Borrowing it
Nothing to install: this file belongs to jordanburke/oura-ring-mcp-server. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/jordanburke/oura-ring-mcp-server/main/CLAUDE.mdgit clone --depth 1 https://github.com/jordanburke/oura-ring-mcp-serverWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/jordanburke/oura-ring-mcp-server/claude-md)<a href="https://agentmods.dev/instructions/jordanburke/oura-ring-mcp-server/claude-md"><img src="https://agentmods.dev/badge/instructions/jordanburke/oura-ring-mcp-server/claude-md/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/instructions/jordanburke/oura-ring-mcp-server/claude-md"><img src="https://agentmods.dev/badge/instructions/jordanburke/oura-ring-mcp-server/claude-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.01208 | $0.01208 |
| Opus 5 | $0.00604 | $0.00604 |
| Sonnet 5 | $0.00242 | $0.00242 |
| Haiku 4.5 | $0.00121 | $0.00121 |
Grade A, and why
oura-ring-mcp-server CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 88 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CLAUDE.md
This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.
Project Overview
An MCP (Model Context Protocol) server for the Oura Ring API v2. It exposes a single
consolidated oura_data tool that covers every Oura usercollection endpoint, so an MCP client
can query sleep, readiness, activity, heart rate, workouts, etc. from the user's Oura data.
Built in the style of dokploy-mcp-server: one action/collection-parameterized tool (minimal token
footprint) on top of somamcp, with functype
for typed error handling and zod for parameter validation.
Development Commands
Commands delegate to the ts-builds toolchain (ESM output via tsdown).
pnpm validate # format + lint + typecheck + test + build (run before commits)
pnpm dev # watch build (outputs to lib/)
pnpm build # production build (outputs to dist/)
pnpm test # vitest run
pnpm test:watch
pnpm typecheck
pnpm inspect # run dist/index.js against @modelcontextprotocol/inspector
Run a single test file: pnpm test -- test/client.spec.ts.
Note: pnpm 11's pre-run deps check requires build-script decisions to be acknowledged in
pnpm-workspace.yamlunderallowBuilds:(e.g.tldjs: false). If you add a dependency whose install printsERR_PNPM_IGNORED_BUILDS, add it there.
Architecture
Entry point src/index.ts:
parseConfig(process.env)→Either<string, OuraConfig>(fails fast with a stderr message + exit 1).createServer(...)fromsomamcpwith telemetry + introspection.server.addTool(createOuraDataTool(config)).server.start(...)onstdio(default) orhttpStream.
Source layout
src/config.ts— env →OuraConfig(Either). Resolves anAuthConfig:oauthwhenOURA_CLIENT_ID/OURA_CLIENT_SECRETare set (preferred), elsepatviaOURA_API_KEY(legacy fallback — Oura stopped issuing new PATs in Dec 2025).OURA_SANDBOXswitches the base URL to Oura's/sandbox/demo data.src/oura/auth.ts—TokenProviderabstraction producing the Bearer token. Static for PAT; for OAuth, refreshes with single-flight + persist-before-use against a token store (~/.config/oura-ring-mcp/tokens.json). Oura refresh tokens are single-use/rotating, so the store is the source of truth — never the env. Also exportsexchangeAuthCode/writeTokenStore.src/login.ts— theloginsubcommand: browser consent → localhost one-shot callback (CSRFstate) → authorization-code exchange → writes the token store.src/oura/collections.ts— the descriptor table: every collection'skind(daily|datetime|listOnly|singleton), whether it has a by-id route, and whether it supportslatest. Source of truth is Oura's OpenAPI spec (openapi-1.35.json); update this table when Oura publishes a newer version.src/oura/params.ts— thezodschema foroura_data, with asuperRefineenforcing which params are legal per collection (returns LLM-actionable messages).src/oura/client.ts—buildUrl(pure; takes an injectednowfor deterministic default ranges) andrequestOura(nativefetch→Either<OuraError, unknown>; never throws on network/HTTP/parse).src/tools/ouraData.ts— theoura_datatool; folds theEitherto a JSON string or throwssomamcp.UserError(which somamcp classifies for the client).src/telemetry.ts— composite telemetry. Defaults to no-op: under stdio, stdout is the JSON-RPC channel, so console telemetry is only enabled underhttpStream. NDJSON file telemetry is opt-in viaOURA_TELEMETRY_FILE.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 88 lines · 1,208 tokens per session scan A 6d39abf53a11
oura-ring-mcp-server CLAUDE.md is an instructions file published in the GitHub repository jordanburke/oura-ring-mcp-server (1 stars, last pushed 1mo ago), licensed MIT. It adds 1,208 tokens to every session, about $0.0060 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
deepseek-harness AGENTS.md
AGENTS.md instructions for deepseek-ai/deepseek-harness, covering agents.md, pre-stable apis and released session data, repository layout, commands and host sandbox failures.