Borrowing it
Nothing to install: this file belongs to marcelopaniza/mempenny. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/marcelopaniza/mempenny/main/.opencode/commands/mempenny-memory-apply.mdgit clone --depth 1 https://github.com/marcelopaniza/mempennyWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/marcelopaniza/mempenny/mempenny-memory-apply)<a href="https://agentmods.dev/commands/marcelopaniza/mempenny/mempenny-memory-apply"><img src="https://agentmods.dev/badge/commands/marcelopaniza/mempenny/mempenny-memory-apply/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/marcelopaniza/mempenny/mempenny-memory-apply"><img src="https://agentmods.dev/badge/commands/marcelopaniza/mempenny/mempenny-memory-apply.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00030 | $0.00529 |
| Opus 5 | $0.00015 | $0.00264 |
| Sonnet 5 | $0.00006 | $0.00106 |
| Haiku 4.5 | $0.00003 | $0.00053 |
Grade A, and why
mempenny-memory-apply scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
MemPenny memory-apply — opencode host adapter
The user invoked this command with: $ARGUMENTS
Execute the MemPenny memory-apply flow. The canonical procedure lives in:
${MEMPENNY_ROOT}/commands/memory-apply.md
Read it first with the Read tool — it is the single source of truth for the backup-first discipline, the rollback-on-failure contract, the table-path validation (H3), and the filename-injection guard (H1). This file only describes the opencode host differences.
Apply these opencode host adaptations (override the source wherever they conflict):
A. Paths & environment
The env shim sets MEMPENNY_HOST=opencode, MEMPENNY_ROOT, MEMPENNY_DATA_DIR. Substitute:
${CLAUDE_PLUGIN_ROOT}→${MEMPENNY_ROOT}${CLAUDE_PLUGIN_DATA}→${MEMPENNY_DATA_DIR}${CLAUDE_PROJECT_DIR}→ the current working directory
B. Config path (shared with Claude Code)
${MEMPENNY_CONFIG_PATH}if set.- Else
~/.claude/mempenny.config.jsonif~/.claude/exists. - Else
~/.config/opencode/mempenny.config.json.
C. Subagents (opencode Task tool)
Where the source spawns subagent_type: general-purpose for the isolated apply, use opencode's subagent_type: "general" (write-capable), lowercase, with description + prompt. The "separately-spawned subagent with no memory of the proposal step" property is load-bearing (it is what makes apply safe against prompt injection in the source content) — preserve it: spawn a fresh subagent, do not apply inline in the triage context.
D. Command namespace
Sibling commands use the hyphen namespace.
apply-specific notes
- The table path is the first positional arg (required);
--dir/--langparse from$ARGUMENTS. - The H3 path validation (C1 regex +
realpath+ exists + not-a-symlink) and the F-M1 permission sanity checks carry over verbatim — re-implement them in the apply context exactly as written.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 39 lines · 30 tokens per session scan A a8485e875733
mempenny-memory-apply is a command published in the GitHub repository marcelopaniza/mempenny (2 stars, last pushed 20d ago), licensed MIT. It adds 30 tokens to every session and 529 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
remember
Stores decisions, patterns, and outcomes in the MCP memory knowledge graph as entities with typed observations and relations. Supports recording architectural decisions, anti-patterns, tool preferences, workflow outcomes, and project conventions that persist across sessions. Use when saving patterns, remembering…
memory
Unified read-side memory operations including knowledge graph search, session context loading, decision timeline viewing, and Mermaid graph visualization. Subcommands: search, load, history, viz, status. Complements /ork:remember (write-side). Use when searching past decisions, loading context, or visualizing the…
mempalace-init
Set up MemPalace — install the package, initialize a palace, register the MCP server with Cursor, and verify everything works.
mempalace-status
Show the current state of your memory palace — wings, rooms, drawer counts, and suggestions.
ingest
Ingest source material into an active wiki. Accepts URLs, file paths, PDFs, freeform text, or processes the inbox. Supports tweets via Grok MCP.
design-import
Scaffolds React components from a Claude Design handoff bundle and stops at files on disk: no stories, no tests, no pull request. Use when handed a claude.ai/design URL or a local bundle file; when that same scaffold should carry on through test generation, browser verification and an opened PR, run /ork:design-ship…