OsqueryMcpServer CLAUDE.md

OsqueryMcpServer CLAUDE.md is an instructions file for coding agents from kousen/OsqueryMcpServer. It costs 3,059 tokens per session, scanned A, original, MIT.

Project instructions for a local Spring Boot service that lets an AI assistant ask an operating-system database called osquery questions in plain language. It also describes an example client using the Model Context Protocol, a standard way for AI tools to communicate with services.

In plain words
What is it for?
Diagnosing computer problems such as high fan activity or memory use, investigating security concerns, and developing or testing the local osquery service and its example client.
Why use it?
They give an AI coding assistant the project’s purpose, structure, branches, and available tools, so it can work in the repository with the right context.

Instructions file

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/kousen/osquerymcpserver/claude-md
Clone the repo
git clone --depth 1 https://github.com/kousen/OsqueryMcpServer

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for OsqueryMcpServer CLAUDE.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/kousen/osquerymcpserver/claude-md.svg)](https://agentmods.dev/instructions/kousen/osquerymcpserver/claude-md)
Your own site
<a href="https://agentmods.dev/instructions/kousen/osquerymcpserver/claude-md"><img src="https://agentmods.dev/badge/instructions/kousen/osquerymcpserver/claude-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 3,059 This file is loaded in full into every session.
When invoked 3,059 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.03059 $0.03059
Opus 5 $0.01529 $0.01529
Sonnet 5 $0.00612 $0.00612
Haiku 4.5 $0.00306 $0.00306

Measured 4d ago against content hash f93b8e81f21d, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

OsqueryMcpServer CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

CLAUDE.md · 322 lines

How it starts

The opening of the file, as written. The whole thing — 322 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Claude AI Assistant Instructions

This document provides context and instructions for AI assistants working on the Osquery MCP Server project.

Project Purpose

The Osquery MCP Server is a Spring Boot application that acts as an intelligent bridge between AI models and the operating system. It translates natural language questions like "Why is my fan running so hot?" or "What's using all my memory?" into precise Osquery SQL queries, enabling AI assistants to diagnose system issues, monitor performance, and investigate security concerns.

The project now includes a complete Spring AI MCP client implementation that demonstrates how to communicate with the server through the Model Context Protocol using Spring AI's auto-configuration.

Key Point: This is NOT a production service exposed to untrusted users. It's designed for local use by AI assistants to help with system diagnostics through natural language interaction.

Bigger Picture: A JavaFX voice client (in ~/Documents/AI/starfleet-voice-interface) transcribes audio and connects to this MCP server. The end goal is Star Trek-style interaction: hold a button, say "Computer, run a level 1 diagnostic," and the MCP server does the work. This makes native image startup time critical — the server needs to respond instantly when the voice client launches it. The all-Java stack (JavaFX client + Spring Boot MCP server + GraalVM native binary) is a key architectural advantage.

Architecture

  • Spring Boot 4.0.3 with Java 25 (GraalVM CE 25)
  • Spring AI 2.0.0 for MCP protocol support
  • Model Context Protocol (MCP) server using Spring AI's MCP starter
  • STDIO-based communication for integration with Claude Desktop and other MCP tools
  • GraalVM native image support — ~36ms startup for instant MCP responses
  • 11 specialized diagnostic tools exposed via @Tool annotations
  • Virtual threads for parallel query execution in getSystemHealthSummary()
  • ProcessBuilder for robust process management with proper resource handling
  • Query timeouts: 30 seconds for queries, 5 seconds for version checks
  • Execution time logging for performance monitoring
  • Jackson 3 (tools.jackson packages) in the client

Read the full file on GitHub · 322 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 322 lines · 3,059 tokens per session scan A f93b8e81f21d

Subscribe to this mod's changes

OsqueryMcpServer CLAUDE.md is an instructions file published in the GitHub repository kousen/OsqueryMcpServer (14 stars, last pushed 2mo ago), licensed MIT. It adds 3,059 tokens to every session, about $0.0153 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,345 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

next.js AGENTS.md

Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens