Borrowing it
Nothing to install: this file belongs to janeksm/mcp-digger. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/janeksm/mcp-digger/main/CLAUDE.mdgit clone --depth 1 https://github.com/janeksm/mcp-diggerWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/janeksm/mcp-digger/claude-md)<a href="https://agentmods.dev/instructions/janeksm/mcp-digger/claude-md"><img src="https://agentmods.dev/badge/instructions/janeksm/mcp-digger/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.01601 | $0.01601 |
| Opus 5 | $0.00800 | $0.00800 |
| Sonnet 5 | $0.00320 | $0.00320 |
| Haiku 4.5 | $0.00160 | $0.00160 |
Grade A, and why
mcp-digger CLAUDE.md scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Runs shell commandslowCapability
Expected in a hook, worth knowing in a rule or an instructions file.
gitClient.ts ← git CLI via child_process.execFile (clone, fetch, revParse, readFile, listFiles) How it starts
The opening of the file, as written. The whole thing — 91 lines — stays where its author put it; the contents beside it link to each section on GitHub.
mcp-digger
Node.js/TypeScript MCP server that gives Claude Code progressive access to .NET NuGet package source code. One health-check tool (dig_status), a discovery tool (dig_list), six dig tools: repo overview (package listing with summaries), package overview (docs + key types), package files (source file listing), lookup (symbol-to-file search, supports cross-package), signatures (stripped public API), file (full source), and one operational tool (dig_refresh — force cache invalidation). Claude decides when to escalate based on tool descriptions.
Claude Rules
- Always use context7 when I need code generation, setup or configuration steps, or library/API documentation.
- Use the mcp-builder skill when you need deeper understanding of MCP best practices, protocol concepts, tool design patterns, annotations, input/output schemas, or transport options.
- Don't combine
cdwith other commands (e.g.cd /path && git status). Run commands directly using absolute paths instead (e.g.git -C /path status). Compound commands can't be matched against the allowed permissions list, causing unnecessary confirmation prompts.
Clean Code (Pragmatic)
Before writing, modifying, or reviewing any code, read CC.md. It contains the full Node.js / TypeScript-specific rule set (async patterns, error handling, module hygiene, testing, security, performance) and complements the language-agnostic principles below.
Follow these principles as defaults, not dogma. Break any rule when it clearly hurts readability or adds unnecessary complexity.
- Naming is design. Functions, variables, and types should reveal intent. If you need a comment to explain what something does, rename it instead. Avoid abbreviations unless universally understood (
config,pkg,idxare fine;prfx,dscare not). - Functions do one thing. A function should have a single reason to change. If a function name needs "and" to describe it, split it. Keep functions short enough to read without scrolling — but don't split just to hit an arbitrary line count.
- One level of abstraction per function. Don't mix high-level orchestration with low-level string manipulation in the same function body. Extract the lower level into a named helper.
- Minimal parameters. Prefer 0–2 parameters. When a function needs 3+, consider grouping related params into an object/config. Booleans as parameters are a smell — they usually mean the function does two things.
- No side effects unless the name says so. A function named
getXorfindXshould not modify state. Functions that mutate should have verbs likeupdate,set,write,mark. - Early returns over nesting. Guard clauses at the top, happy path at normal indentation. Avoid
elseafterreturn. - DRY, but not at the cost of coupling. Extract duplication only when the duplicated pieces change for the same reason. Three similar lines are better than a premature abstraction that couples unrelated concerns.
- Boy Scout Rule. Leave code cleaner than you found it — but only in the area you're already touching. Don't refactor unrelated code in the same change.
- Tests are documentation. Test names should read as specifications. Arrange-Act-Assert structure. One logical assertion per test (multiple
expectcalls are fine if they verify one behavior). - Error handling is behavior. Don't ignore errors silently. Return meaningful messages (this project: tools never throw, they return
toolError()). Handle errors at the right level — where you have enough context to do something useful.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 91 lines · 1,601 tokens per session scan A 94324d50f0ed
mcp-digger CLAUDE.md is an instructions file published in the GitHub repository janeksm/mcp-digger (0 stars, last pushed 3mo ago), licensed MIT. It adds 1,601 tokens to every session, about $0.0080 per session on Opus 5. A static security scan graded it A with 1 finding (runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.