msloop-mcp AGENTS.md

Repository guidance for an MCP server that gives agents read and discovery access to Microsoft Loop. Microsoft Loop is a workspace app for collaborative pages, and this project uses the Loop web app’s internal web APIs because no public Loop API exists.

In plain words
What is it for?
Use it when developing or maintaining this Loop connector, especially when working with workspaces, Fluid Framework pages, browser-session tokens, or the lack of public content-writing access.
Why use it?
It explains the project’s authentication, data model, installation, and limits so an agent does not assume Loop works like an ordinary REST service.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/shayanline/msloop-mcp/agents-md
Clone the repo
git clone --depth 1 https://github.com/shayanline/msloop-mcp

Made for: Codex, OpenCode.

Per session 1,341 This file is loaded in full into every session.
When invoked 1,341 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01341 $0.01341
Opus 5 $0.00671 $0.00671
Sonnet 5 $0.00268 $0.00268
Haiku 4.5 $0.00134 $0.00134

Measured yesterday against content hash 305713a3126e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

msloop-mcp AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 80 lines

How it starts

The opening of the file, as written. The whole thing — 80 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Agent Guidelines for Loop MCP

This document captures project knowledge to help AI agents work effectively with this codebase.

Repository

Project Overview

An MCP server that gives AI assistants read and discovery access to Microsoft Loop. Microsoft publishes no Loop API, so this reuses the Loop web app's own first party client ID and the internal APIs the web client calls, with tokens extracted from a browser session. The browser is only used for initial login and silent refresh fallback, everything else is direct HTTP.

The central constraint

Loop is not a REST resource model like mail or calendar. Workspaces are SharePoint Embedded containers, and pages are Fluid Framework documents (ops plus snapshots). There is no public content-write API and content cannot be materialised over plain HTTP without the Fluid client runtime.

So this server is read and discovery only:

  • Metadata (workspaces, pages) comes from the Substrate Loop API.
  • Page content is read by asking SharePoint to render the Fluid document to HTML on demand (?format=html), then converting to Markdown. Lossy for rich components.
  • Writing or editing page content is out of scope and not achievable here.

Architecture

src/
  index.ts              Entry point, runs the MCP server on stdio
  server.ts             createServer() — registers all tool groups
  constants.ts          Client ID, endpoints, scopes, timeouts
  auth/
    index.ts            getSubstrateToken / getSharePointToken / getGraphToken, status
    session-store.ts    AES-256-GCM encrypted token + session storage in ~/.msloop-mcp-server/
    token-extractor.ts  Pure: select Substrate/SharePoint/Graph tokens from MSAL entries by audience
    token-refresh.ts    HTTP refresh, one OAuth2 call per resource
    browser-login.ts    Playwright login at loop.cloud.microsoft (headless first)
  browser/
    cookie-import.ts    Cross-platform SSO cookie import (Keychain / libsecret / DPAPI)
  api/
    client.ts           substrateGet/Post, graphGet/Post, sharePointGetText
    loop.ts             discover() (merge /workspaces + /recent + /deltasync), listPages, createWorkspace
    pages.ts            getPageContent — HTML export then htmlToMarkdown
    search.ts           Graph /search/query for .loop / .fluid files
  utils/
    http.ts             Bearer headers, retry, the SharePoint multipart "GET via POST" builder
    parsers.ts          Pure: decodePodId, itemIdFromPageId, hostFromSiteUrl, slugify, htmlToMarkdown
    logger.ts           stderr logger (MSLOOP_DEBUG=true)
  types/loop.ts         Substrate API shapes

Read the full file on GitHub · 80 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 80 lines · 1,341 tokens per session scan A 305713a3126e

Subscribe to this mod's changes

msloop-mcp AGENTS.md is an instructions file published in the GitHub repository shayanline/msloop-mcp (1 stars, last pushed 2mo ago), licensed MIT. It adds 1,341 tokens to every session, about $0.0067 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.