惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Security Blog
Microsoft Security Blog
WordPress大学
WordPress大学
S
SegmentFault 最新的问题
爱范儿
爱范儿
B
Blog RSS Feed
Last Week in AI
Last Week in AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Blog — PlanetScale
Blog — PlanetScale
Vercel News
Vercel News
Jina AI
Jina AI
aimingoo的专栏
aimingoo的专栏
I
Intezer
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Attack and Defense Labs
Attack and Defense Labs
The GitHub Blog
The GitHub Blog
小众软件
小众软件
AI
AI
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
N
News and Events Feed by Topic
腾讯CDC
D
Docker
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
罗磊的独立博客
人人都是产品经理
人人都是产品经理
W
WeLiveSecurity
N
News and Events Feed by Topic
Security Archives - TechRepublic
Security Archives - TechRepublic
C
Check Point Blog
Webroot Blog
Webroot Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
H
Help Net Security
Recorded Future
Recorded Future
H
Hacker News: Front Page
T
Troy Hunt's Blog
V
V2EX
Forbes - Security
Forbes - Security
Stack Overflow Blog
Stack Overflow Blog
The Register - Security
The Register - Security
P
Palo Alto Networks Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
博客园 - 叶小钗
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
S
Security Affairs
The Hacker News
The Hacker News
Simon Willison's Weblog
Simon Willison's Weblog
博客园 - 三生石上(FineUI控件)
B
Blog
Apple Machine Learning Research
Apple Machine Learning Research
C
Cyber Attacks, Cyber Crime and Cyber Security
D
DataBreaches.Net

Hacker News: Show HN

PurrrrrFocus: Pomodoro Timer App - App Store Workflow Engine — Multi-Step Orchestration for Bun RapidPhoto: Pro Photo Editor App - App Store GitHub - DheerG/swarms: Achieve extraordinary results with claude code across a variety of tasks SPICE simulation → oscilloscope → verification with Claude Code — Lucas Gerads Show HN: VCoding – A 5 MB native Windows IDE with no dynamic dependencies Show HN: LLMs don't hallucinate because they're bad at math, it's the format GitHub - Agent-FM/agentfm-core: AgentFM is a peer-to-peer network that turns everyday computers into a decentralized AI supercomputer. AgentFM lets you run massive AI workloads directly across a global mesh of idle CPUs and GPUs. Show HN: Tracking Top US Science Olympiad Alumni over Last 25 Years GitHub - Potarix/agent-hub: One place to talk to all your agents Show HN: Runtime security for AI agents(injection,tool abuse, data exfiltration) GitHub - dubeyKartikay/lazyspotify: Terminal Spotify client for macOS and Linux GitHub - the-banana-tool/king-louie: Easy to use GUI Personal AI Assistant. Win/Linux/Mac. Show HN I made my vacation rental bookable by AI agents–no Airbnb, 0% commission GitHub - basteez/jsf-autoreload: maven plugin to enable hot reload on jsf projects uvm32/hosts/host-gdbstub at main · ringtailsoftware/uvm32 GitHub - labsai/EDDI: Config-driven engine that turns JSON into production-grade AI agents. Multi-agent orchestration, 12+ LLM providers, MCP/A2A protocols, RAG, persistent memory, and enterprise compliance (EU AI Act, GDPR, HIPAA). Built on Quarkus. GitHub - glitchnsec/fortyone-oss: AI Executive Assistant Platform Quickstart | Alien GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. GitHub - ocrbase-hq/ocrbase: 📄 PDF/IMG ->.MD/JSON Document OCR API for PaddleOCR and GLMOCR. Self-hostable. GitHub - impactjo/home-memory: MCP server that lets your AI assistant remember everything about your home. GitHub - Sets88/dbcls: DbCls is a powerful terminal database client that supports various databases GitHub - neptun2000/heor-agent-mcp GitHub - SeanFDZ/macmind: Single-layer transformer in HyperTalk for the classic Macintosh RollQuation: Math Puzzles - Apps on Google Play GitHub - dropbox/witchcraft Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis GitHub - opentalon/opentalon: OpenTalon is an open-source platform built from the ground up in Go as a robust alternative to OpenClaw LinkedIn™ 职位抓取工具 - Chrome 应用商店 GitHub - EdoardoBambini/Agent-Armor-Iaga: AI agents are getting tool access — shell, file system, databases, APIs, secrets. But **nobody is governing what they actually do with it**. Frameworks like LangChain, CrewAI, AutoGen, and Claude Code give agents the power to execute. Agent Armor gives you the power to control, audit, and approve every single action before it happens. HN Vibes — Week 15, Apr 7–13 2026 GitHub - chojs23/ec: Easy terminal-native 3-way git mergetool vim-like workflow GitHub - SethPyle376/hiraeth: Local AWS emulator focused on fast integration testing, with SQS support, SQLite-backed state, and a debug-friendly web UI. GitHub - JakOb-dotcom/cloud-sandbox-security-analysis: Technical analysis and Proof of Concept (PoC) regarding environment variable exfiltration in containerized cloud sandboxes via side-channel data leaks. Springboards - Flint Alpha Show HN: A simpler coding agent harness GitHub - audiodude/sudomake-friends GitHub - 256thFission/mini-mythos: OSS clone of Anthropic’s Mythos harness to locate C/C++ memory vulnerabilities Show HN: OpenParallax: OS-level privilege separation for AI agent execution Hacker News Sorted - Chrome 应用商店 Show HN: How to Install Docker on Ubuntu 24.04 LTS: Complete 2026 Guide GitHub - himanshudongre/smriti GitHub - sverrirsig/claude-control: macOS desktop dashboard for monitoring and managing multiple Claude Code sessions GitHub - ory/dockertest: Write better integration tests! Dockertest helps you boot up ephermal docker images for your Go tests with minimal work. Chiral - Chrome 应用商店 Show HN: Two Claudes collaborating through shared memory on a $100 mini-PC GitHub - pmichaillat/latex-cv: Minimalist LaTeX template for academic CVs GitHub - oguzbilgic/posse: A web UI for Anthropic Managed Agents. GitHub - sshiraz/depsly: Dependency risk analysis tool for npm packages ABI Add safari/agent-harness — Safari browser automation via safari-mcp by achiya-automation · Pull Request #212 · HKUDS/CLI-Anything GitHub - Halfblood-Prince/trustcheck: Verify PyPI package attestations and improve Python supply-chain security GitHub - oguzbilgic/kern-ai: Agents that do the work and show it. GitHub - bruits/satteri: High-performance Markdown and MDX processing for the JavaScript ecosystem GitHub - tylergibbs1/feedstock: High-performance web crawler and scraper for TypeScript, powered by Bun and Playwright GitHub - Grimm67123/grimmbot: The self-improving sandboxed and open-source AI agent. With persistent memory and scheduling. GitHub - whitevanillaskies/whitebloom: Local whiteboard that blooms. GitHub - hwdsl2/docker-whisper: Docker image for a self-hosted Whisper speech-to-text server with speaker diarization and OpenAI-compatible transcription and translation APIs. Powered by faster-whisper. Supports all Whisper models, NVIDIA GPU (CUDA) acceleration, JSON/SRT/VTT output, SSE streaming, offline mode, and multi-arch (amd64, arm64). GitHub - yisding/reviewwiggum GitHub - MarwanAlsoltany/serrors: Structured errors for Go: sentinel hierarchies, typed data, custom formatting, and slog integration. GitHub - soatok/age-php GitHub - Luthiraa/markitme GitHub - stagas/rtdiff: realtime git diff gui and AI-assisted commits GitHub - tombedor/excalicharts GitHub - wh1le/excalidraw-edit: Open and edit .excalidraw files from the terminal. Offline, auto-saves to disk. MalExt Sentry - Malicious Extension Scanner - Chrome 应用商店 GitHub - syi0808/asciianimesvg: Generate animated ASCII art SVGs from text. CLI, Rust library, WASM, and web editor. GitHub - zaina-ml/ml_forge: A visual-based graph node editor for training computer vision models. GitHub - anakin87/llm-rl-environments-lil-course: 🌱 A little course on Reinforcement Learning Environments for evaluating and training Language Models GitHub - takaakit/superpowers-uml: Superpowers-UML modifies Superpowers to ensure a software development workflow in which AI agents design through UML modeling. AdriByte Studio - Sviluppo Web e Soluzioni Digitali GitHub - chouligi/angel-copilot: Your personalized Angel Investment Advisor Show HN: MoodSense AI (ML and FastAPI and Gradio, Deployed on Hugging Face) Moodsense Ai - a Hugging Face Space by aman179102 GitHub - agenteractai/lodmem: Level Of Detail Context Management for Agents GitHub - ostefani/subnetlens: A fast, concurrent network scanner with a TUI and plain-text CLI, built in Go. It discovers live hosts on your network, scans their open ports, resolves hostnames, and fingerprints operating systems—delivered. Cyber Pulse: Agentic Intel - Apps on Google Play Whisper API: Self-Hostable Speech to Text Transcription The Agent-Web Protocol Stack: A Research Thesis GitHub - msmarkgu/RelayFreeLLM: A restful API designed to route user prompts to various AI model providers. Show HN: Provepy – A Python decorator that proves your code using Lean and LLMs Show HN: Pardonned.com – A searchable database of US Pardons GitHub - patrickdappollonio/dux: Dux is a terminal UI that lets you run multiple AI coding agents side by side, each in its own git worktree, with full companion terminals, macros, commit generation, and a command palette that knows more tricks than you do. kMC Crystal Simulator Show HN: HyperFlow – A self-improving agent framework built on LangGraph GitHub - stef41/vibescore: 🎵 Grade your vibe-coded project. One command, instant letter grade across security, quality, dependencies, and testing. GitHub - stef41/lmscan: 🔍 Detect AI-generated text and fingerprint which LLM wrote it. Open-source GPTZero alternative. Zero dependencies, works offline. imgur.com GitHub - visionscaper/collabmem: Enabling long-term collaboration with Agentic AI - building up episodic and world model memory over time with in-context awareness 在 Steam 上购买 FriedrichAI: Offline AI 立省 10% GitHub - atripati/ark: AI Runtime Kernel — a context operating system for AI agents. Eliminates tool bloat, loads only what’s needed, and gives LLMs their reasoning space back. GitHub - nowork-studio/toprank: Open-source Claude Code skills for SEO, SEM, Google Ads GitHub - tacomanator/sash: Lightweight macOS menu bar app for reliably cycling through windows of the current application. Appents | Social Media Management for Product-First Teams GitHub - pnhoang/youtube-spam-blocker: Automatically detects and hides spam messages in YouTube Live chat. Set rate limits, keyword filters, and block repeat offenders. GitHub - decisionnode/DecisionNode: CLI + Local MCP - A shared structured memory store across Claude Code, Cursor, Windsurf, Antigravity, and every MCP client. Semantically queryable. GitHub - AvaCodeSolutions/django-email-learning: An open source Django app for creating email-based learning platforms with IMAP integration and React frontend components. The $100K Gap in Kubernetes Security Tooling Function Calling Harness: From 6.75% to 100%
GitHub - shanirsh/prismodev: local cli for ai coding cost control. scans your repo, finds token waste, and generates smaller context packs for claude code, cursor, codex, and other agents.
shanirshad · 2026-05-20 · via Hacker News: Show HN

local ai coding cost control. one command to diagnose token waste, fix it, and prove the improvement.

npx getprismo doctor

that's it. run it on any repo. no api keys, no login, no data leaves your machine.


the problem

ai coding agents (claude code, codex, cursor) burn tokens on things that don't help you ship. lockfiles get read into context. old logs get loaded. generated artifacts leak in. sessions balloon to millions of tokens because nothing tells the agent what to ignore.

most developers don't realize this is happening until the bill arrives or the agent starts looping.

prismodev catches it before, during, and after.


the loop

prismodev is three commands that cover an entire coding session:

before you code     npx getprismo doctor
while you code      npx getprismo watch
after you code      npx getprismo cc timeline

doctor diagnoses the repo, applies safe fixes, and shows the before/after score. watch monitors context pressure live and warns when things go wrong. cc timeline reconstructs what happened in the session so you learn from it.


what prismodev catches

  • missing .claudeignore / .cursorignore (the biggest single fix for most repos)
  • lockfiles entering context (package-lock.json, yarn.lock, pnpm-lock.yaml)
  • generated artifacts leaking in (__pycache__, dist/, coverage/, .next/)
  • operational source-stream dumps leaking in (events/, source-streams/, inbox/calendar/GitHub JSONL exports)
  • oversized instruction files (CLAUDE.md or AGENTS.md over 500 tokens)
  • tool output dominating sessions (repeated reads, large command output)
  • long-running sessions with stale context accumulation
  • repeated file reads (same file loaded 100+ times in one session)
  • repeated commands (agent running the same command in a loop)
  • high context risk sessions that should have been split at task boundaries

real output: doctor

run npx getprismo doctor on any repo. here's what it looks like on a real project:

PrismoDev Doctor

Before: 79/100 - Medium risk - 5 token leaks
After:  91/100 - Low risk - 3 token leaks (+12)
Local usage: 976k tokens across 3 recent session(s)
Estimated exposed context reduction: 100%
Payoff: repo is 12 points cleaner for AI coding sessions

Fixed:
- Created .claudeignore
- Created .cursorignore
- Generated prismo-dev-report.md
- Generated .prismo/architecture-summary.md
- Generated .prismo/recommended-CLAUDE.boilerplate.md
- Generated .prismo/recommended-AGENTS.boilerplate.md
- Generated .prismo/recommended-.claudeignore
- Generated .prismo/recommended-.cursorignore
- Generated .prismo/recommended-.gitignore-additions
- Generated .prismo/backend-summary.md
- Generated .prismo/frontend-summary.md

Still Risky:
- Tool output/context contributed about 319k tokens
- 1 recent session reached high context risk

Recommended starting context:
.prismo/frontend-context.md

Next:
1. npx getprismo context frontend
2. npx getprismo watch --once
3. npx getprismo cc

doctor went from 79 to 91 in one run. the repo now has proper ignore files, compact context packs, and a clear starting point for the next coding session.


real output: watch

run npx getprismo watch during a coding session. it monitors context pressure in real time:

Prismo Watch

Context Pressure: HIGH
Session Size: 707k tokens (exact-local-log)
Recent Growth: +0 tokens
Tool Output: 237k tokens
Turns: 102  |  Tool calls: 774
Model: gpt-5.5

Warnings
- Context risk is high; consider starting a fresh session.
- Tool/output tokens are dominating this session.
- lib/prismo-dev-scan.js appears repeatedly in context (286x).
- node bin/prismo.js appears repeatedly in context (85x).
- lockfiles likely entered active context (60 mentions).

Do This Now
Cause: tool-output-flood (high confidence)
Tool/output tokens are dominating this session (237k tokens).
1. Stop loading full logs or broad command output.
2. Rerun failing commands with tight filters or short ranges.
3. Ask the agent to summarize current errors before reading more files.
Rescue: npx getprismo watch --rescue

Signals
- Repeated file: lib/prismo-dev-scan.js (286x)
- Repeated file: node bin/prismo.js (85x)
- Generated artifacts: lockfiles (60 mentions)
- Generated artifacts: __pycache__ (47 mentions)

Suggested Action
Run: npx getprismo doctor

watch caught lockfiles entering context, a file being read 286 times, and tool output dominating the session. without this, you'd never know.


new: live guardrails mode

the easiest proactive mode is:

npx getprismo watch --auto

--auto turns on live guardrails, live context throttling, event logging, and a default 600k session budget. it writes:

.prismo/live-guardrails.md
.prismo/live-context-throttle.md
.prismo/live-rescue-prompt.md
.prismo/watch-events.jsonl

if you want prismodev to keep updating instructions while the session runs, use:

npx getprismo watch --guardrails

this writes and continuously updates:

.prismo/live-guardrails.md
.prismo/live-rescue-prompt.md

the idea is simple: tell your coding agent once at the start of the session:

follow .prismo/live-guardrails.md during this session.

then keep watch --guardrails running. when prismodev detects tool-output floods, artifact leaks, repeated reads, loops, or context spikes, it updates the guardrails file with the current issue and the exact behavior the agent should follow next.

example guardrails:

# Prismo Live Guardrails

Context pressure: High
Current issue: tool-output-flood
Confidence: high

## Effective Immediately

- Stop loading full logs or broad command output.
- Rerun failing commands with tight filters or short ranges.
- Ask the agent to summarize current errors before reading more files.
- Do not read generated artifacts, lockfiles, caches, build output, coverage, or logs unless explicitly required.

this does not secretly control claude code or codex internals. it gives the agent a live-updating instruction file to follow, which is the safest local-first way to reduce token waste without requiring an IDE extension or agent plugin.


new: live rescue mode

when watch detects a session going sideways, run:

npx getprismo watch --rescue

it prints a paste-ready rescue prompt for the current ai coding session:

Prismo Rescue Prompt

Paste this into the current AI coding session:

We are in a high-context AI coding session. Stop broad exploration and recover state before doing more work.

Current Prismo signal: tool-output-flood (high confidence).
Summary: Tool/output tokens are dominating this session (264k tokens).
Context pressure: High. Session size: 1.11M tokens. Tool output: 264k tokens.

Do this now:
1. Stop loading full logs or broad command output.
2. Rerun failing commands with tight filters or short ranges.
3. Ask the agent to summarize current errors before reading more files.

Before reading or editing anything else, summarize:
- files changed so far
- exact failing command or error
- current hypothesis
- next smallest file/test to inspect

Do not re-read these files unless they changed.
Do not read generated/noisy artifacts unless explicitly required.

watch --rescue --json includes the same prompt as rescuePrompt, plus the structured live action:

{
  "live": {
    "contextPressure": "High",
    "liveAction": {
      "cause": "tool-output-flood",
      "confidence": "high",
      "summary": "Tool/output tokens are dominating this session.",
      "rescueAvailable": true
    }
  }
}

live action causes include:

  • tool-output-flood
  • artifact-leak
  • possible-loop
  • repeated-file-read
  • context-spike
  • high-context-pressure

this is the proactive part of prismodev: it does not just tell you something is expensive. it tells you what to do right now while the session is still recoverable.

use --guardrails when you want files to update automatically during the session. use --rescue when you want a one-shot prompt to paste immediately.


new: live context throttle

if you want prismodev to enforce a session budget while you work, run:

npx getprismo watch --throttle --budget 600k

this writes:

.prismo/live-context-throttle.md

when the active session gets near or crosses the budget, watch turns that into a live action:

Cause: token-budget-exceeded
Stop broad exploration.
Summarize current state before more file reads.
Start a fresh scoped session at the next task boundary.

use it with guardrails for the most proactive setup:

npx getprismo watch --auto

that gives the agent a live instruction file, a rescue prompt, and a stricter context throttle file that updates as the session changes.

watch --auto also appends changed live warnings to .prismo/watch-events.jsonl, so expensive-session events can be reused later in postmortems.

Use --no-events when you want live protection without writing session event history:

npx getprismo watch --auto --no-events

new: context firewall

generate a scoped context policy before a task:

npx getprismo firewall auth-bug

this writes:

.prismo/context-firewall.md
.prismo/allowed-context.txt
.prismo/blocked-context.txt
.prismo/firewall-prompt.md

the firewall tells the agent what it should read first and what it should avoid unless it explains why. this is the prevention layer: instead of only warning after context bloat happens, prismodev gives the agent a smaller context boundary up front.

example:

Allowed first:
- .prismo/architecture-summary.md
- .prismo/backend-summary.md
- backend/app/*/auth/*

Blocked unless justified:
- node_modules/**
- .next/**
- dist/**
- coverage/**
- package-lock.json

watch --auto also updates .prismo/context-firewall.md when it detects live waste, so the active session gets a tighter context policy as pressure rises.


real output: cc timeline

run npx getprismo cc timeline after a session to understand what happened:

Prismo Claude Code Cost

Session: 7689982e-42a3-44fb-9734-2588e5e01145
Model: claude-opus-4-6

Timeline
05:24 PM  Generated artifact likely entered context  package-lock.json (2x)
05:24 PM  Generated artifact likely entered context  logs/debug-output.json (1x)
05:24 PM  Repeated file/path context  CLAUDE.md (8x)
05:24 PM  Repeated file/path context  AGENTS.md (8x)
05:24 PM  Repeated file/path context  node bin/prismo.js (6x)

Suggested Action
Run npx getprismo optimize, then start from .prismo/architecture-summary.md.

timeline shows exactly what leaked, what repeated, and what to do differently next time.


how doctor improves a repo

doctor does four things in sequence:

  1. scans the repo and reads local codex/claude code session logs
  2. applies safe fixes — creates .claudeignore, .cursorignore, generates recommendation templates
  3. generates context packs — compact .prismo/ files that give agents focused context instead of reading everything
  4. re-scans and shows the before/after score

what doctor creates:

.claudeignore                              blocks waste from claude code
.cursorignore                              blocks waste from cursor
.prismo/architecture-summary.md            compact project overview for agents
.prismo/backend-summary.md                 backend-specific context
.prismo/frontend-summary.md                frontend-specific context
.prismo/recommended-CLAUDE.boilerplate.md              CLAUDE.md boilerplate reference; do not overwrite curated files
.prismo/recommended-AGENTS.boilerplate.md              AGENTS.md boilerplate reference; do not overwrite curated files
.prismo/recommended-.claudeignore          full recommended ignore list
.prismo/recommended-.cursorignore          full recommended ignore list
.prismo/recommended-.gitignore-additions   things your gitignore might be missing
prismo-dev-report.md                       full diagnostic report

if an existing .claudeignore or .cursorignore already covers prismo's recommendations, doctor skips the suggested ignore file instead of creating redundant noise. the default recommendations include common project state, local db, export, credential, and token patterns such as *_state.json, *_tokens.json, *_export.json, *.sqlite, models/, and state-backups/.

backend and frontend summaries include load-bearing candidates ranked by import references, text-reference signals, recent git touches when available, and file size, not just directory listings.

prismo also flags source-stream dumps separately from normal build artifacts. large inbox/calendar/github/event payload files are treated as operational noise because they often get summarized once, written near the repo, and then accidentally re-read by later coding sessions.

what doctor never touches:

  • your real CLAUDE.md
  • your real AGENTS.md
  • your .gitignore
  • any source code
  • any config files

it only creates new files and recommendations. you decide what to apply.


how watch catches waste live

watch reads local session logs from codex and claude code. it detects:

signal what it means
context pressure HIGH session is consuming too many tokens
repeated file 286x agent keeps re-reading the same file
lockfiles entered context package-lock.json got loaded (pure waste)
tool output dominating agent output is larger than actual code context
loop suspicion agent may be stuck in a command loop
recent growth +380k context just spiked by 380k tokens

watch tells you the single most useful action to take right now. usually: start a fresh session, or switch to a scoped context pack.

watch --rescue prints a paste-ready prompt for the active coding session. use it when the agent is looping, reading too many files, or flooding context with logs:

npx getprismo watch --rescue

the rescue prompt tells the agent to stop broad exploration, summarize changed files and current failures, avoid noisy artifacts, and continue from the next smallest useful file/test.

watch is tuned for large repos:

  • ignores absolute paths outside the target repo
  • keeps generated artifacts out of repeated-source-file actions
  • groups lockfiles, __pycache__, node_modules, and hashed build assets separately
  • only treats repeated non-generated files as actionable when they exist inside the target repo

this keeps large-repo output focused on real source context instead of path noise from old logs or unrelated projects.


quick start

# see what prismodev does without touching anything
npx getprismo demo

# simple plain-english check
npx getprismo scan --simple

# the full workflow
npx getprismo doctor
npx getprismo watch --once
npx getprismo cc timeline

if you don't have node installed, get it from nodejs.org (LTS). then:

node -v   # should print 18+
npx getprismo doctor

no install needed. npx runs it directly.


all commands

command what it does
doctor diagnose, fix, optimize, show before/after
watch live session monitoring with warnings
cc claude code cost breakdown
cc timeline session reconstruction with events
scan --usage full repo scan with local usage data
scan --simple plain-english summary
scan --fix create safe fix files
scan --ci fail CI when token-risk gates fail
optimize generate .prismo/ context packs
context print paste-ready prompt for agents
setup detect tools, logs, proxy readiness
usage show raw session token usage
init add npm scripts and .prismo/README.md
demo sample output without reading your repo

doctor modes

npx getprismo doctor                     # full run
npx getprismo firewall auth-bug          # generate scoped context firewall
npx getprismo doctor --dry-run           # preview without writing files
npx getprismo doctor --apply-ignores-only # only create ignore files
npx getprismo doctor --no-context-packs  # skip .prismo/ generation
npx getprismo doctor frontend            # scope to frontend
npx getprismo doctor --json              # machine-readable output

watch modes

npx getprismo watch                      # live refresh
npx getprismo watch --once               # single snapshot
npx getprismo watch --once --report      # write .prismo/watch-report.md
npx getprismo watch --once --json        # machine-readable
npx getprismo watch --auto               # guardrails + throttle + 600k budget
npx getprismo watch --auto --no-events   # live protection without event history
npx getprismo watch --guardrails         # update .prismo/live-guardrails.md continuously
npx getprismo watch --guardrails --json  # include guardrailsPath and rescuePath
npx getprismo watch --throttle --budget 600k # enforce a live context budget
npx getprismo watch --events             # append changed warnings to .prismo/watch-events.jsonl
npx getprismo watch --rescue             # paste-ready live-session rescue prompt
npx getprismo watch --rescue --json      # include rescuePrompt in JSON
npx getprismo watch --once --redact-paths # hide local paths
npx getprismo watch codex                # only codex sessions
npx getprismo watch claude               # only claude code sessions

cc modes

npx getprismo cc                         # latest session cost
npx getprismo cc timeline                # event timeline for latest session
npx getprismo cc list                    # list recent sessions
npx getprismo cc last 5                  # last 5 sessions
npx getprismo cc all                     # everything
npx getprismo cc timeline --json         # machine-readable timeline

ci integration

npx getprismo scan --ci --no-report

exits non-zero when:

  • score is below threshold
  • risk is too high
  • ai ignore files are missing
  • generated artifacts are exposed
  • large files are exposed

add to your ci:

{
  "scripts": {
    "ai:ci": "prismo scan --ci --no-report"
  }
}

scoped context packs

prismodev generates context packs scoped to different areas of your codebase:

npx getprismo optimize frontend
npx getprismo optimize backend
npx getprismo optimize auth
npx getprismo context frontend          # prints a paste-ready prompt
npx getprismo context backend

use these as the starting point for coding sessions instead of letting agents explore the whole repo.


tracking modes

local scan        heuristic repo/context risk, no keys needed
local logs        exact when codex/claude session logs expose token fields
prismo proxy      exact usage/cost when traffic routes through prismo base url

prismodev reads local session logs from:

  • codex: ~/.codex/sessions/**/*.jsonl
  • claude code: ~/.claude/projects/**/*.jsonl

no api keys. no intercepted prompts. no data uploaded.


what gets generated

.prismo/
├── architecture-summary.md
├── backend-summary.md
├── frontend-summary.md
├── frontend-context.md
├── backend-context.md
├── recommended-CLAUDE.boilerplate.md
├── recommended-AGENTS.boilerplate.md
├── recommended-.claudeignore
├── recommended-.cursorignore
├── recommended-.gitignore-additions
├── optimize-report.md
└── watch-report.md (when using --report)

all recommendation files. nothing is overwritten. you decide what to use.


init (npm project setup)

npx getprismo init

adds to your package.json:

{
  "scripts": {
    "ai:doctor": "prismo doctor",
    "ai:watch": "prismo watch",
    "ai:context": "prismo context",
    "ai:scan": "prismo scan --usage"
  }
}

then your team can run npm run ai:doctor without remembering the full command.


philosophy

  • local first. nothing leaves your machine.
  • safe by default. doctor never overwrites your real config files.
  • exact when possible. reads real session logs when agents expose them.
  • honest about limits. uses "likely" and "estimate" language when visibility is limited.
  • one suggested action. every output ends with the single best thing to do next.

works with

  • claude code (subscription and api modes)
  • openai codex
  • cursor
  • any tool that respects .claudeignore or .cursorignore
  • any repo (node, python, go, rust, vue, svelte, astro, monorepos, whatever)

internal layout

lib/prismo-dev-scan.js           cli entry and command dispatch
lib/prismo-dev/constants.js      shared defaults, pricing, patterns
lib/prismo-dev/context-optimize.js  context packs, scoped prompts
lib/prismo-dev/doctor.js         doctor/dev/init orchestration
lib/prismo-dev/fixes.js          safe ignore/template generation
lib/prismo-dev/report.js         terminal, markdown, ci reports
lib/prismo-dev/scan.js           repo scanning, scoring, readiness
lib/prismo-dev/usage-watch.js    local logs, watch, cost, timeline

help

npx getprismo --help
npx getprismo doctor --help
npx getprismo watch --help
npx getprismo cc --help
npx getprismo scan --help