Borrowing it
Nothing to install: this file belongs to plural-pinelabs/pinelabs-online-mcp. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/plural-pinelabs/pinelabs-online-mcp/main/.claude/settings.jsongit clone --depth 1 https://github.com/plural-pinelabs/pinelabs-online-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/settings/plural-pinelabs/pinelabs-online-mcp/settings)<a href="https://agentmods.dev/settings/plural-pinelabs/pinelabs-online-mcp/settings"><img src="https://agentmods.dev/badge/settings/plural-pinelabs/pinelabs-online-mcp/settings/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/settings/plural-pinelabs/pinelabs-online-mcp/settings"><img src="https://agentmods.dev/badge/settings/plural-pinelabs/pinelabs-online-mcp/settings.svg" alt="Reviewed on agentmods" width="80" height="20"></a>Grade A, and why
settings scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"projectContext": "Pine Labs MCP Server — Python async MCP server wrapping Pine Labs payment APIs using FastMCP, httpx, and Pydantic v2. Stdio transport only.",
"codeStyle": {
"language": "python",
"minVersion": "3.10",
"importOrder": ["stdlib", "third-party", "pkg.*"],
"asyncFirst": true,
"formatter": "ruff",
"linter": "ruff"
},
"conventions": [
"Tool handlers are async functions returning JSON strings",
"Use validate_resource_id() and validate_path_param() for input validation",
"Use api_error_response() and unexpected_error_response() for error returns",
"One tool file per resource at pkg/pinelabs/{resource}.py",
"Registration function pattern: register_{resource}_tools(mcp, client)",
"Tests use fake_mcp and mock_client fixtures from conftest.py",
"No Redis, no metrics, no tracing, no HTTP server"
],
"keyFiles": {
"entryPoint": "cli/pinelabs_mcp_server/main.py",
"client": "pkg/pinelabs/client.py",
"config": "pkg/pinelabs/config.py",
"serverFactory": "pkg/pinelabs/server.py",
"toolRegistration": "pkg/pinelabs/tools.py",
"validators": "pkg/pinelabs/utils/validators.py",
"errors": "pkg/pinelabs/utils/errors.py",
"testFixtures": "tests/conftest.py"
},
"commands": {
"test": "make test",
"format": "make fmt",
"lint": "make lint",
"run": "python -m cli.pinelabs_mcp_server.main stdio"
}
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 37 lines scan A 6e260413e727
settings is a settings file published in the GitHub repository plural-pinelabs/pinelabs-online-mcp (1 stars, last pushed 1mo ago), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other settings, from other repositories
supabase
Agent settings declaring 2 hook events (SessionStart, PostToolUse).
superset
Agent settings declaring 1 hook event (PreToolUse).
RuView
Agent settings declaring 8 hook events (PreToolUse, PostToolUse, UserPromptSubmit, SessionStart) and 4 allowed tools.
orm
Agent settings declaring 4 hook events (PreToolUse, PostToolUse, WorktreeCreate, Stop) and 21 allowed tools.
claude-cookbooks
Agent settings declaring 2 hook events (SessionStart, PreToolUse).
claude-code-best-practice
Agent settings declaring 30 hook events (PreToolUse, PermissionRequest, PostToolUse, PostToolUseFailure) and 24 allowed tools.