Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/rapid7/rapid7-bulk-export-mcp/agents-mdgit clone --depth 1 https://github.com/rapid7/rapid7-bulk-export-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/rapid7/rapid7-bulk-export-mcp/agents-md)<a href="https://agentmods.dev/instructions/rapid7/rapid7-bulk-export-mcp/agents-md"><img src="https://agentmods.dev/badge/instructions/rapid7/rapid7-bulk-export-mcp/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.02192 | $0.02192 |
| Opus 5 | $0.01096 | $0.01096 |
| Sonnet 5 | $0.00438 | $0.00438 |
| Haiku 4.5 | $0.00219 | $0.00219 |
Grade A, and why
rapid7-bulk-export-mcp AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- Rapid7-MCP AGENTS.md — 100% identical, 25 lines differ
How it starts
The opening of the file, as written. The whole thing — 197 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AGENTS.md
Project
MCP server that exports Rapid7 data via the Bulk Export API and loads it into DuckDB for SQL analysis. Exposes MCP tools consumed by AI assistants (Claude Desktop, Kiro, etc.).
Dev Setup
# Install dependencies
uv sync
# Required env vars
export RAPID7_API_KEY=your-key
export RAPID7_REGION=us # us, us2, us3, eu, ca, au, ap
# Run the server (stdio)
uv run rapid7-mcp-server
# Or via venv entry point directly (required for Claude Desktop)
.venv/bin/rapid7-mcp-server
Commands
make test # run the test suite
make lint # ruff check + format check
make lint-fix # auto-fix lint and format issues
make security # bandit security scan
make help # list all targets
Version management
make version # print current version
make check-version # verify manifest.json, pyproject.toml, SKILL.md are in sync
make bump-version V=0.5.0 # bump all three version files atomically + uv lock
Packaging and release
make package # build .mcpb bundle + skill zip (requires mcpb: npm install -g @anthropic-ai/mcpb)
make package-mcpb # .mcpb bundle only
make package-skill # skill zip only
make release # check-version + package + create GitHub release (requires gh CLI + GH_TOKEN)
make clean # remove build artifacts
Architecture
| Module | Responsibility |
|---|---|
src/mcp_server.py |
FastMCP tool definitions, request routing, startup |
src/export_manager.py |
GraphQL mutations to create exports, status polling |
src/duckdb_loader.py |
Load Parquet files into DuckDB, prefix → table routing |
src/export_tracker.py |
Separate DuckDB tracking DB — avoids redundant daily exports |
src/graphql_client.py |
Authenticated GraphQL HTTP client |
src/download.py |
Download Parquet files from signed URLs |
src/config.py |
Load and validate config from environment variables |
Database tables
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago Changed · +13 lines · +245 tokens per session 5ece9e26c675
- 6d ago First seen · 184 lines · 1,947 tokens per session scan A fe995dd540c5
rapid7-bulk-export-mcp AGENTS.md is an instructions file published in the GitHub repository rapid7/rapid7-bulk-export-mcp (29 stars, last pushed 2d ago), licensed MIT. It adds 2,192 tokens to every session, about $0.0110 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
lms-front CLAUDE.md
Claude Code instructions for guillermoscript/lms-front, covering claude.md, project overview, commands, architecture and multi-tenancy.
vespertide AGENTS.md
AGENTS.md instructions for dev-five-git/vespertide, covering vespertide knowledge base, structure, where to look, data flow and conventions.
seekstone CLAUDE.md
Claude Code instructions for shaqmughal/seekstone, covering claude.md, what this repo is, commands, the harness itself (run after npm install) and architecture.
rails_ai_agents AGENTS.md
AGENTS.md instructions for ThibautBaissac/rails_ai_agents, covering project configuration, tech stack, architecture, key commands and tests.
pg-dash CLAUDE.md
Claude Code instructions for indiekitai/pg-dash, covering pg-dash claude.md, 项目结构, 构建与测试, 发版纪律(强制) and 发版检查清单(每次 npm publish 前必须按序执行).
MCP-SqlServer CLAUDE.md
Claude Code instructions for Aron-Valenzuela/MCP-SqlServer, covering claude.md, project overview, setup (for each user), 1. install dependencies and 2. configure claude desktop.