Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/jketreno/clare/skill-mcp-servergit clone --depth 1 https://github.com/jketreno/clareWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/jketreno/clare/skill-mcp-server)<a href="https://agentmods.dev/rules/jketreno/clare/skill-mcp-server"><img src="https://agentmods.dev/badge/rules/jketreno/clare/skill-mcp-server.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00008 | $0.02860 |
| Opus 5 | $0.00004 | $0.01430 |
| Sonnet 5 | $0.00002 | $0.00572 |
| Haiku 4.5 | $0.00001 | $0.00286 |
Grade A, and why
skill-mcp-server scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Runs shell commandslowCapability
Expected in a hook, worth knowing in a rule or an instructions file.
import { execSync } from 'child_process'; How it starts
The opening of the file, as written. The whole thing — 368 lines — stays where its author put it; the contents beside it link to each section on GitHub.
name: mcp-server description: "Scaffold an MCP server exposing CLARE verify and autonomy-check tools" mode: agent
CLARE MCP Server
What this skill does: Scaffolds a minimal MCP (Model Context Protocol) server that exposes CLARE's enforcement primitives —
verify-ci.shandautonomy.yml— as typed tool calls. Any MCP-compatible agent or orchestrator can then call CLARE tools without needing bash access or CLARE-specific prompt engineering.When to use: When running multi-agent pipelines, headless agents, or any workflow where you need CLARE enforcement available as a structured tool rather than a bash script.
Output: A
mcp/directory containing a runnable MCP server + registration instructions.
Context
CLARE's two core enforcement primitives are:
clare/verify-ci.sh— runs all CI checks, exits non-zero on failureclare/autonomy.yml— YAML file mapping file paths to autonomy levels
This skill exposes them as three MCP tools:
| Tool | Input | Output |
|---|---|---|
clare_verify |
(none) | {status, passed[], failed[{check, output}], summary} |
clare_check_autonomy |
{path: string} |
{path, matched_rule, level, reason} |
clare_list_humans_only |
(none) | {humans_only_paths: string[]} |
Instructions
When this skill is invoked, generate a CLARE MCP server for the current project.
Step 1: Detect the project runtime
Check for package.json → generate Node.js server.
Check for pyproject.toml or requirements.txt → generate Python server.
If both exist, ask the user which runtime to use.
If neither, default to Node.js.
Step 2: Scaffold the server
For Node.js — create mcp/clare-server.js:
#!/usr/bin/env node
// @generated — regenerate from clare/templates/skills/mcp-server.md, do not hand-edit
//
// CLARE MCP Server
// Exposes CLARE enforcement primitives as MCP tool calls.
// See docs/agentic.md for usage in multi-agent pipelines.
import { Server } from '@modelcontextprotocol/sdk/server/index.js';
import { StdioServerTransport } from '@modelcontextprotocol/sdk/server/stdio.js';
import { CallToolRequestSchema, ListToolsRequestSchema } from '@modelcontextprotocol/sdk/types.js';
import { execSync } from 'child_process';
import { readFileSync } from 'fs';
import { resolve, dirname } from 'path';
import { fileURLToPath } from 'url';
import yaml from 'js-yaml';
const __dirname = dirname(fileURLToPath(import.meta.url));
const PROJECT_ROOT = resolve(__dirname, '..');
const server = new Server(
{ name: 'clare', version: '1.0.0' },
{ capabilities: { tools: {} } }
);
server.setRequestHandler(ListToolsRequestSchema, async () => ({
tools: [
{
name: 'clare_verify',
description: 'Run clare/verify-ci.sh and return structured pass/fail results. Call this after any code generation before reporting work complete.',
inputSchema: { type: 'object', properties: {}, required: [] }
},
{
name: 'clare_check_autonomy',
description: 'Look up the autonomy level for a file path in clare/autonomy.yml. Call this before modifying any file.',
inputSchema: {
type: 'object',
properties: {
path: { type: 'string', description: 'File path relative to project root' }
},
required: ['path']
}
},
{
name: 'clare_list_humans_only',
description: 'List all humans-only paths from clare/autonomy.yml. Call this as a pre-flight check before delegating tasks to sub-agents.',
inputSchema: { type: 'object', properties: {}, required: [] }
}
]
}));
server.setRequestHandler(CallToolRequestSchema, async (request) => {
const { name, arguments: args } = request.params;
if (name === 'clare_verify') {
try {
const output = execSync(`${PROJECT_ROOT}/clare/verify-ci.sh`, {
cwd: PROJECT_ROOT,
encoding: 'utf8',
stdio: ['pipe', 'pipe', 'pipe']
});
return {
content: [{ type: 'text', text: JSON.stringify({ status: 'passed', output, summary: 'All checks passed' }) }]
};
} catch (err) {
const output = err.stdout + err.stderr;
const failedChecks = (output.match(/❌ (.+)/g) || []).map(l => l.replace('❌ ', '').trim());
return {
content: [{ type: 'text', text: JSON.stringify({ status: 'failed', failed: failedChecks, output, summary: `${failedChecks.length} check(s) failed` }) }]
};
}
}
if (name === 'clare_check_autonomy') {
const targetPath = args.path;
const autonomyFile = readFileSync(`${PROJECT_ROOT}/clare/autonomy.yml`, 'utf8');
const autonomy = yaml.load(autonomyFile);
const modules = autonomy.modules || [];
let matched = modules.find(m => m.path !== '*' && targetPath.startsWith(m.path));
if (!matched) matched = modules.find(m => m.path === '*');
return {
content: [{
type: 'text',
text: JSON.stringify({
path: targetPath,
matched_rule: matched?.path || 'none',
level: matched?.level || 'unknown',
reason: matched?.reason || ''
})
}]
};
}
if (name === 'clare_list_humans_only') {
const autonomyFile = readFileSync(`${PROJECT_ROOT}/clare/autonomy.yml`, 'utf8');
const autonomy = yaml.load(autonomyFile);
const humansOnly = (autonomy.modules || [])
.filter(m => m.level === 'humans-only')
.map(m => m.path);
return {
content: [{ type: 'text', text: JSON.stringify({ humans_only_paths: humansOnly }) }]
};
}
throw new Error(`Unknown tool: ${name}`);
});
const transport = new StdioServerTransport();
await server.connect(transport);
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 368 lines · 8 tokens per session scan A 31922b0fbbd1
skill-mcp-server is a cursor rule published in the GitHub repository jketreno/clare (5 stars, last pushed 1mo ago), licensed MIT. It adds 8 tokens to every session and 2,860 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 1 finding (runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.
control-plane-descriptors
Control plane descriptor and instance implementation patterns.
family-instance-domain-actions
Family instance domain action implementation patterns.