Borrowing it
Nothing to install: this file belongs to shanevcantwell/surf-mcp. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/shanevcantwell/surf-mcp/release/v0.5.0/CLAUDE.mdgit clone --depth 1 https://github.com/shanevcantwell/surf-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/shanevcantwell/surf-mcp/claude-md)<a href="https://agentmods.dev/instructions/shanevcantwell/surf-mcp/claude-md"><img src="https://agentmods.dev/badge/instructions/shanevcantwell/surf-mcp/claude-md/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/instructions/shanevcantwell/surf-mcp/claude-md"><img src="https://agentmods.dev/badge/instructions/shanevcantwell/surf-mcp/claude-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.01824 | $0.01824 |
| Opus 5 | $0.00912 | $0.00912 |
| Sonnet 5 | $0.00365 | $0.00365 |
| Haiku 4.5 | $0.00182 | $0.00182 |
Grade A, and why
surf-mcp CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 212 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Surf MCP Server
Purpose: MCP server for visual browser automation via Fara.
Version: 0.5.0
Core Concepts
Visual Grounding
Surf uses multimodal LLMs (Fara-7B via LM Studio, or Gemini/GPT-4V) to locate UI elements by natural language description instead of brittle CSS selectors.
An AI that can see the page doesn't need to parse HTML.
Direct Fara Execution (ADR-005)
Fara returns complete tool_calls, not just coordinates. We execute what Fara decides:
{
"name": "computer_use",
"arguments": {
"action": "left_click",
"coordinate": [624, 280],
"reasoning": "The search button is a blue element..."
}
}
Available actions: left_click, double_click, type, scroll, key, visit_url, terminate, wait
FaraToolCall Data Model
The FaraToolCall dataclass preserves Fara's full action context:
action: Action type (left_click, type, scroll, etc.)coordinate: (x, y) pixel coordinatestext: Text to type (for type action)direction: Scroll direction (up/down)keys: Keys to press (for key action)confidence: Model confidence (0.0-1.0)reasoning: Fara's chain-of-thought explanation
Multi-Server LM Studio Support
Supports multiple LM Studio instances across different GPUs/machines:
- Server Discovery: Probes each server's
/v1/modelsmanifest - Prefer Loaded: Prioritizes servers with Fara already loaded in VRAM
- Fallback: Sequential retry across servers on failure
Configure in .env:
LMSTUDIO_SERVERS="rtx3090=http://localhost:1234/v1,rtx8000=http://192.168.137.2:1234/v1"
FARA_MODEL_IDS="microsoft_fara-7b,fara-7b-gguf,gao-zijian/fara-7b"
FARA_MAX_FAILURES=2
FARA_PROBE_TIMEOUT=2.0
Installation & Running
Docker (Recommended)
docker compose up
Direct Installation (Development)
pip install -e ".[dev]"
playwright install chromium
surf-mcp # Run the server
Development Directives
Testing
# Setup
pip install -e ".[dev]"
docker build --target prod -t surf-mcp .
# Run tests
pytest # All tests (skips unavailable)
pytest -m "not llm" # Skip LLM tests (for CI)
pytest -m docker # Docker container tests
pytest -m "docker and browser" # Docker + browser tests
pytest -m llm -v -s # Real LLM tests (requires LM Studio)
mypy src/
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 212 lines · 1,824 tokens per session scan A b5a508396573
surf-mcp CLAUDE.md is an instructions file published in the GitHub repository shanevcantwell/surf-mcp (0 stars, last pushed 1mo ago), licensed MIT. It adds 1,824 tokens to every session, about $0.0091 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
deepseek-harness AGENTS.md
AGENTS.md instructions for deepseek-ai/deepseek-harness, covering agents.md, pre-stable apis and released session data, repository layout, commands and host sandbox failures.