Borrowing it
Nothing to install: this file belongs to sapientsai/microsoft-mcp-server. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/sapientsai/microsoft-mcp-server/main/CLAUDE.mdgit clone --depth 1 https://github.com/sapientsai/microsoft-mcp-serverWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/sapientsai/microsoft-mcp-server/claude-md)<a href="https://agentmods.dev/instructions/sapientsai/microsoft-mcp-server/claude-md"><img src="https://agentmods.dev/badge/instructions/sapientsai/microsoft-mcp-server/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00604 | $0.00604 |
| Opus 5 | $0.00302 | $0.00302 |
| Sonnet 5 | $0.00121 | $0.00121 |
| Haiku 4.5 | $0.00060 | $0.00060 |
Grade A, and why
microsoft-mcp-server CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 75 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CLAUDE.md
This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.
Project Overview
Microsoft Graph MCP Server - A Model Context Protocol server built with FastMCP that provides AI assistants access to Microsoft Graph API for Microsoft 365 services (users, mail, calendar, files, etc.).
Development Commands
pnpm validate # Main command: format + lint + test + build (use before commits)
pnpm test # Run tests once
pnpm test -- --testNamePattern="pattern" # Filter by test name
pnpm test -- test/specific.spec.ts # Run specific file
pnpm build # Production build
pnpm dev # Development build with watch mode
pnpm start # Run the server (requires build first)
Architecture
Built with FastMCP - a TypeScript framework for MCP servers.
src/
├── index.ts # Server factory, config, tools, exports
└── bin.ts # CLI entry point (shebang, dotenv, runServer)
Key Components
- FastMCP: Server framework handling MCP protocol, sessions, transport
- AzureProvider: OAuth 2.0 authentication with Azure AD/Entra ID
- Tools:
microsoft_graph(Graph API calls) andget_auth_status(check auth)
Authentication Flow
OAuth 2.0 handled by FastMCP's AzureProvider:
- MCP client (Claude Desktop) initiates OAuth when tool requires auth
- User redirected to Microsoft login
- Callback to
{BASE_URL}/oauth/callback - Token stored in session, passed to tools via
session.accessToken
Transport Modes
- httpStream (default): HTTP server with
/mcpendpoint and/oauth/callback - stdio: For Claude Code CLI integration
Configuration
Required environment variables:
AZURE_CLIENT_ID=... # Azure app registration client ID
AZURE_CLIENT_SECRET=... # Azure app client secret
AZURE_TENANT_ID=common # Tenant ID (default: "common" for multi-tenant)
BASE_URL=http://localhost:8080 # Server URL (for OAuth callback)
PORT=8080 # Server port
TRANSPORT_TYPE=httpStream # httpStream or stdio
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 75 lines · 604 tokens per session scan A e24b7d8e1f0b
microsoft-mcp-server CLAUDE.md is an instructions file published in the GitHub repository sapientsai/microsoft-mcp-server (1 stars, last pushed 2mo ago), licensed MIT. It adds 604 tokens to every session, about $0.0030 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.