Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/teehooai/spidershield/claude-mdgit clone --depth 1 https://github.com/teehooai/spidershieldWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/teehooai/spidershield/claude-md)<a href="https://agentmods.dev/instructions/teehooai/spidershield/claude-md"><img src="https://agentmods.dev/badge/instructions/teehooai/spidershield/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.02134 | $0.02134 |
| Opus 5 | $0.01067 | $0.01067 |
| Sonnet 5 | $0.00427 | $0.00427 |
| Haiku 4.5 | $0.00213 | $0.00213 |
Grade A, and why
spidershield CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 165 lines — stays where its author put it; the contents beside it link to each section on GitHub.
SpiderShield -- MCP Server Security Linter
Project Overview
SpiderShield is a static analysis tool for MCP (Model Context Protocol) servers. It scans tool descriptions, security patterns, architecture quality, and licensing. Think "npm audit for MCP tools".
Architecture
src/spidershield/
cli.py -- Click CLI entry point (thin orchestrator)
commands/ -- CLI command modules (scan, rewrite, harden, eval, agent, dataset, guard, policy, audit)
models.py -- Pydantic V2 models (ScanReport, SecurityIssue, etc.)
server.py -- MCP server mode (scan_mcp_server tool)
spiderrating.py -- SpiderRating format conversion (metadata, grades)
scanner/
runner.py -- Orchestrates 4-stage scan pipeline + metadata emission
description_quality.py -- Tool description scoring (7 criteria)
security_scan.py -- Static security pattern matching
architecture_check.py -- Code quality checks
license_check.py -- License detection
dataset/
db.py -- SQLite schema v5, migration, get_stats
collector.py -- Best-effort recording (scans, rewrites, PRs, agent, guard)
agent/
scanner.py -- Agent config security audit
skill_scanner.py -- Skill malware/injection pattern matching (20 patterns)
toxic_flow.py -- Dangerous capability combination detection (keyword + AST)
pinning.py -- SHA-256 content pinning for rug-pull detection
allowlist.py -- Approved-only skills enforcement
sarif.py -- SARIF output for agent findings
models.py -- Finding, SkillFinding, ScanResult, AuditFramework
issue_codes.py -- TS-E/W/C/P code registry
rewriter/
runner.py -- Template + LLM description rewriter
cache.py -- SHA-256 keyed LLM rewrite cache
providers.py -- Anthropic / OpenAI / Gemini providers
hardener/runner.py -- Security fix suggestions
evaluator/runner.py -- Tool selection accuracy testing
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 165 lines · 2,134 tokens per session scan A 75c055816cc7
spidershield CLAUDE.md is an instructions file published in the GitHub repository teehooai/spidershield (10 stars, last pushed 4mo ago), licensed MIT. It adds 2,134 tokens to every session, about $0.0107 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
mcp AGENTS.md
AGENTS.md instructions for Teamwork/mcp, covering agents.md, this repository is public, project overview, setup commands and build and run.
raindrop-mcp AGENTS.md
Instructions for adeze/raindrop-mcp, covering raindrop mcp — codex guide, commands, architecture, non-negotiable contracts and codex workflow.
raindrop-mcp mcp-inspector.instructions.md
Instructions for adeze/raindrop-mcp, covering mcp inspector cli prompt, prerequisites, usage examples, list available tools and send a protocol request (e.g., ping).
raindrop-mcp GEMINI.md
Instructions for adeze/raindrop-mcp, covering raindrop mcp server - project context, project overview, core technologies, architecture and key commands.
assay CLAUDE.md
Claude Code instructions for Rul1an/assay, covering assay - ai agent context, what is assay?, workspace structure, key commands and cli entry points.
assay AGENTS.md
AGENTS.md instructions for Rul1an/assay, covering assay agent contract, canonical state, adr-042/043 scope, branch and worktree ownership and development discipline.