Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/opensesh/karimo/updategit clone --depth 1 https://github.com/opensesh/KARIMOWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01454 |
| Opus 5 | $0.00000 | $0.00727 |
| Sonnet 5 | $0.00000 | $0.00291 |
| Haiku 4.5 | $0.00000 | $0.00145 |
Grade A, and why
update scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- update — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 203 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/karimo:update — Update Command
Check for and apply KARIMO updates from GitHub releases.
Usage
/karimo:update # Check for updates and install if available
/karimo:update --check # Only check for updates, don't install
/karimo:update --force # Update even if already on latest version
Behavior
Step 1: Run Update Script
Execute the update script:
bash .karimo/update.sh
For check-only mode:
bash .karimo/update.sh --check
For force update:
bash .karimo/update.sh --force
Step 2: Interpret Results
The script will:
- Check current version from
.karimo/VERSION - Fetch latest release from GitHub (opensesh/KARIMO)
- Compare versions using semver
- Show what will be updated (if update available)
- Apply updates after user confirmation
Step 3: Check Config Version & Run Migrations
After update script completes successfully, check if config migration is needed:
# Get current config version
if [ -f .karimo/config.yaml ]; then
config_version=$(grep -E "^config_version:" .karimo/config.yaml | sed 's/.*"\(.*\)".*/\1/' || echo "unknown")
else
echo "Warning: No config.yaml found, skipping migrations"
config_version="unknown"
fi
# Get latest KARIMO version (should match updated VERSION file)
karimo_version=$(cat .karimo/VERSION)
echo "Config version: $config_version"
echo "KARIMO version: $karimo_version"
# Determine if migration needed
if [ "$config_version" != "unknown" ] && [ "$config_version" != "$karimo_version" ]; then
echo
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
echo "Config Migration Required"
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
echo "Your config: v$config_version"
echo "Latest KARIMO: v$karimo_version"
echo
# Check for migration scripts
migration_count=0
for script in .karimo/migrations/v*.sh; do
if [ -f "$script" ] && [ -x "$script" ]; then
# Extract version numbers from script name (e.g., v1-to-v2.sh)
script_name=$(basename "$script")
if [[ "$script_name" =~ v([0-9.]+)-to-v([0-9.]+) ]]; then
from_ver="${BASH_REMATCH[1]}"
to_ver="${BASH_REMATCH[2]}"
# Check if this migration applies to current config
if [ "$config_version" = "$from_ver" ]; then
echo "Running migration: $script_name"
echo " From: v$from_ver"
echo " To: v$to_ver"
echo
# Run migration
if bash "$script" .karimo/config.yaml; then
echo "✓ Migration succeeded: v$from_ver → v$to_ver"
echo
config_version="$to_ver" # Update for next migration
migration_count=$((migration_count + 1))
else
echo "✗ Migration failed: $script_name"
echo
echo "Error: Config migration failed. Please review the error above."
echo "Your config has been backed up to: .karimo/config.yaml.backup-*"
echo
exit 1
fi
fi
fi
fi
done
if [ $migration_count -eq 0 ]; then
echo "No migrations found for v$config_version → v$karimo_version"
echo
echo "Manual migration may be required. See:"
echo " .karimo/migrations/README.md"
echo
else
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
echo "✓ Applied $migration_count migration(s)"
echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"
echo
fi
elif [ "$config_version" = "$karimo_version" ]; then
echo "Config is up to date (v$config_version)"
fi
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 203 lines · 0 tokens per session scan A 4f4d07ca4139
update is a command published in the GitHub repository opensesh/KARIMO (283 stars, last pushed 3mo ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 1,454 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
run
Execute an approved PRD using feature branch workflow (v7.0). This command generates briefs, auto-reviews them, allows user iteration, and then orchestrates execution.
create-plugin
Guided end-to-end plugin creation workflow with component design, implementation, and validation.
test-mcp
Test MCP server connection and all tools.
audit-components
Scan all feature components against the 7 architecture principles in .claude/reference/react-architecture.md, produce a structured report with pass/fail per check, and output a prioritized fix plan.
audit-devprops
Scan the codebase for devProps compliance and produce a structured report grouped by section, with a percentage summary and an explicit exemption list.
feature-dev
Guided feature development with design-first thinking and systematic architecture.