icemage
Token-efficient context engine for AI coding agents. v2.23.0: token-killer pack — deep-forget (unlearning propagation), dangling-reference guard, MCP schemas-on-demand. 2462 tests, 43 MCP tools, Elastic-2.0.
Install / Use
claude mcp add ncmonx -- npx -y github:ncmonx/icemageIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
AI & Machine LearningSupported Platforms
Our assessment of icemage
icemage scores 81/100 on our quality scale, 562nd of 821 AI & Machine Learning skills we index.
Its MCP Server is 16 KB long, well organised into 13 sections with 3 code examples: a thorough specification that gives an agent plenty to work with.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated 5 days ago, so icemage is actively maintained.
- Our last check on 2026-09-18 found the source still online.
- No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
- Its trust signals score 80/100, with 2 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the first 100 KB of the file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands (2 minor notes below).
- noteInstalls by piping a downloaded script into a shellline 93
curl -fsSL https://raw.githubusercontent.com/ncmonx/icemage/main/scripts/install.sh | sh - noteInstalls by piping a downloaded script into a shellline 99
irm https://raw.githubusercontent.com/ncmonx/icemage/main/scripts/install.ps1 | iex
Automated pattern scan on 2026-09-29. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
icemage compared with similar skills
All 4 of these similar skills score higher than icemage; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| icemage (this skill)by ncmonx | 81 | 3 | 5d ago | MCP Server |
| claude-memby thedotmack | 100 | 94.9k | today | CLAUDE.md |
| Agent-Reachby Panniantong | 100 | 86.0k | 13d ago | CLAUDE.md |
| Understand-Anythingby Egonex-AI | 100 | 84.5k | today | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.0k | today | CLAUDE.md |
Frequently asked questions
- How do I install icemage?
- Run
claude mcp add ncmonx -- npx -y github:ncmonx/icemage. The install tabs above show the steps for each supported agent. - Which AI agents does icemage work with?
- It is written for Claude Code, Claude Desktop, Cursor and Cline, as a MCP Server file. Other agents that read the same format can often use it too.
- Is icemage safe to use?
- Our scan of the first 100 KB of the file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands (2 minor notes below). It declares no license and scores 80/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is icemage still maintained?
- The repository was last updated 5 days ago, so icemage is actively maintained.
Skill content
View source on GitHubIcemage <sub><sup>(icmg)</sup></sub>
Stop burning tokens. Stop losing context. Ship faster.
A single binary that makes Claude Code, Cursor, and every other AI coding assistant 70–90% cheaper to run — without dumbing them down.
If you've ever watched 30K tokens evaporate on a single file read, paid for "thinking" you didn't need, or re-explained the same project context after /clear for the fifth time today — this is for you.
🟢 Why Icemage
AI assistants are powerful but wasteful by default. Every time the AI opens a file, runs a command, or starts a new chat, it re-reads context it has seen many times and dumps full output into the conversation. Icemage sits quietly in the background and trims the noise before it ever reaches the AI:
- Long files → only the relevant slice
- Noisy command output → just the parts that matter
- Web pages → cached + summarised
- Past decisions → remembered across sessions so the AI doesn't ask twice
- Repeated work → results reused instead of recomputed
The AI keeps its full intelligence. Your wallet keeps more of its money.
📊 Headline numbers
| Metric | Typical | Best | Since |
|---|---|---|---|
| File-read savings | 70 – 85 % fewer tokens | up to 92 % | v0.5 |
| Test / build output | 60 – 80 % shorter | up to 90 % | v0.5 |
| Multi-file UI propagation (style-clone) | 30 – 50× cheaper | up to 98 % | v1.22.0 |
| Cross-project bundle (port) | 8 – 12× cheaper | up to 95 % | v1.24.0 |
| Compressed-Write (AI emit diff) | 70 – 95% fewer tokens | up to 98 % | v1.25.0 |
| Web-fetch reduction | 70 – 90 % smaller | up to 95 % | v0.4 |
| Repeat-context recall | near-zero, < 5 ms cached | — | v1.21.8 |
| Past-chat full-text search | < 10 ms across months | — | v1.21.7 |
| Graph symbol lookup | 256-slot in-RAM cache | — | v1.21.8 |
| First-prompt warmup | < 1 s | — | v1.18 |
| Cold build time (icmg itself) | ~50 % faster (20 min → 9-10 min) | — | v1.26.0 |
| MCP response filter (verbose plugins) | 50 – 80 % smaller | up to 90 % | v1.30.0 |
| Auto-thinking suppress (trivial prompts) | ~1500 tok / call saved | — | v1.30.0 |
| Sayless-auto (long-prose replies) | 60 – 75 % compress | up to 85 % | v1.30.0 |
| Service auto-start (UserPromptSubmit) | 0-touch warm-up | — | v1.30.0 |
| Path ambiguity warning (icmg context) | wrong-file lookups → loud | — | v1.29.0 |
| rg-wrapper + brace glob (icmg grep/files) | flag-mirror, {a,b} expand | — | v1.29.0 |
| Local AI model (built-in, opt-in) | 0 cloud calls | privacy-first | v1.31.0 |
| Smart router (REGEX vs LLM_LOCAL vs CACHE) | <100 us p99 | hot-path forced regex | v1.31.0 |
| HTTP streaming download (model fetch + SHA256) | 400 MB - 2 GB safe-verify | tamper-detect | v1.31.0 |
| icmg git wrapper (single ergonomic entry) | Tkil-filtered + safety-gated | enforces icmg-FIRST | v1.31.0 |
| Python-free core (PRECOMPACT_PY dropped) | -200-500 ms boot saved | single-binary | v1.31.0 |
| pack --rerank (LLM-reorder memory hits) | opt-in warm-path | router-gated | v1.32.0 |
| PreCompact LLM summary (warm-pool Qwen 0.5B) | <15 s cold | regex fallback always | v1.32.0 |
| icmg compact-bg (proactive memory worker) | <3 s warm | manual + future hook | v1.32.0 |
| Smarter local AI memory | multi-prompt safe | no overflow | v1.32.0 |
| Code graph viz + report (icmg graph viz) | interactive D3 + god-nodes | — | v1.71.0 |
| Secret scanner (icmg scan) | 21 detectors, CI-gate | redact-by-default | v1.68.0 |
| MCP server hardening (token + rate-limit + path-guard) | abuse / RCE-safe | — | v1.72.0 |
| Post-compact memory re-anchor | rules survive compaction | auto on init | v1.73.0 |
| Scripted-safe icmg run (non-interactive guard) | no hang on destructive | --yes/env opt-in | v1.74.0 |
| Clean self-upgrade (idempotent Defender step) | no phantom B: drive popup | --no-defender opt-out | v1.75.0 |
| Encryption-at-rest (icmg encrypt, SQLCipher AES-256) | opt-in full-DB encrypt | BM25 recall intact | v1.76.0 |
| Hot recall cache (RAM, daemon-shared) | < 5 ms repeat recall | self-governing RAM | v1.77.0 |
| Cost per AI session | down 70 – 90 % vs. raw | up to 95 % | — |
✨ What's new
- v2.21.0 — Brain + token trio: session-aware recall delta, contradiction sentinel, adaptive recall depth. When the session TTL dedup suppresses memory nodes you already saw this session,
recallnow emits a single stdout line[N prior memories still apply: #ids]instead of silently dropping the reference — the agent keeps the pointer without re-paying the tokens for full bodies. Newicmg memory-health --contradictionsscans the memory store for node pairs that overlap heavily (Jaccard ≥ 0.6 default,--jaccard-minto tune) yet disagree — a negation marker on one side or a conflictingkey=valuefact; flag-only (never deletes), strongest-first, capped at--max(default 25), each hit suggesting the existing bi-temporal fixicmg memory invalidate <old> --by <new>. Verified live on a 31k-node store: caught realicmg_versionandprefixconflicts at 100% overlap. Andrecall --adaptivesizes recall depth with the deterministic v2.20 intent classifier — simple task = 3 results, unknown = 7, complex = 12; an explicit--limitalways wins. All deterministic, no LLM. 2416/2416 tests ✓. - v2.20.0 — Model-era capability pack. As frontier models grew 1M-token windows and extended-thinking budgets, the token lever shifted from how much to trim toward cache-hit rate and reasoning-token cost. Five shipped:
pack --cache-awareclassifies sections (conventions/rules/graph/files = stable; task/recall/diff = volatile), orders stable-first, and wraps ONLY the byte-stable prefix (FNV-1aprefix_hashmakes drift visible) so prompt caching (-90% cost / -85% latency) actually hits. MCP tool annotations — every tools/list entry now carriesreadOnlyHint/destructiveHint/idempotentHint/openWorldHintso an agent host can plan safely. Newicmg_graph_queryMCP tool: deterministic multi-hop structural search (blast_radius|who_calls|path_between).pack --effort-hintrecommends an extended-thinking budget from task intent + graph fan-out.token-ledger stats/otelreport cache-hit ratio + honest cost estimate, OpenTelemetry GenAI-style JSON offline. 2406/2406 tests ✓. - v2.19.1 —
icmg rundestructive-op guard goes argv-aware — no more false positives. The guard gatingrm -rf/Remove-Item/DROP TABLEused a whole-string substring scan, so any command merely containing the pattern —grep 'rm -rf' notes.txt, a path likesrc/farm/— was wrongly refused, and a--yes/ICMG_ASSUME_YES=1bypass on an auto-wrapped child never reached the icmg process. Now detection is argv-aware (isDestructiveArgv): flags only when the leading verb is the destructive tool (skippingenv VAR=val/sudoprefixes), honors a leadingICMG_ASSUME_YES=1/FORCE=1env-prefix as explicit bypass intent.psql -c "DROP TABLE t"still caught;git rm --cachedno longer trips. 10 new tests, TDD. - v2.19.0 — graphify-parity ingest & graph pack. Five gaps from the graphify landscape research, closed:
icmg ingestnow reads Office documents (.docxparagraphs + table cells,.xlsxall sheets) and transcribes audio/video (.mp4.mp3.wav… via faster-whisper sidecar, graceful when the dep is absent);.sql/.ddlfiles feed the code graph (CREATE TABLE→table nodes,FOREIGN KEY→references:edges); HCL/Terraform extractor (.tf/.hcl/.tfvarsblocks → nodes,module.source→ dependency edges); andicmg init --all-tools/--strictwires every detected host CLI (Cursor, Windsurf, Zed, Codex, Copilot, OpenCode, Gemini, Amp) in one run. 34 new tests; 2364 C++ + 15 Python green. - v2.18.0 — Filter-coverage telemetry goes proactive + a stray-
nuldaemon bug fix.icmg savingsnow self-diagnoses filter-coverage gaps (the command verbs burning the most raw output while Tkil saves the least — born from two same-week reactive discoveries:git log7-char hash miss andgh api0% filtered).icmg learnturns each gap into an actionable filter recommendation, andicmg savings --jsonexposes afilter_gapsarray for badge/CI tooling. Plus a real bug fix:RuleDaemonClient::ensureDaemon()spawned the daemon via a cmd.exe-specific>nul 2>nulredirect throughsafeExecShell(), which prefers bash — so on any Windows box with Git installed,nulwas treated as an ordinary filename and a straynulfile was created in the current directory on everyicmginvocation. Fixed with a plain-argv spawn, plus an audit that fixed three moresafeExecShellsites with the same hazard (new bash-safecore::suppressStderr()). 2340/2340 tests ✓.
curl -fsSL https://raw.githubusercontent.com/ncmonx/icemage/main/scripts/install.sh | sh
One line — Windows (PowerShell):
irm https://raw.githubusercontent.com/ncmonx/icemage/main/scripts/install.ps1 | iex
The installer grabs the latest release, verifies its SHA-256, and drops icmg into your bin dir (~/.local/bin on Linux/macOS, %USERPROFILE%\bin on Windows). Pin a version with ICMG_VERSION=2.1.0, or change where it lands with ICMG_BIN_DIR.
- Download the latest archive from the Releases page —
icmg-<version>-win-x64.zipfor Windows,icmg-<version>-linux-x64.tar.gzfor Linux,icmg-<version>-macos-arm64.tar.gzfor macOS. - Extract it into any folder.
- Add that folder to your
PATHsoicmgis available everywhere.
Then, in your project terminal:
icmg init
That's it. The next time you launch Claude Code (or Cursor / Cline / Windsurf — see below), Icemage will quietly start trimming tokens.
🧰 What you'll actually use day-to-day
After install, the only command most people type is icmg init once per project. Everything else happens automatically. A few useful commands when you want to peek under the hood:
| Want to | Type |
|---|---|
| See how much you saved this month | icmg savings |
| See a chart in the terminal | icmg savings --ascii |
| Recall a past decision in this project | icmg recall "<question>" |
| Recall something from another projec
Truncated for display — read the full file on GitHub.
Related Skills
claude-mem
94.9kPersistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Agent-Reach
86.0kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
Understand-Anything
84.5kGraphs that teach > graphs that impress. Turn any code into an interactive knowledge graph you can explore, search, and ask questions about. Works with Claude Code, Codex, Cursor, Copilot, Gemini CLI, and more.
headroom
74.0kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
