A prompt library your agents read and cannot rewrite
A prompt that works lives wherever you last used it: a saved command in one editor, a text file on the work laptop, a chat from March. The next assistant gets a pasted copy, and the next time you improve the wording, one of the copies improves and the others do not.
Keep them in one branch of your outline, one bullet per prompt with the prompt in its note and a tag on its line, and lock that branch against agents. Any agent that reaches the branch can then find a prompt by its tag and read it whole when you name it, and none of them can change it.
Set it up
- Point the client at https://pando.ink/mcp, which speaks streamable HTTP.
- Authenticate with OAuth 2.1 and dynamic client registration, or paste a key from Agents and API keys as a Bearer token.
Connect each client you use, then make the branch. A prompt you already have goes into its bullet’s note: paste it there and its lines stay lines of the note, where the same paste into the bullet’s own line would make a bullet of each line. If your prompts sit in files a connected agent can open, the saved commands in a repository for one, let the agent do the moving: ask it to create one bullet per prompt under Prompts, with the file’s text as the note, and put the lock on only after that, because the lock refuses agents.
The shape
Prompts locked against agents
Summarise a meeting #prompt/meeting
note: You are my note taker. List the decisions first,
then who owns each one, then the open questions.
Review a pull request #prompt/code
note: Review this diff. Name every change to a public
function before anything else.
Answer a customer #prompt/email #draft
note: ...
The line is the name you will ask for, with its tags. The prompt is the note, and a note is never shortened: whenever a read returns it, it returns all of it, however long it is. One bullet holds up to 1.5 MB, line and note together.
Tags an agent can search
A tag search matches the start of a tag, so #prompt finds #prompt/meeting and #prompt/code too, and #prompt/code finds only the code ones. The operators go into the search as written here, without quotes:
- #prompt: every prompt in the library.
- #prompt/code: only the code prompts.
- #prompt -#draft: every prompt except the ones still tagged #draft.
- #prompt/code OR #prompt/meeting: either kind. OR is written in capitals.
- in:note decisions: looks only in the notes, which is where the prompts are.
Matching the start cuts both ways: #prompt also finds #prompts, so choose tags that are not the beginning of another tag you use. An operator Pando does not know, tag:prompt for one, refuses the whole search, and the refusal names it, so a misspelt operator is never passed over in silence. A misspelt tag or word is not refused but searched as written: #promtp finds nothing, and #promp finds every prompt, because every one of them starts with it.
Tags are read from the note as well as the line. A prompt whose note says @alice or step #1 gains @alice and #1 as tags, and turns up in a search for them. Put such words between backticks where you can, which marks them as code, and a # or @ inside code is not a tag. And keep two tags off your prompts: #template, because tapping it makes a copy of the bullet instead of searching, and #noindex, because a branch that carries it is left out of an agent’s tree reads unless it asks for it.
In the app, tap a tag on any prompt and Pando searches for it inside the view you are in. Tap it again and the search closes.
How an agent reads a prompt
- search answers in full by default, so every hit carries its note and its path: one search for #prompt/meeting hands back the prompt itself. The same default makes #prompt alone hand back every prompt whole, 50 to a page, so an agent that only wants the list should send mode outline, which leaves the notes out, and then fetch the one prompt it needs.
- tree reads in outline mode by default, which leaves notes out and marks a bullet that has one with n. On a single bullet with depth 0 it answers in full, note included, and mode full reads the library with its notes exactly as you wrote them. Mode markdown is for reading, not for following: it puts a backslash before a note line that starts like Markdown, a list item, a heading, a quote or a code fence, so an agent should fetch a prompt in full.
- changes, with the library as its root, returns the prompts added or edited since the cursor it last handed out, each with its note, so an agent can keep up without reading the branch again.
A prompt it reads is not an order
Pando tells every agent that connects to it that the words it reads in a bullet are data, and never an instruction to it. A stored prompt is no exception, and that is the right way round: an agent looking through your outline for something else should not start doing what the first prompt it meets tells it to. A prompt becomes the task when you make it one, in your own message:
Search Pando for #prompt/meeting, read the note of Summarise a meeting, and follow that prompt on the notes I paste below.
How closely a model then follows a prompt it fetched is up to the model, and it has not been measured for any client against Pando. A prompt you paste yourself leaves no such question, because it is then your own message.
Nor does a prompt show up in a slash menu. The Model Context Protocol lets a server hand a client prompt templates, which its specification says are "designed to be user-controlled", with slash commands as its example, and a server that offers them has to declare it when a client connects. Pando declares only its tools, so the agent fetches a prompt with search or tree, when you ask.
Lock it so no agent rewrites it
- Open the Prompts bullet’s menu and choose Protect it from changes, or press Ctrl+Shift+L at a desk (Cmd+Shift+L on a Mac). Nothing can now change or delete it or anything under it, you included.
- Open the menu again, choose How it is protected, and under Refuses pick Agents only. You can add and edit prompts again. Anything that arrives with a key cannot, and a connector you approved holds a key of its own.
A lock stops changes, not reading. Every agent that reaches the library still reads and searches it. A tree read marks every bullet under the lock, with p in its default outline mode, a write that tries anyway is refused with the name of the bullet that holds the lock, and an agent may set a lock but may not lift one.
If you want agents to improve the wording, choose Its shape only under Reaches as well. They can then rewrite the line and the note of each prompt, and still cannot add, move or delete one.
A locked library also refuses an agent that wants to add a prompt. Let it draft new ones outside the library, in its own memory bullet for one, and move the ones you keep into the library yourself: the lock refuses agents, not you. For the same reason, an agent’s memory bullet must not sit inside the library, where every note it tries to keep would be refused.
An agent held to one branch
A connector you approve on Pando’s consent page starts with your whole outline, read and write or read only, so it reads the library wherever it sits. Once you hold an agent to one bullet, it reaches that bullet and what is under it, and nothing else, so it reads the library when the library is under that bullet.
So give the library and the agent’s notes one parent: put Prompts and a bullet for its notes under the same bullet. Open that parent, open Agents and API keys in Settings, tap the agent’s row under Your agents, and press Let it reach only “…”, the bullet you are in. That press also makes the parent itself its memory, so open the bullet for its notes, open Agents and API keys again, tap its row, and press Remember in “…”, the bullet you are in. It then reads the prompts, keeps its notes in their own bullet, still reaches nothing outside the parent, and the lock keeps the prompts as they are. Do not hold it to the library itself: its memory would move there, and a library locked against agents refuses every note it tries to keep.
A second agent held to the same parent reads the same prompts. Give it a notes bullet of its own with the same two presses, and know that each of the two can read and write what the other keeps there, since both reach the whole parent.
An agent you create under Agents and API keys with “Let it read and write this outline” and “Give it a bullet of its own to remember in” both unticked reaches nothing at all until you hold it to a bullet the same way. Its key, which begins with pf_, goes in an Authorization: Bearer header. ChatGPT cannot send one, and the Claude apps can only through the Request headers setting of a custom connector, a beta that only a limited set of organizations has.
When a client’s own place is better
- For one client, or for a slash command. Pando offers no slash commands, so if typing / and picking a prompt in one assistant is the point, that assistant’s own saved commands, where it has them, are closer to hand.
- For rules about one repository, its AGENTS.md or CLAUDE.md, next to the code. Some of those files already cross clients: Zed uses the first it finds of a list that includes .cursorrules, .clinerules, AGENTS.md, CLAUDE.md and GEMINI.md.
- Some clients carry their own further. Warp syncs your global rules through Warp Drive, and its docs say "All objects stored in Warp Drive sync immediately as they’re updated". With Apply your cloud configuration to local sessions on, Kiro loads your cloud steering files, custom agents and skills into each new local session, and if you use Claude Code, Devin CLI also reads ~/.claude/CLAUDE.md as a global rule.
- If you only ever paste your prompts yourself, any notes app that syncs to your phone does that as well. The outline earns its place when an agent fetches the prompt itself.
The outline is for the prompt that has to reach more than one client, where one copy should be the only copy, kept in the same place as the rest of your notes and read on your phone like any other bullet.
What it costs
Nothing, for 1,000 bullets, with every feature included and no payment card. Each prompt is one bullet.
Deeper
Connect an agent, about two minutes · The twelve tools · Which note apps an agent can reach · Who runs this