one-search-mcp: Instructions file for Codex

AGENTS.md

one-search-mcp AGENTS.md is an instructions file for Codex, OpenCode from yokingma/one-search-mcp. It costs 583 tokens per session, scanned A, original, MIT.

Repository instructions for one-search-mcp, a TypeScript MCP server that searches through different providers and can use a browser to extract page content. MCP is a standard way for AI clients to call tools.

In plain words
What is it for?
Use them when adding or changing search providers, browser tasks, MCP tools, or lifecycle behavior. They guide strict TypeScript changes, required context checks, and the project’s test and issue-tracking workflow.
Why use it?
They show where startup code, public tool definitions, search providers, browser handling, and tests live. They also require preserving existing work and validating inputs at the tool boundary.

Instructions file for CodexOpenCode

Written for Codex and OpenCode: the file is AGENTS.md.

This is yokingma/one-search-mcp's own configuration. It tells Codex and OpenCode how to work on one-search-mcp itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything one-search-mcp configures →

Reuse

Borrowing it

Nothing to install: this file belongs to yokingma/one-search-mcp. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/yokingma/one-search-mcp/main/AGENTS.md
Clone the repo
git clone --depth 1 https://github.com/yokingma/one-search-mcp

Made for: Codex, OpenCode.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for one-search-mcp AGENTS.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/yokingma/one-search-mcp/agents-md.svg)](https://agentmods.dev/instructions/yokingma/one-search-mcp/agents-md)
Your own site
<a href="https://agentmods.dev/instructions/yokingma/one-search-mcp/agents-md"><img src="https://agentmods.dev/badge/instructions/yokingma/one-search-mcp/agents-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 583 This file is loaded in full into every session.
When invoked 583 The same file — it is already loaded in full.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00583 $0.00583
Opus 5 $0.00292 $0.00292
Sonnet 5 $0.00117 $0.00117
Haiku 4.5 $0.00058 $0.00058

Measured 8d ago against content hash 2991ca1628dd, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

one-search-mcp AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 40 lines

How it starts

The opening of the file, as written. The whole thing — 40 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Agent Guide

Start Here

  • Check git status --short before editing. Preserve unrelated user changes.
  • Read CONTEXT.md, CONTEXT-MAP.md, and relevant docs/adr/ files when they exist; proceed silently when they do not.
  • Track implementation work in .scratch/<feature-slug>/. Follow docs/agents/issue-tracker.md and use only the labels in docs/agents/triage-labels.md.
  • Use the vocabulary defined by the domain context. Surface conflicts with an ADR instead of silently overriding it.

Project Map

  • src/index.ts: MCP server startup, tool registration, and process cleanup.
  • src/tools.ts: public MCP tool schemas and descriptions.
  • src/search/: provider dispatch and provider implementations.
  • src/libs/agent-browser/: browser lifecycle, navigation, and content extraction.
  • test/: Vitest behavior and lifecycle coverage.

Implementation Rules

  • Keep TypeScript strict and ESM-only. Local TypeScript imports use .js extensions.
  • Treat MCP tool schemas as public API. Expose only behavior that the implementation honors, and reject removed or invalid inputs at the schema boundary.
  • Route every browser task through runBrowserTask(...); propagate the MCP request AbortSignal to browser and search operations.
  • Preserve the shared safeSearch contract: 0 off, 1 moderate, 2 strict. Map it explicitly for each provider.
  • Keep browser navigation protected by the SSRF guard. Private-network access remains opt-in through configuration.
  • one_extract preprocesses content only. Do not add prompt, schema, or model-extraction inputs unless the server gains that execution capability.
  • Do not introduce compatibility shims or undocumented configuration behavior without an explicit requirement.

Tests And Verification

  • For a behavior change or bug fix, write a failing Vitest regression test first. Test contracts rather than implementation details.
  • Run the narrowest relevant test while iterating, then run npm test, npm run lint, and npm run build before handoff when the change scope warrants it.
  • Browser lifecycle changes require coverage for cancellation, cleanup, and signal propagation. Provider changes must cover every affected dispatch branch.

Read the full file on GitHub · 40 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 40 lines · 583 tokens per session scan A 2991ca1628dd

Subscribe to this mod's changes

one-search-mcp AGENTS.md is an instructions file published in the GitHub repository yokingma/one-search-mcp (140 stars, last pushed 1mo ago), licensed MIT. It adds 583 tokens to every session, about $0.0029 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,153 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens