why

A command that explains which earlier context records were present when an answer was produced. The ⟦rcpt:id⟧ markers identify those records.

In plain words
What is it for?
Use it to resolve receipt markers, trace their recorded context positions, and report the matching presence evidence in the required order.
Why use it?
It helps investigate whether specific stored context was available to the agent at a particular point, without claiming that the context caused the answer.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/cdeust/cortex/why
Clone the repo
git clone --depth 1 https://github.com/cdeust/Cortex
Per session 27 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 454 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00027 $0.00454
Opus 5 $0.00014 $0.00227
Sonnet 5 $0.00005 $0.00091
Haiku 4.5 $0.00003 $0.00045

Measured yesterday against content hash 2937a2719777, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

why scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

commands/why.md · 19 lines

What it actually says

Deterministic entry point for the blame path (decision 4255039, correction 6 — natural-language routing to the tool is not guaranteed; this command is).

  1. Scan the conversation context for ⟦rcpt:N⟧ markers. They sit in the header line of every memory injection block (session-start banner, auto-recall block, agent briefing, recall responses' receipt_id field).
  2. Exclude the marker that arrived with THIS prompt's own memory-injection block (the auto-recall block directly attached to the current user message). That receipt records what was injected for the current question — including it would blame the question's own context (self-pollution guard, correction 4).
  3. If the user is questioning a specific earlier answer, keep only markers that were already in context before that answer was produced.
  4. Call the why tool with the collected ids: why(receipt_ids=[...]).
  5. Present the evidence with the locked lexicon:
    • Say the memories were present in context ("présence-en-contexte") at the recorded instants and ranks. Never say a memory caused the answer — the receipts are Pearl-rung-1 evidence of presence, nothing more.
    • Order as returned (emitted_at DESC, receipt id DESC as deterministic tiebreak, then persisted rank) — recorded facts only.
    • Flag rows where superseded_by_id is set (already corrected) and rows with memory_missing: true (hard-forgotten after injection; the receipt remains valid presence evidence).
  6. If the user identifies a wrong memory among the evidence, offer to store a correcting memory with remember (the write path supersedes near-duplicates; the explicit atomic correction flow lands in tranche 4).

If no ⟦rcpt:N⟧ marker is visible in context, say so honestly: no receipt in scope means no presence evidence to resolve — do not guess or reconstruct ids.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 19 lines · 27 tokens per session scan A 2937a2719777

Subscribe to this mod's changes

why is a command published in the GitHub repository cdeust/Cortex (71 stars, last pushed 3d ago), licensed MIT. It adds 27 tokens to every session and 454 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.