Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/joncovington/meicagent/setupgit clone --depth 1 https://github.com/joncovington/MEICAgentWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00588 |
| Opus 5 | $0.00000 | $0.00294 |
| Sonnet 5 | $0.00000 | $0.00118 |
| Haiku 4.5 | $0.00000 | $0.00059 |
Grade A, and why
setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 75 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Set up MEICAgent credentials and verify the broker connection.
Step 1 — Check current credential status
python src/tt.py secrets_status
Report which secrets are set and which are missing. The two required secrets are client_secret and refresh_token. account_number is optional (the SDK discovers accounts automatically if omitted).
Step 2 — Set missing credentials
If any required secrets are missing, instruct the user to run this command in their own terminal (not here — getpass requires interactive input):
python src/tt.py secrets_set
This prompts for each credential with hidden input (no echo) and stores them in the OS keyring (Windows Credential Manager / macOS Keychain / Linux Secret Service). Existing values are preserved if the user presses Enter without typing.
To update a single key only:
python src/tt.py secrets_set --keys refresh_token
Tell the user: credentials are stored under service name meicagent in the OS keyring. secrets_set/get_secret also fall back to reading the older tastytrade-mcp service name (read-only) so anyone with credentials already stored under it don't need to re-enter them — new writes always go to meicagent.
Step 3 — Verify connection
After the user confirms credentials are set, test the broker connection:
python src/tt.py get_connection_status
A successful response includes "ok": true and account details. If it fails:
401 Unauthorized: refresh token is expired — the user needs to re-authenticate via tastytrade and obtain a new refresh tokenNoKeyringError: no keyring backend — on Linux, installpython3-keyringorgnome-keyringCredentialError: keyring read failure — check OS keyring permissions
Step 4 — Verify account access
python src/tt.py get_account_info
Confirm buying power and NLV are visible. If the wrong account appears, set the explicit account number:
python src/tt.py secrets_set --keys account_number
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 75 lines · 0 tokens per session scan A 24030fa999f1
setup is a command published in the GitHub repository joncovington/MEICAgent (4 stars, last pushed 1mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 588 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
scan
Universal scan — auto-detects asset class (stock / crypto / index / FX / commodity) and runs the matching protocol. With no args, regenerates scanned/INDEX.md.
ingest
Ingest new framework knowledge into docs/ and recalibrate guide/. The ONLY command authorized to write inside docs/.
help
Show available commands for this app.
discover
Run a Finviz screener aligned with the framework + current macro regime. Saves a dated candidate list to scanned/SCREENS/.
rescan
Refresh existing scan, rotating prior snapshot to archive/. Args: or "macro.
scan-earnings
Earnings setup analysis for ticker. 8-point checklist + pre-print read.