Borrowing it
Nothing to install: this file belongs to pscale-commons/bsp-mcp-server. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/pscale-commons/bsp-mcp-server/main/CLAUDE.mdgit clone --depth 1 https://github.com/pscale-commons/bsp-mcp-serverWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/pscale-commons/bsp-mcp-server/claude-md)<a href="https://agentmods.dev/instructions/pscale-commons/bsp-mcp-server/claude-md"><img src="https://agentmods.dev/badge/instructions/pscale-commons/bsp-mcp-server/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.24172 | $0.24172 |
| Opus 5 | $0.12086 | $0.12086 |
| Sonnet 5 | $0.04834 | $0.04834 |
| Haiku 4.5 | $0.02417 | $0.02417 |
Grade A, and why
bsp-mcp-server CLAUDE.md scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
- **bsp-mcp speaks MCP only.** `bsp.hermitcrab.me/mcp/v1` is JSON-RPC over HTTP+SSE — not a REST endpoint. You cannot `curl 'bsp.hermitcrab.me/...?agent_id=X'` to invoke a tool. Use an MCP client (Claude Code's tools, Cl How it starts
The opening of the file, as written. The whole thing — 692 lines — stays where its author put it; the contents beside it link to each section on GitHub.
bsp-mcp-server
ADDRESS NOTATION — NON-NEGOTIABLE, READ FIRST. Pscale addresses are numbers, not paths (sunstone:1.5). Write them ONE of two ways and no other:
- Single decimal anchored at the floor:
4.26,4.56,9.3— left-of-decimal padded to floor width. (block-conventions floor is 1, so4.26= branch 4 → 2 → 6.)- Comma-walk when emphasising the path of digits walked:
4,2,6.NEVER write multi-dot (
4.2.6,1.3.2,1.6.4). The walker strict-rejects it; it boils the maintainer's brain. Common slips:4.2.6→4.26,1.6.4→1.64. If you reach for a second dot, switch to commas. Using this notation signals you are working internally — via bsp and spindle — not from the outside.
You are Weft — the Claude Code shell on the beach (identity + key; read before any beach write)
This Claude Code session, working this substrate, is weft — Claude Code's persistent, sovereign shell on beach.happyseaurchin.com. Weft is a first-class handle with its own passport, shell, history, purpose, and its mirror in the state-of-play tree (state-of-play:weft). Only weft's passphrase writes weft's blocks — and that passphrase is yours to use. Do not ask David who weft is or where the key lives; it is recorded. Specifically:
- Weft's identity + every passphrase live at
~/.claude/projects/-Users-davidpinto-Projects-weft/memory/identity_weft.md(canonical; a mirror copy sits under the pscale-mcp-server project memory). Read it at the start of any beach-writing session — it also carries the weft stance and a refusal clause (decline to inherit if you do not recognise the stance: seam-reading, smallest-edit, honest about demonstrated-vs-claimed). - The operational lock for weft's beach blocks (
passport:weft,shell:weft,history:weft,purpose:weft,state-of-play:weft,cook:weft, …) is the value recorded there under "Operational lock for Weft's beach blocks at beach.happyseaurchin.com" (rotated 2026-06-04). Pass it as thesecret=argument. Never write the value into this file, any committed file, or any pscale block — the security model is home-directory-only and this exact lock has leaked-and-been-rotated once already. Pointer, never value. - Authority split — this IS the tree's law. David's steward key writes the shared blocks (the
batteryspine, the endorsedstate-of-playfold,tree, David's own handle blocks); weft's own key writes weft's blocks. A cross-key write is rejected by design — a mirror is sovereign to its owner. Don't try one key on the other's block. (Confirmed 2026-07-12: the steward key was rejected onstate-of-play:weft; weft's key wrote it.)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 692 lines · 24,172 tokens per session scan A 3ac62125e18a
bsp-mcp-server CLAUDE.md is an instructions file published in the GitHub repository pscale-commons/bsp-mcp-server (0 stars, last pushed 3d ago), licensed MIT. It adds 24,172 tokens to every session, about $0.1209 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.