Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/devzonayed/mochi/comms-setupgit clone --depth 1 https://github.com/DevZonayed/MochiWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00027 | $0.00668 |
| Opus 5 | $0.00014 | $0.00334 |
| Sonnet 5 | $0.00005 | $0.00134 |
| Haiku 4.5 | $0.00003 | $0.00067 |
Grade A, and why
comms-setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Onboard a communication channel for THIS repo. The provider defaults to whatsapp. Drive the mcp__plugin_mochi_comms__* tools; do not shell out.
1. ToS warning + consent (required gate). Tell the user verbatim, then wait for a yes:
This uses an unofficial WhatsApp connection. It violates WhatsApp's ToS and the number can be banned, sometimes within weeks. Use a non-primary number. Proceed?
If they decline, stop and write nothing.
2. Start login. Call comms_link_account({provider, accountId, phone?}).
accountIdis a short label the user picks (e.g.work). Ask if unspecified.- If the user gives a
phone, you get an 8-char pairing code (requested once — never loop on 429). - Otherwise you get a QR (PNG data-URL + ASCII). Show the ASCII QR for the user to scan.
3. Wait for connection. Poll comms_account_status({provider, accountId}) until connected. The first connect may trigger an internal 515 restart — keep polling a few times before giving up.
4. Pick chats for this repo. Call comms_list_groups and comms_list_chats, present them, and let the user choose which chats/groups this repo should sync. Only chosen chats are ever captured (strict allowlist).
5. Save the allowlist. Call comms_set_allowlist({provider, accountId, allowed_jids}). This merges into the allowlist and flips config to decided:true, declined:false. History for newly-allowlisted chats is best-effort: WhatsApp ships whatever it syncs at login, and you can backfill older history later via /mochi:comms-import.
Privacy note: allowlisted phone/group JIDs are written to
.continuum/comms/config.json, which is committed to git (and lands in your repo's history). For a private allowlist, put the JIDs in.continuum/comms/config.local.jsoninstead — it is gitignored and wins on merge.
6. Initial sync. Call comms_sync_now({provider, accountId}). Then offer /mochi:comms-import for older history WhatsApp didn't ship at login.
Report a concise summary (account, linked status, chats synced). Do not dump message bodies.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 30 lines · 0 tokens per session scan A d1ff06e5c8d5
comms-setup is a command published in the GitHub repository DevZonayed/Mochi (3 stars, last pushed 15d ago), licensed MIT. It adds 27 tokens to every session and 668 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
toon
A lightweight data format designed to minimize token usage when passing structured data to LLMs.
browse
You have access to a browser via the MCP Browser Bridge tools. Use them to interact with web pages.
computer
Control the macOS desktop — move mouse, click, type, press keys, scroll, drag, take screenshots, list windows/displays, clipboard. Uses usecomputer CLI for native Quartz event automation.
autoresearch
Autonomous research loop — iteratively edit, test, measure, keep/discard. Usage: /autoresearch [--budget 5m] [--provider ark].
gitlab-scrum
GitLab Scrum management - create/manage issues, labels, milestones, and boards. Use when user says: create issue, list issues, move issue, add label, scrum, kanban, backlog, or task tracking.
web-setup
Guide users through Chrome extension setup for browser control. Use when user asks about setup, installing the extension, connecting Chrome, or when browsercontrol tools return 'No browser connected'.