Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/zircote/mcp-bundle/claude-mdgit clone --depth 1 https://github.com/zircote/mcp-bundleWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/zircote/mcp-bundle/claude-md)<a href="https://agentmods.dev/instructions/zircote/mcp-bundle/claude-md"><img src="https://agentmods.dev/badge/instructions/zircote/mcp-bundle/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00431 | $0.00431 |
| Opus 5 | $0.00216 | $0.00216 |
| Sonnet 5 | $0.00086 | $0.00086 |
| Haiku 4.5 | $0.00043 | $0.00043 |
Grade A, and why
mcp-bundle CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
mcp-bundle
Claude Code plugin for generating MCPB (MCP Bundle) packages and a reusable GitHub Actions workflow for automated MCPB packaging.
Plugin Structure
mcp-bundle/
├── .claude-plugin/
│ └── plugin.json # Plugin manifest (required)
├── skills/
│ └── mcpb/
│ └── SKILL.md # /mcp-bundle:mcpb skill
├── .github/
│ └── workflows/
│ └── mcp-bundle.yml # Reusable workflow for CI/CD packaging
├── action.yml # GitHub Actions Marketplace composite action
├── examples/ # Example caller workflows
├── tests/ # Validation and test scripts
├── CLAUDE.md # This file
├── LICENSE # MIT
└── README.md # Documentation
Skills
/mcp-bundle:mcpb
Generates MCPB bundle packages for MCP server projects. Detects existing MCP server implementations, generates manifest.json, creates bundle directory structure, validates against the MANIFEST.md spec, and wires in CI/CD via the reusable workflow.
Testing
Run the test suite:
./tests/test-manifest-validation.sh
Requires: bash 4+, jq. Tests validate manifest parsing, required fields, validation rules, workflow/action structure, skill content, and example presence. All 262 tests must pass before committing.
Test fixtures live in tests/fixtures/ — add new .json fixtures there for additional validation test cases.
MCPB Spec Reference
- Manifest spec version:
0.3(Node/Python/Binary),0.4(UV runtime) - Bundle format: ZIP archive with
.mcpbextension - Transport: stdio only
- Required manifest fields:
manifest_version,name,version,description,author,server - Server types:
node,python,binary,uv
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 49 lines · 431 tokens per session scan A eae77bef3cb4
mcp-bundle CLAUDE.md is an instructions file published in the GitHub repository zircote/mcp-bundle (3 stars, last pushed 5mo ago), licensed MIT. It adds 431 tokens to every session, about $0.0022 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
local-ci CLAUDE.md
Claude Code instructions for redwoodjs/local-ci, covering local ci — agent instructions, rules, ci and code.
local-ci AGENTS.md
AGENTS.md instructions for redwoodjs/local-ci, a project described as: Run GitHub Actions locally — pause on failure, retry in place, and keep caches on your machine.
dev3000 AGENTS.md
Instructions for vercel-labs/dev3000, covering agents.md, runtime, local ui, production workflows, browser tools and development rules.
jenkins-cli CLAUDE.md
Instructions for avivsinai/jenkins-cli, covering claude.md, build & test commands, run a single test, skip e2e tests during unit testing and e2e with colima on macos (if docker is unreachable).
ConsultMe CLAUDE.md
Instructions for Tarek-Bohdima/ConsultMe, covering claude.md, project context, common commands, module graph and conventions enforced by tooling.
shipproof AGENTS.md
Instructions for kingggg5/shipproof, covering agents.md, what this repository is, non-negotiable rules, verify before declaring done and where things live.