 |
| Haiku 4.5 | $0.00092 | $0.00092 |
Grade A, and why
buda-mcp AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 70 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AGENTS.md — buda-mcp
MCP server exposing Buda.com public REST API v2 as tools and resources for AI assistants. No API key required (v2.0.0+).
Layout
src/index.ts stdio MCP server entrypoint
src/http.ts HTTP/SSE MCP server entrypoint (Express, stateless)
src/client.ts BudaClient — fetch wrapper, 429 retry, error sanitization
src/cache.ts In-memory TTL cache with in-flight deduplication
src/validation.ts validateMarketId(), validateCurrency()
src/utils.ts flattenAmount(), aggregateTradesToCandles(), etc.
src/format.ts Shared markdown formatting helpers (liquidityBadge, fmtSlippage, fmtTimestamp)
src/version.ts Version string (reads package.json)
src/types.ts TypeScript types for Buda API responses
src/tools/ One file per tool — each exports register(), toolSchema, handler
test/unit.ts Unit tests (no network)
test/run-all.ts Integration tests (live API, skips if unreachable)
marketplace/ Listing artifacts (openapi.yaml, gemini-tools.json, claude-listing.md)
scripts/ sync-version.mjs
Commands
- Install:
npm install - Dev (stdio):
npm run dev - Dev (HTTP):
npm run dev:http - Build:
npm run build - Test (all):
npm test - Test (unit only):
npm run test:unit - Test (integration):
npm run test:integration - Sync version:
npm run sync-version - Publish:
npm publish --access public --provenance
Invariants
NEVER violate without an ADR amendment.
- Public-only API. No authenticated/private tools exist since v2.0.0. NEVER accept or require API keys. The
with-authbranch preserves legacy auth code. - Tool output is markdown. Every tool MUST return pre-formatted markdown via
content: [{ type: "text", text }]. Usesrc/format.tshelpers. NEVER return rawJSON.stringify. - Agent passthrough. Downstream agents MUST relay tool output verbatim — no re-summary, re-table, or paraphrase unless the user asks.
- Input validation before URL interpolation. MUST call
validateMarketId()orvalidateCurrency()before building API paths. Validation errors MUST use static strings — NEVER embed user input. - Error sanitization. Internal details (paths, stack traces) go to
stderronly. Callers see generic messages viaformatApiError(). - Dual entrypoint registration. New tools MUST be registered in both
src/index.ts(stdio) andsrc/http.ts(HTTP). - Version in package.json only. Run
npm run sync-versionafter bumping. NEVER hardcode version strings.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 70 lines · 922 tokens per session scan A ba6872090377
buda-mcp AGENTS.md is an instructions file published in the GitHub repository gtorreal/buda-mcp (0 stars, last pushed 2mo ago), licensed MIT. It adds 922 tokens to every session, about $0.0046 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
ClawRouter CLAUDE.md
Claude Code instructions for BlockRunAI/ClawRouter, covering clawrouter, commands, project structure, key dependencies and conventions.
InvestSkill GEMINI.md
Gemini CLI instructions for yennanliu/InvestSkill, covering investskill — gemini cli setup & usage guide, installation & setup, quick start, navigate to the investskill directory and start gemini cli (loads gemini.md automatically).
LLM-TradeBot copilot-instructions.md
Copilot instructions for EthanAlgoX/LLM-TradeBot, covering repository instructions, core rules, validation and ai asset governance.
Convertible-Bond-Pricing-Research CLAUDE.md
Instructions for ericxuzhesheng/Convertible-Bond-Pricing-Research, covering claude.md — convertible bond pricing research, current published state and routine commands.
bukio-cli AGENTS.md
AGENTS.md instructions for erikvankempen/bukio-cli, covering agents.md — bukio-cli agent manual, 1. house rules (non-negotiable), 2. environment, 3. command quick reference and 3.1 jurisdiction profiles (16 markets).
swiss-snb-mcp CLAUDE.md
Claude Code instructions for malkreide/swiss-snb-mcp, covering claude.md, teil 1 — konventionen (portfolio-weit), vor der arbeit, tests and wenn etwas rot ist.