Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/irisxc4/memoryguard/memoryguard-local-opsnpx skills add irisxc4/memoryguard --skill memoryguard-local-opsgit clone --depth 1 https://github.com/irisxc4/memoryguardWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00051 | $0.02025 |
| Opus 5 | $0.00026 | $0.01012 |
| Sonnet 5 | $0.00010 | $0.00405 |
| Haiku 4.5 | $0.00005 | $0.00202 |
Grade A, and why
memoryguard-local-ops scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 226 lines — stays where its author put it; the contents beside it link to each section on GitHub.
MemoryGuard local operations
Use this skill for the repository's agent-memguard package (the current
checkout declares version 0.7.8). Scope is local Windows installation,
configuration, repair, diagnostics, and governed memory operations.
This is a skills-only plugin. It does not bundle agent-memguard, add a
remote MCP server, or silently edit a user's host configuration. Run commands
only when the user asked for the corresponding operation; use read-only checks
first when diagnosing.
Windows install
-
Check the interpreter and package manager:
py -3 --version py -3 -m pip --version py -3 -c "import sys; print(sys.executable)"agent-memguardrequires Python 3.10 or newer. If thepylauncher is not available, usepythonconsistently and verify that it resolves to the interpreter that will run the MCP process. -
Install or upgrade the PyPI package:
py -3 -m pip install --upgrade agent-memguardThe optional desktop console is a separate extra:
py -3 -m pip install --upgrade "agent-memguard[gui]"For a source checkout, use a non-editable install (
py -3 -m pip install .). Do not point a live Codex MCP process atsrcor usepip install -eas its runtime. The provider installer can select or build a content-keyed, non-editable runtime snapshot when it detects a local/editable install. -
Verify the exact interpreter and package:
memoryguard --version py -3 -c "import importlib.metadata as m; print(m.version('agent-memguard'))" py -3 -m memoryguard.mcp_server --help memoryguard doctorIf
memoryguardresolves to another Python installation, use that interpreter's console-script path or repairPATH; do not assume that a successfulpipcommand configured Codex.
Codex configuration
Preferred provider path
If the MemoryGuard MCP tools are already available, call:
memoryguard_provider_install(provider="codex")
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 226 lines · 51 tokens per session scan A 0f058465caa4
memoryguard-local-ops is a skill published in the GitHub repository irisxc4/memoryguard (2 stars, last pushed 2d ago), licensed MIT. It adds 51 tokens to every session and 2,025 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
brain-page
Operating manual for reading and writing a project's brain — every read and write goes through the bundled zero-dependency brain CLI; never hand-edit brain files. Read it before creating or modifying any page or root page.
brain-bootstrap
Seed a freshly-scaffolded brain with real project knowledge — on an existing (brownfield) project read the code, docs, and git log to draft the six root pages and capture key historical decisions; on a near-empty (greenfield) project interview the user. Every write goes through the brain CLI. Run it after brain-setup.
brain-ingest
The process for digesting a conversation, document, or research result, classifying it, and writing it down as brain content (a root-page update or a new/updated page) through the brain CLI.
brain-setup
Bootstrap the Open Project Brain Standard into the current project — prefer brain init (ensure BRAIN.md, scaffold empty brain brainRoot-aware, default-wire CLAUDE.md + AGENTS.md). Optionally install a pre-commit hook and a Claude Code SessionStart hook.
c-03-repo-bootstrap
Bootstrap onboarding for undocumented repos or existing memory slices. Builds root overviews, route-local overview pillars, evidence packs, file cards, onboarding waves, deleted-slice cleanup, curator reviews, and handoff while keeping the orchestrator thin.
c-12-closeout
Close out approved Agents Remember edits by preserving approval authority, mandatory strict code quality before code commit, missing-onboarding checks, external-memory refresh, memory quality, ledger alignment, and no automatic push.