Borrowing it
Nothing to install: this file belongs to siqiliu-tsinghua/mma-mcp. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/siqiliu-tsinghua/mma-mcp/main/CLAUDE.mdgit clone --depth 1 https://github.com/siqiliu-tsinghua/mma-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/siqiliu-tsinghua/mma-mcp/claude-md)<a href="https://agentmods.dev/instructions/siqiliu-tsinghua/mma-mcp/claude-md"><img src="https://agentmods.dev/badge/instructions/siqiliu-tsinghua/mma-mcp/claude-md/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/instructions/siqiliu-tsinghua/mma-mcp/claude-md"><img src="https://agentmods.dev/badge/instructions/siqiliu-tsinghua/mma-mcp/claude-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.02190 | $0.02190 |
| Opus 5 | $0.01095 | $0.01095 |
| Sonnet 5 | $0.00438 | $0.00438 |
| Haiku 4.5 | $0.00219 | $0.00219 |
Grade A, and why
mma-mcp CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 174 lines — stays where its author put it; the contents beside it link to each section on GitHub.
mma-mcp — Wolfram Engine MCP Server
Working Language
Preferred: Chinese (Simplified). Fallback: English. Never use other languages.
Project Overview
A Model Context Protocol (MCP) server that wraps a local Wolfram Engine, enabling AI assistants (Claude, ChatGPT, etc.) to invoke Wolfram Language computation — symbolic math, numerical analysis, data visualization, and more.
Tech Stack
- Language: Python 3.11+
- MCP framework:
mcp[cli](official Python SDK, FastMCP) - Wolfram bridge:
wolframclient(local kernel viaWolframLanguageSession) - HTTP: Starlette + uvicorn (via
mcp[cli]transitive deps) - Package manager:
uv
Project Structure
mma-mcp/
├── src/
│ └── mma_mcp/
│ ├── __init__.py
│ ├── server.py # App class + CLI entry point (argparse subcommands)
│ ├── config.py # TOML config loading, dataclasses, validation
│ ├── kernel.py # KernelSession: single kernel lifecycle, auto-restart, timeout
│ ├── pool.py # KernelPool: worker pool for cross-client isolation
│ ├── auth.py # BearerAuthMiddleware, ClientIdentity contextvar
│ ├── oauth.py # Minimal OAuth 2.1 server (DCR + PKCE + AuthCode)
│ ├── passwords.py # scrypt hash/verify (stdlib only)
│ ├── logging_config.py # Structured logging with per-request ID
│ ├── stdio_transport.py # Custom stdio transport (fixes SDK pipe hang)
│ ├── caddyfile.py # Caddyfile generator for HTTPS deployment
│ ├── setup_groups.py # Generate security group JSONs from local kernel
│ ├── security/
│ │ ├── __init__.py
│ │ ├── filter.py # ExpressionFilter: regex symbol extraction + policy check
│ │ ├── registry.py # CapabilityRegistry: load groups, build filters
│ │ └── groups/ # User-generated JSON symbol lists per group (not committed)
│ │ ├── manifest.json # Group metadata (29 groups: 22 safe + 7 dangerous)
│ │ ├── math_core.json, algebra.json, ... # 22 safe groups
│ │ ├── system_exec.json, file_read.json, ... # 7 dangerous groups
│ │ └── (regenerate via: mma-mcp setup)
│ └── tools/
│ ├── __init__.py # Tool registry, ToolContext, RoleRuntime, RBAC wrapper
│ └── evaluate.py # evaluate (text) / evaluate_image (PNG)
├── tests/
│ ├── test_security.py # Filter + registry unit tests
│ ├── test_config.py # Config loading/validation tests
│ ├── test_auth.py # Auth + OAuth + password tests
│ ├── test_tools.py # Tool registry + RBAC + session isolation tests
│ ├── test_cli.py # CLI subcommand unit tests
│ ├── test_integration.py # Real kernel integration tests
│ └── test_mcp_e2e.py # Full MCP protocol end-to-end tests
├── scripts/
│ └── generate_groups.wl # Pure WL alternative for group generation
├── pyproject.toml
├── CLAUDE.md
├── LICENSE # MIT License
├── README.md # English README
├── README-cn.md # Chinese README
├── ARCHITECTURE.md # Architecture documentation (English)
├── ARCHITECTURE-cn.md # Architecture documentation (Chinese)
├── DEPLOY.md # HTTPS deployment guide (English)
├── DEPLOY-cn.md # HTTPS deployment guide (Chinese)
├── CONTRIBUTING.md # Contributing guide (English)
├── CONTRIBUTING-cn.md # Contributing guide (Chinese)
├── SECURITY.md # Security policy (English)
└── SECURITY-cn.md # Security policy (Chinese)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 174 lines · 2,190 tokens per session scan A c3a8948df581
mma-mcp CLAUDE.md is an instructions file published in the GitHub repository siqiliu-tsinghua/mma-mcp (32 stars, last pushed 1mo ago), licensed MIT. It adds 2,190 tokens to every session, about $0.0110 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).