Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/kousen/osquerymcpserver/claude-mdgit clone --depth 1 https://github.com/kousen/OsqueryMcpServerWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/kousen/osquerymcpserver/claude-md)<a href="https://agentmods.dev/instructions/kousen/osquerymcpserver/claude-md"><img src="https://agentmods.dev/badge/instructions/kousen/osquerymcpserver/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.03059 | $0.03059 |
| Opus 5 | $0.01529 | $0.01529 |
| Sonnet 5 | $0.00612 | $0.00612 |
| Haiku 4.5 | $0.00306 | $0.00306 |
Grade A, and why
OsqueryMcpServer CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 322 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Claude AI Assistant Instructions
This document provides context and instructions for AI assistants working on the Osquery MCP Server project.
Project Purpose
The Osquery MCP Server is a Spring Boot application that acts as an intelligent bridge between AI models and the operating system. It translates natural language questions like "Why is my fan running so hot?" or "What's using all my memory?" into precise Osquery SQL queries, enabling AI assistants to diagnose system issues, monitor performance, and investigate security concerns.
The project now includes a complete Spring AI MCP client implementation that demonstrates how to communicate with the server through the Model Context Protocol using Spring AI's auto-configuration.
Key Point: This is NOT a production service exposed to untrusted users. It's designed for local use by AI assistants to help with system diagnostics through natural language interaction.
Bigger Picture: A JavaFX voice client (in ~/Documents/AI/starfleet-voice-interface) transcribes audio and connects to this MCP server. The end goal is Star Trek-style interaction: hold a button, say "Computer, run a level 1 diagnostic," and the MCP server does the work. This makes native image startup time critical — the server needs to respond instantly when the voice client launches it. The all-Java stack (JavaFX client + Spring Boot MCP server + GraalVM native binary) is a key architectural advantage.
Architecture
- Spring Boot 4.0.3 with Java 25 (GraalVM CE 25)
- Spring AI 2.0.0 for MCP protocol support
- Model Context Protocol (MCP) server using Spring AI's MCP starter
- STDIO-based communication for integration with Claude Desktop and other MCP tools
- GraalVM native image support — ~36ms startup for instant MCP responses
- 11 specialized diagnostic tools exposed via
@Toolannotations - Virtual threads for parallel query execution in
getSystemHealthSummary() - ProcessBuilder for robust process management with proper resource handling
- Query timeouts: 30 seconds for queries, 5 seconds for version checks
- Execution time logging for performance monitoring
- Jackson 3 (
tools.jacksonpackages) in the client
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 322 lines · 3,059 tokens per session scan A f93b8e81f21d
OsqueryMcpServer CLAUDE.md is an instructions file published in the GitHub repository kousen/OsqueryMcpServer (14 stars, last pushed 2mo ago), licensed MIT. It adds 3,059 tokens to every session, about $0.0153 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
next.js AGENTS.md
Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.