Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/codesstar/loci/loci-scangit clone --depth 1 https://github.com/codesstar/lociWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00492 |
| Opus 5 | $0.00000 | $0.00246 |
| Sonnet 5 | $0.00000 | $0.00098 |
| Haiku 4.5 | $0.00000 | $0.00049 |
Grade A, and why
loci-scan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Refresh the current project's local Loci memory.
This command updates the project repo's .loci/memory.md, .loci/profile.md, and .loci/progress/YYYY-MM.md according to their roles. Loci aggregates memory; it does not own it, so the brain keeps only a one-line index in projects/index.md.
Steps:
-
Check connection: Read
.loci/memory.mdin current directory. If not found, offer once at the end of the exchange: "这个项目还没有本地记忆。要不要我帮你在这里留个记忆?" If the user says yes, follow the "Connecting a serious project" rule in the main instructions. -
Get brain path from
.loci/memory.mdfrontmatter (brain: ...) and locate the brain index at<brain>/projects/index.md. -
Refresh the local project memory from the repo:
- Read identity files (CLAUDE.md, README.md, package.json/pyproject.toml/etc., .git/config, LICENSE)
- Scan directory skeleton (tree -L 2)
- Extract structured data deterministically
- Generate AI one-line summary
- Never read .env, secrets, node_modules, build outputs, or private credentials
-
Compare with existing
.loci/memory.md:- Show what changed (e.g. "Tech stack updated: added Prisma", "Scale changed: medium → large")
- Preserve user-written Goal / Current State / Now / Next unless the change is clear
- Append project progress to
.loci/progress/YYYY-MM.md - Put stable attributes in
.loci/profile.md
-
Write updated
.loci/memory.md,.loci/profile.md, and.loci/progress/YYYY-MM.mdas needed -
Update brain index only if needed: If the one-line essence or status changed, update the project's entry in
projects/index.md. Do not copy the full project memory into the brain. -
Confirm: Show summary of changes or "Project memory is up to date, no changes detected."
Flags
--all: Run from brain directory to review projects listed inprojects/index.md. Only open repos that are relevant or explicitly requested. Shows a summary table at the end.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 33 lines · 0 tokens per session scan A 0d29aecbfb52
loci-scan is a command published in the GitHub repository codesstar/loci (99 stars, last pushed 3d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 492 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
release-note-csoar
Automates the creation of Cloud SOAR (Automation Service) release notes for platform updates, integration changes, and bug fixes.
doc
Use this command to create a new feature doc, how-to, concept, reference, or troubleshooting guide — it scaffolds the file, frontmatter, structure, and sidebar entry.
wf-ads
Generate 50-100 ad copy variants from pain point research, then create renderable ad images.
claude-tracker
List and browse your saved Claude Code sessions with status (running/inactive/VS Code).
oss
Daily OSS contribution check - uses CLI with --json for structured data.
doncheli-status
Show current project status — phase, progress, coverage, gates.