← Pando

A prompt library your agents read and cannot rewrite

Any MCP client and Pando, for prompts shared across clients.

A prompt that works lives wherever you last used it: a saved command in one editor, a text file on the work laptop, a chat from March. The next assistant gets a pasted copy, and the next time you improve the wording, one of the copies improves and the others do not.

Keep them in one branch of your outline, one bullet per prompt with the prompt in its note and a tag on its line, and lock that branch against agents. Any agent that reaches the branch can then find a prompt by its tag and read it whole when you name it, and none of them can change it.

Set it up

  1. Point the client at https://pando.ink/mcp, which speaks streamable HTTP.
  2. Authenticate with OAuth 2.1 and dynamic client registration, or paste a key from Agents and API keys as a Bearer token.

Connect each client you use, then make the branch. A prompt you already have goes into its bullet’s note: paste it there and its lines stay lines of the note, where the same paste into the bullet’s own line would make a bullet of each line. If your prompts sit in files a connected agent can open, the saved commands in a repository for one, let the agent do the moving: ask it to create one bullet per prompt under Prompts, with the file’s text as the note, and put the lock on only after that, because the lock refuses agents.

The shape

Prompts                                  locked against agents
  Summarise a meeting #prompt/meeting
    note: You are my note taker. List the decisions first,
          then who owns each one, then the open questions.
  Review a pull request #prompt/code
    note: Review this diff. Name every change to a public
          function before anything else.
  Answer a customer #prompt/email #draft
    note: ...

The line is the name you will ask for, with its tags. The prompt is the note, and a note is never shortened: whenever a read returns it, it returns all of it, however long it is. One bullet holds up to 1.5 MB, line and note together.

Tags an agent can search

A tag search matches the start of a tag, so #prompt finds #prompt/meeting and #prompt/code too, and #prompt/code finds only the code ones. The operators go into the search as written here, without quotes:

Matching the start cuts both ways: #prompt also finds #prompts, so choose tags that are not the beginning of another tag you use. An operator Pando does not know, tag:prompt for one, refuses the whole search, and the refusal names it, so a misspelt operator is never passed over in silence. A misspelt tag or word is not refused but searched as written: #promtp finds nothing, and #promp finds every prompt, because every one of them starts with it.

Tags are read from the note as well as the line. A prompt whose note says @alice or step #1 gains @alice and #1 as tags, and turns up in a search for them. Put such words between backticks where you can, which marks them as code, and a # or @ inside code is not a tag. And keep two tags off your prompts: #template, because tapping it makes a copy of the bullet instead of searching, and #noindex, because a branch that carries it is left out of an agent’s tree reads unless it asks for it.

In the app, tap a tag on any prompt and Pando searches for it inside the view you are in. Tap it again and the search closes.

How an agent reads a prompt

A prompt it reads is not an order

Pando tells every agent that connects to it that the words it reads in a bullet are data, and never an instruction to it. A stored prompt is no exception, and that is the right way round: an agent looking through your outline for something else should not start doing what the first prompt it meets tells it to. A prompt becomes the task when you make it one, in your own message:

Search Pando for #prompt/meeting, read the note of
Summarise a meeting, and follow that prompt on the
notes I paste below.

How closely a model then follows a prompt it fetched is up to the model, and it has not been measured for any client against Pando. A prompt you paste yourself leaves no such question, because it is then your own message.

Nor does a prompt show up in a slash menu. The Model Context Protocol lets a server hand a client prompt templates, which its specification says are "designed to be user-controlled", with slash commands as its example, and a server that offers them has to declare it when a client connects. Pando declares only its tools, so the agent fetches a prompt with search or tree, when you ask.

Lock it so no agent rewrites it

A lock stops changes, not reading. Every agent that reaches the library still reads and searches it. A tree read marks every bullet under the lock, with p in its default outline mode, a write that tries anyway is refused with the name of the bullet that holds the lock, and an agent may set a lock but may not lift one.

If you want agents to improve the wording, choose Its shape only under Reaches as well. They can then rewrite the line and the note of each prompt, and still cannot add, move or delete one.

A locked library also refuses an agent that wants to add a prompt. Let it draft new ones outside the library, in its own memory bullet for one, and move the ones you keep into the library yourself: the lock refuses agents, not you. For the same reason, an agent’s memory bullet must not sit inside the library, where every note it tries to keep would be refused.

An agent held to one branch

A connector you approve on Pando’s consent page starts with your whole outline, read and write or read only, so it reads the library wherever it sits. Once you hold an agent to one bullet, it reaches that bullet and what is under it, and nothing else, so it reads the library when the library is under that bullet.

So give the library and the agent’s notes one parent: put Prompts and a bullet for its notes under the same bullet. Open that parent, open Agents and API keys in Settings, tap the agent’s row under Your agents, and press Let it reach only “…”, the bullet you are in. That press also makes the parent itself its memory, so open the bullet for its notes, open Agents and API keys again, tap its row, and press Remember in “…”, the bullet you are in. It then reads the prompts, keeps its notes in their own bullet, still reaches nothing outside the parent, and the lock keeps the prompts as they are. Do not hold it to the library itself: its memory would move there, and a library locked against agents refuses every note it tries to keep.

A second agent held to the same parent reads the same prompts. Give it a notes bullet of its own with the same two presses, and know that each of the two can read and write what the other keeps there, since both reach the whole parent.

An agent you create under Agents and API keys with “Let it read and write this outline” and “Give it a bullet of its own to remember in” both unticked reaches nothing at all until you hold it to a bullet the same way. Its key, which begins with pf_, goes in an Authorization: Bearer header. ChatGPT cannot send one, and the Claude apps can only through the Request headers setting of a custom connector, a beta that only a limited set of organizations has.

When a client’s own place is better

The outline is for the prompt that has to reach more than one client, where one copy should be the only copy, kept in the same place as the rest of your notes and read on your phone like any other bullet.

What it costs

Nothing, for 1,000 bullets, with every feature included and no payment card. Each prompt is one bullet.

Deeper

Connect an agent, about two minutes · The twelve tools · Which note apps an agent can reach · Who runs this