Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/pepuscz/passwd/claude-mdgit clone --depth 1 https://github.com/pepuscz/passwdWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/pepuscz/passwd/claude-md)<a href="https://agentmods.dev/instructions/pepuscz/passwd/claude-md"><img src="https://agentmods.dev/badge/instructions/pepuscz/passwd/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.01378 | $0.01378 |
| Opus 5 | $0.00689 | $0.00689 |
| Sonnet 5 | $0.00276 | $0.00276 |
| Haiku 4.5 | $0.00138 | $0.00138 |
Grade A, and why
passwd CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 88 lines — stays where its author put it; the contents beside it link to each section on GitHub.
passwd
Monorepo with four npm packages + one desktop extension for passwd.team:
- passwd-lib — core library (auth, API client, types). Zero dependencies.
- passwd-mcp — MCP server for AI assistants. Depends on passwd-lib, @modelcontextprotocol/sdk, zod.
- passwd-mcpb — Desktop extension for Claude (.mcpb). All 8 tools including credential injection and MCP proxy. Depends on passwd-lib, @modelcontextprotocol/sdk, zod.
- passwd-cli — full CLI tool. Depends on passwd-lib, commander.
- passwd-agent-cli — agent-safe CLI (no command exposes raw credentials). Depends on passwd-lib, commander.
Build
npm install # links workspaces
npm run build # tsc -b (builds lib first, then mcp + cli)
npm run clean # tsc -b --clean
Project structure
packages/
passwd-lib/src/ types.ts, auth.ts, api.ts, index.ts (barrel)
passwd-mcp/src/ index.ts (MCP server with 5 read-only tools)
passwd-mcpb/src/ index.ts (desktop extension with 8 tools including run_with_credentials and MCP proxy)
passwd-cli/src/ index.ts (commander), commands/*.ts, util/format.ts
passwd-agent-cli/src/ index.ts (commander, 8 safe commands), commands/*.ts, util/
Key design decisions
- npm workspaces with TypeScript project references (
composite: true,tsc -b) - passwd-lib has zero npm dependencies — only Node.js built-ins
- Client-side filtering: the passwd API returns all secrets at once. Filtering/pagination is done in
listSecrets(). MCP defaults to limit 50, CLI defaults to no limit. passwd get <id> --field passwordoutputs raw value with no trailing newline (for$()piping)passwd exec --inject VAR=ID:FIELDfetches secrets in parallel, execs child withstdio: inherit- Token storage uses VS Code pattern: one AES-256-GCM encryption key stored in platform keychain (macOS
securityCLI / Linuxsecret-toolvia libsecret), accountencryption-key. Encrypted token blobs stored as files at~/.passwd/tokens-{hash}.json. Format:{v:1, iv, tag, data}hex-encoded. Keychain key created on firstsaveTokens(), shared across environments.deleteTokens()removes the file but not the key. Linuxsecret-tool storereads value via stdin (no process list exposure). No env var bypass — keychain is required. Zero npm dependencies maintained (node:cryptobuilt-in).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 88 lines · 1,378 tokens per session scan A 49f5fc9ef766
passwd CLAUDE.md is an instructions file published in the GitHub repository pepuscz/passwd (4 stars, last pushed 5mo ago), licensed MIT. It adds 1,378 tokens to every session, about $0.0069 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
pfsense-mcp-server AGENTS.md
AGENTS.md instructions for night4me/pfsense-mcp-server, covering pfsense mcp server, architecture and security, development workflow, long-running validation and test parallelism.
sui-mcp CLAUDE.md
Claude Code instructions for 0xfreak0/sui-mcp, covering sui-mcp, stack, architecture, which transport to use and archive fallback.
pdf-toolkit-mcp CLAUDE.md
Instructions for AryanBV/pdf-toolkit-mcp, covering pdf-toolkit-mcp, 1. project overview, 2. tech stack, 3. project structure and 4. mcp sdk patterns.
clawstash CLAUDE.md
Claude Code instructions for fo0/clawstash, covering claude.md -- project guide, session start -- read order, workflow triggers, output languages and performance / modes.
datadog-mcp CLAUDE.md
Claude Code instructions for dreamiurg/datadog-mcp, covering agent instructions, project, stack, commands and releases.
pubmed-mcp-server AGENTS.md
AGENTS.md instructions for cyanheads/pubmed-mcp-server, covering agent protocol, what's next?, core rules, patterns and tool.