Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/krakenfx/kraken-cli/claude-mdgit clone --depth 1 https://github.com/krakenfx/kraken-cliWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/krakenfx/kraken-cli/claude-md)<a href="https://agentmods.dev/instructions/krakenfx/kraken-cli/claude-md"><img src="https://agentmods.dev/badge/instructions/krakenfx/kraken-cli/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01521 | $0.01521 |
| Opus 5 | $0.00760 | $0.00760 |
| Sonnet 5 | $0.00304 | $0.00304 |
| Haiku 4.5 | $0.00152 | $0.00152 |
Grade B, and why
kraken-cli CLAUDE.md scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Unrestricted tool accessmediumExcessive agency
A wildcard tool grant or "run any command" leaves no least-privilege boundary at all.
1. Never execute any command marked `dangerous` without explicit user confirmation. The `dangerous` field in `agents/tool-catalog.json` is the authoritative list (41 commands). Four of them (`order buy/sell/cancel/cancel How it starts
The opening of the file, as written. The whole thing — 150 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CLAUDE.md
This is experimental software. Commands execute real financial transactions. Test with
kraken paper(spot) orkraken futures paper(futures) before real funds. SeeDISCLAIMER.md.
Integration guidance for Claude Code, Claude Desktop, and other Anthropic-powered agents interacting with kraken-cli.
Fast entry points:
- Runtime context:
CONTEXT.md - Full command contract:
agents/tool-catalog.json
What is kraken-cli?
A command-line interface for trading crypto, stocks, forex, and derivatives on Kraken. Every command returns structured JSON. Designed for AI agents and automated pipelines.
Invocation
Call kraken as a subprocess. Always use -o json and redirect stderr:
kraken <command> [args...] -o json 2>/dev/null
Authentication
Set environment variables before invoking:
export KRAKEN_API_KEY="your-key"
export KRAKEN_API_SECRET="your-secret"
Public market data commands (ticker, orderbook, ohlc, trades, spreads, status) require no credentials.
Key Conventions
- stdout is valid JSON on success (exit 0), or a JSON error envelope on runtime failure (exit 1).
- The
errorfield in error envelopes is a stable category code:api,auth,network,rate_limit,validation,config,websocket,io,timeout,parse. - WebSocket commands emit JSONL (one JSON object per line).
- Paper trading commands (
kraken paper ...for spot,kraken futures paper ...for futures) use live prices but no real money. No auth needed. - Exit code 0 = success, 1 = runtime failure (JSON envelope on stdout), 2 = argument/usage error from the parser. With
-o json, exit 2 puts a{"error":"validation"}envelope on stdout (stderr stays empty); without it, clap's usage text goes to stderr. Validate argument values against thevaluesarrays inagents/tool-catalog.jsonbefore invoking.
Safety Rules
- Never execute any command marked
dangerouswithout explicit user confirmation. Thedangerousfield inagents/tool-catalog.jsonis the authoritative list (41 commands). Four of them (order buy/sell/cancel/cancel-all) also carrypaper_safe: true: inside a paper workspace they execute simulated fills and need no confirmation. - Use
--validateflag to dry-run order commands before submitting. - Use
kraken paper(spot) orkraken futures paper(futures) commands for testing strategies safely. - Gate all order placement, cancellation, withdrawal, transfer, and staking operations behind user approval.
- Never log or display API secrets.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 150 lines · 1,521 tokens per session scan B 724bf7530244
kraken-cli CLAUDE.md is an instructions file published in the GitHub repository krakenfx/kraken-cli (704 stars, last pushed 28d ago), licensed MIT. It adds 1,521 tokens to every session, about $0.0076 per session on Opus 5. A static security scan graded it B with 1 finding (unrestricted tool access). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
ClawRouter CLAUDE.md
Claude Code instructions for BlockRunAI/ClawRouter, covering clawrouter, commands, project structure, key dependencies and conventions.
InvestSkill GEMINI.md
Gemini CLI instructions for yennanliu/InvestSkill, covering investskill — gemini cli setup & usage guide, installation & setup, quick start, navigate to the investskill directory and start gemini cli (loads gemini.md automatically).
LLM-TradeBot copilot-instructions.md
Copilot instructions for EthanAlgoX/LLM-TradeBot, covering repository instructions, core rules, validation and ai asset governance.
Convertible-Bond-Pricing-Research CLAUDE.md
Instructions for ericxuzhesheng/Convertible-Bond-Pricing-Research, covering claude.md — convertible bond pricing research, current published state and routine commands.
bukio-cli AGENTS.md
AGENTS.md instructions for erikvankempen/bukio-cli, covering agents.md — bukio-cli agent manual, 1. house rules (non-negotiable), 2. environment, 3. command quick reference and 3.1 jurisdiction profiles (16 markets).
swiss-snb-mcp CLAUDE.md
Claude Code instructions for malkreide/swiss-snb-mcp, covering claude.md, teil 1 — konventionen (portfolio-weit), vor der arbeit, tests and wenn etwas rot ist.