bookstack-mcp CLAUDE.md

bookstack-mcp CLAUDE.md is an instructions file for coding agents from ttpears/bookstack-mcp. It costs 1,443 tokens per session, scanned A, original, MIT.

A set of project instructions for developing BookStack MCP Server, a TypeScript service that lets AI assistants use a BookStack wiki. MCP is a standard connection between assistants and external tools.

In plain words
What is it for?
Use it when building, type-checking, running, or changing the server and its BookStack search and page-management tools.
Why use it?
It records the project's build commands, architecture, validation rules, and compatibility details in one place.

Instructions file

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/ttpears/bookstack-mcp/claude-md
Clone the repo
git clone --depth 1 https://github.com/ttpears/bookstack-mcp

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for bookstack-mcp CLAUDE.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/ttpears/bookstack-mcp/claude-md.svg)](https://agentmods.dev/instructions/ttpears/bookstack-mcp/claude-md)
Your own site
<a href="https://agentmods.dev/instructions/ttpears/bookstack-mcp/claude-md"><img src="https://agentmods.dev/badge/instructions/ttpears/bookstack-mcp/claude-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 1,443 This file is loaded in full into every session.
When invoked 1,443 The same file — it is already loaded in full.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01443 $0.01443
Opus 5 $0.00722 $0.00722
Sonnet 5 $0.00289 $0.00289
Haiku 4.5 $0.00144 $0.00144

Measured 3d ago against content hash 632a69bbe6d8, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

bookstack-mcp CLAUDE.md scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

curl -H "Authorization: Token $BOOKSTACK_TOKEN_ID:$BOOKSTACK_TOKEN_SECRET" \
CLAUDE.md · 142 lines

How it starts

The opening of the file, as written. The whole thing — 142 lines — stays where its author put it; the contents beside it link to each section on GitHub.

CLAUDE.md

This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.

Project Overview

BookStack MCP Server — A TypeScript MCP server providing BookStack wiki integration for AI assistants. Published to npm as bookstack-mcp. Uses McpServer API with registerTool() and Zod schemas with z.coerce.number() for broad MCP client compatibility. Current version is tracked in package.json.

Build & Development Commands

npm install              # Install dependencies
npm run build           # Compile TypeScript + chmod +x dist/*.js
npm run type-check      # Type-check without emitting files
npm run dev             # Start server with hot reload (tsx)
npm start               # Run compiled server (node dist/index.js)

Architecture

Two source files in src/:

src/index.ts — MCP server entry point

  • McpServer from @modelcontextprotocol/sdk/server/mcp.js
  • Tool registration with server.registerTool()
  • Zod schemas using z.coerce.number() (accepts both 8 and "8" from clients)
  • Required ID params use .min(1) to guard against empty string coercion
  • Stdio transport
  • Write tools conditionally registered based on BOOKSTACK_ENABLE_WRITE

src/bookstack-client.ts — BookStack API wrapper

  • Axios-based HTTP client with token auth
  • Response enhancement: URLs via slugs, human-friendly dates, content previews, word counts
  • Export handling: binary formats return download URLs, text formats return content
  • Write operations gated by enableWrite flag

Configuration

Environment Variables

BOOKSTACK_BASE_URL=https://your-bookstack.com   # Required
BOOKSTACK_TOKEN_ID=your-token-id                # Required
BOOKSTACK_TOKEN_SECRET=your-token-secret        # Required
BOOKSTACK_ENABLE_WRITE=false                    # Optional
BOOKSTACK_INSECURE_SKIP_TLS_VERIFY=false        # Optional, for self-signed BookStack

TypeScript Configuration

  • Target: ES2022 with NodeNext modules/resolution
  • Output: dist/ directory
  • No source maps or declarations (CLI package, not a library)

Read the full file on GitHub · 142 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 142 lines · 1,443 tokens per session scan A 632a69bbe6d8

Subscribe to this mod's changes

bookstack-mcp CLAUDE.md is an instructions file published in the GitHub repository ttpears/bookstack-mcp (31 stars, last pushed 7d ago), licensed MIT. It adds 1,443 tokens to every session, about $0.0072 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.