Borrowing it
Nothing to install: this file belongs to sweetrb/apple-photos-mcp. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/sweetrb/apple-photos-mcp/main/CLAUDE.mdgit clone --depth 1 https://github.com/sweetrb/apple-photos-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/sweetrb/apple-photos-mcp/claude-md)<a href="https://agentmods.dev/instructions/sweetrb/apple-photos-mcp/claude-md"><img src="https://agentmods.dev/badge/instructions/sweetrb/apple-photos-mcp/claude-md/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/instructions/sweetrb/apple-photos-mcp/claude-md"><img src="https://agentmods.dev/badge/instructions/sweetrb/apple-photos-mcp/claude-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.05917 | $0.05917 |
| Opus 5 | $0.02959 | $0.02959 |
| Sonnet 5 | $0.01183 | $0.01183 |
| Haiku 4.5 | $0.00592 | $0.00592 |
Grade A, and why
apple-photos-mcp CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 330 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CLAUDE.md - Apple Photos MCP Server
This file provides guidance for AI agents (Claude, etc.) when using this MCP server.
Overview
This MCP server gives AI assistants access to the macOS Apple Photos library via osxphotos — read-only by default. All operations are local — nothing leaves the user's machine. You can query the library (including by GPS radius, aesthetic score, and OCR-detected text), inspect individual photos (singly or in batches, including EXIF camera data, ML score/detected text, shared-album comments/likes, and burst siblings), read the live Photos.app selection, see photos inline via thumbnails, find exact-duplicate groups, browse the library's structure (albums, folders, keywords, persons), and export copies of photos to a directory.
Write tools exist but are gated: create-album, add-to-album,
remove-from-album, set-photo-metadata, set-keywords, set-photo-date,
and import-photos only work when the user has set
APPLE_PHOTOS_MCP_ENABLE_WRITES=1 (env or config.json + server restart).
Until then every write call returns a clear opt-in error — run doctor
first when writes matter: its writes check reports the gate state. Even
with writes enabled, nothing can delete a photo (see "Write workflow"
below).
Related Documentation
- docs/FULL-DISK-ACCESS.md — why Full Disk Access is required, how to grant it, and how to verify it. Required reading when tools fail with permission errors.
- docs/LIMITATIONS.md — what the server can and can't do (read-only, iCloud export caveats, face/album behavior, library lag).
- docs/QUERY-GUIDE.md —
queryfilter syntax in detail: accepted date forms, AND/OR combination semantics, exact-vs-substring matching, result ordering, and what is not filterable. - docs/WRITE-BACKEND.md — why reads use osxphotos (direct DB) and writes use photoscript/AppleScript, and why that split can't be collapsed (no safe DB writes; osxphotos's own writes are AppleScript; PhotoKit needs an app bundle). Read before proposing to "eliminate AppleScript" in writes.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 330 lines · 5,917 tokens per session scan A 09331946d587
apple-photos-mcp CLAUDE.md is an instructions file published in the GitHub repository sweetrb/apple-photos-mcp (20 stars, last pushed yesterday), licensed MIT. It adds 5,917 tokens to every session, about $0.0296 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.