Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/smorand/mcp-htmleditor/agents-mdgit clone --depth 1 https://github.com/smorand/mcp-htmleditorWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/smorand/mcp-htmleditor/agents-md)<a href="https://agentmods.dev/instructions/smorand/mcp-htmleditor/agents-md"><img src="https://agentmods.dev/badge/instructions/smorand/mcp-htmleditor/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01640 | $0.01640 |
| Opus 5 | $0.00820 | $0.00820 |
| Sonnet 5 | $0.00328 | $0.00328 |
| Haiku 4.5 | $0.00164 | $0.00164 |
Grade A, and why
mcp-htmleditor AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 107 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AGENTS.md, mcp-htmleditor
Overview
WYSIWYG HTML editor plus MCP server, with PPTX and DOCX export. LLM agents modify HTML files on disk; the browser renders them in an iframe and reloads on mtime change. Python 3.13+, uv, click, FastMCP, python-pptx, BeautifulSoup4, pandoc for DOCX.
Key commands
make is the only entry point. Never call uv, ruff, mypy or pytest directly.
make sync # uv sync (deps + dev group)
make check # GATE: lint + format-check + typecheck + security + test-cov (80 %)
make test # pytest -v (ARGS='-k pptx' for a subset)
make install # uv tool install + templates + log dir + Pi skill
make run ARGS='export pptx in.html out.pptx'
make docker-build / run-up / run-down
make bootstrap-ei # regenerate the EI bootstrap from the EI reference
make sync-medical-css # propagate the medical charter CSS to the reference decks
make help # every target
CLI (same after make install):
mcp-htmleditor --version
mcp-htmleditor templates # ei, carbon, medical, doc, doc-perso, doc-ei, mail, website
mcp-htmleditor new ei pres.html --serve
mcp-htmleditor new medical talk.html --serve
mcp-htmleditor serve file.html [-v|-q] [--host] [--port] [--poll] [--no-browser]
mcp-htmleditor mcp # MCP server (stdio)
mcp-htmleditor export pptx in.html out.pptx
mcp-htmleditor export docx in.html out.docx
mcp-htmleditor arch-layout in.html # compute arch-diagram positions from topology
mcp-htmleditor arch-checklist # print the editable arch-diagram QA checklist
mcp-htmleditor skill # full skill content
Essential conventions
- LLM workflow:
update_start()then write the HTML file thenupdate_end(). Never write the file without those flanking calls. - Configuration only through
Settingsinconfig.py(pydantic-settings,HTMLEDITOR_*). Noos.environread anywhere else. - Logging:
logger = logging.getLogger(__name__),%lazy formatting, console on stderr.click.echois for user output only. Never log on stdout: the MCP protocol and the CLI output live there. - Tracing: wrap every external call in
trace_span("category.operation", {...}). Never put document content, prompts or credentials in an attribute. data-doc-typeon<html>drives the mode,data-type="slide"needsdata-idanddata-title, document headings are semantic<h1>to<h5>.- Templates are read only through the server;
templates/bootstrap/slides-ei-empty.htmlis generated, edit the EI reference thenmake bootstrap-ei. For themedicalcharter it is the reverse: the bootstrap<style>is the source, edit it thenmake sync-medical-cssto propagate the copy into the two reference decks. - A
medicaldeck cites every third party image (non empty.med-sourcein the footer band) and anonymizes every patient image (no name, initials, MRN, care date, full date of birth; DICOM header and burned in pixels cleaned): seeskill/types/medical.md. Its flex rows (.med-strip,.med-split,.med-cols,.med-compare,.med-steps,.med-stats,.med-timeline,.med-section-figs) need an explicit width class (w-25tow-70) on every child, otherwise the PPTX export flattens the row into a vertical stack. - After editing anything under
templates/, runmake installor exportHTMLEDITOR_TEMPLATES_DIR=$PWD/templates, otherwise the installed copy wins. - Every slide template (current and future) must ship fullscreen support (
:fullscreenCSS,#btn-presentbutton,enterPresentation/exitPresentation/updateFullscreenScaleJS): see.agent_docs/html-conventions.md§ Fullscreen. A presentation file missing it (e.g. created before this convention) is a bug to patch, not a valid variant. - Architecture diagrams (
data-type="arch-diagram") with 4+ nodes or a multi-row flow: never writedata-x/data-yby hand, author the declarative topology (arch-row/arch-node/arch-col/arch-edge/arch-lane/arch-spacer) and runmcp-htmleditor arch-layout(or thelayout_arch_diagramMCP tool) to compute positions. Seeskill/types/arch-diagram.mdandsrc/mcp_htmleditor/arch_layout.py. The old manualdata-x/data-yformat stays valid for 2-3 node diagrams only. - After every
arch-layoutrun, spawn a dedicated review sub-agent againstmcp-htmleditor arch-checklistbefore considering the diagram done (protocol:skill/workflow-arch-qa.md). The checklist itself is user-editable at~/.config/mcp-htmleditor/arch-checks/arch-diagram-checklist.md, never in code. .mcp_state.jsonis written next to the edited file. It is gitignored, never commit it.- JS has no build step:
node --check src/mcp_htmleditor/static/*.js. src/mcp_htmleditor/version.pystays committed with"dev"; the build overwrites it from the git tag.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 107 lines · 1,640 tokens per session scan A 6d0b96377c82
mcp-htmleditor AGENTS.md is an instructions file published in the GitHub repository smorand/mcp-htmleditor (0 stars, last pushed 11d ago), licensed MIT. It adds 1,640 tokens to every session, about $0.0082 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
next.js AGENTS.md
Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.