Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/jagoff/memo/memogit clone --depth 1 https://github.com/jagoff/memoWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00012 | $0.00514 |
| Opus 5 | $0.00006 | $0.00257 |
| Sonnet 5 | $0.00002 | $0.00103 |
| Haiku 4.5 | $0.00001 | $0.00051 |
Grade A, and why
memo scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
/memo
Route $ARGUMENTS to the local memo MCP server. Use MCP tools whenever
the active profile exposes them; use the isolated memo CLI for maintenance
commands that are intentionally absent from the default 13-tool agent profile.
Preflight
If MCP tools named mcp__memo__memo_* are not available, tell the user to
register memo first:
memo install-slash --client claude-code
# or only print the MCP command:
memo mcp-command --client claude-code
# other client installers:
memo install-slash --client codex
memo install-slash --client devin-desktop
Then open a new Claude Code session so the / menu and MCP tools reload.
Routing
- Empty arguments: smart-capture the actionable insight from the current turn
and call
mcp__memo__memo_save. stats: callmcp__memo__memo_statswhen available; otherwise runmemo stats.list [n]: callmcp__memo__memo_listwhen available; otherwise runmemo list --limit n.save <text>: derive a short title, type, and tags, then callmcp__memo__memo_save.get <id|prefix>: callmcp__memo__memo_get.update <id|prefix> ...: callmcp__memo__memo_updatewhen available; otherwise runmemo edit.delete <id|prefix>: ask for explicit confirmation, then callmcp__memo__memo_deletewhen available; otherwise runmemo delete --yes.reindex: callmcp__memo__memo_reindexwhen available; otherwise runmemo reindex.doctor [--gc] [--fix]: runMEMO_NONINTERACTIVE=1 memo doctor ....- Anything else: semantic search via
mcp__memo__memo_searchwithlimit=5andbody_chars=280.
Keep output compact. For search results, show score, type, title, updated date, and id prefix. For saves/updates/deletes, show the resulting id and title.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 47 lines · 12 tokens per session scan A 83799a76514a
memo is a command published in the GitHub repository jagoff/memo (16 stars, last pushed yesterday), licensed MIT. It adds 12 tokens to every session and 514 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.