Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/fockus/skill-memory-bank/api-contractgit clone --depth 1 https://github.com/fockus/skill-memory-bankWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00016 | $0.01152 |
| Opus 5 | $0.00008 | $0.00576 |
| Sonnet 5 | $0.00003 | $0.00230 |
| Haiku 4.5 | $0.00002 | $0.00115 |
Grade A, and why
api-contract scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
- **gRPC**: `buf curl` + generated client stubs How it starts
The opening of the file, as written. The whole thing — 116 lines — stays where its author put it; the contents beside it link to each section on GitHub.
API Contract: $ARGUMENTS
0. Validate arguments
If $ARGUMENTS is empty, stop and ask the user which action to perform (generate, check, test).
1. Stack detection
eval "$(bash ~/.claude/skills/memory-bank/scripts/mb-metrics.sh)"
If stack=unknown, ask the user for the framework / language in use.
2. Detect the API type
# OpenAPI / Swagger
find . -name "*.yaml" -o -name "*.yml" 2>/dev/null | xargs grep -l "openapi\|swagger" 2>/dev/null
find . -name "openapi*" -o -name "swagger*" 2>/dev/null
# gRPC / Protobuf
find . -name "*.proto" 2>/dev/null
# GraphQL
find . -name "*.graphql" -o -name "*.gql" 2>/dev/null
# Handler detection across frameworks:
# Go (gin / echo / chi / net/http)
grep -rn "func.*Handler\|func.*http\.\|r\.GET\|r\.POST\|e\.GET\|e\.POST\|http\.HandleFunc" --include="*.go" . | head -30
# Node.js — Express / Fastify / Nest
grep -rn "app\.\(get\|post\|put\|delete\|patch\)\|router\.\(get\|post\)\|@Get\|@Post" --include="*.ts" --include="*.js" . | head -30
# Python — FastAPI / Flask / Django
grep -rn "@app\.\(get\|post\|put\|delete\)\|@router\.\(get\|post\)\|@app\.route\|path(" --include="*.py" . | head -30
# Java / Kotlin — Spring
grep -rn "@GetMapping\|@PostMapping\|@PutMapping\|@DeleteMapping\|@RequestMapping" --include="*.java" --include="*.kt" . | head -30
# .NET
grep -rn "\[HttpGet\]\|\[HttpPost\]\|\[HttpPut\]\|\[HttpDelete\]\|MapGet\|MapPost" --include="*.cs" . | head -30
# Rust — Axum / Actix / Rocket
grep -rn "\.route(\|#\[get\|#\[post\|#\[put\|#\[delete" --include="*.rs" . | head -30
# Ruby — Rails
grep -rn "resources \|get \|post \|put \|delete " --include="routes.rb" . | head -30
3. Action
generate — specification generation
- Study all detected endpoints / handlers / routes
- Generate an OpenAPI 3.1 (or 3.0) specification — paths, schemas, request / response bodies, error codes, auth
- For gRPC, emit / update
.protofiles - For GraphQL, emit / update the schema SDL
check — breaking-change detection
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 116 lines · 16 tokens per session scan A 0f7a0618a809
api-contract is a command published in the GitHub repository fockus/skill-memory-bank (25 stars, last pushed 1mo ago), licensed MIT. It adds 16 tokens to every session and 1,152 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
git
The pre-finish status: branch, hygiene findings, message checks, workflow lint, template state.
init
Install the formatters this repository needs, with every command visible before it runs.
release-now
Create a git tag + GitHub Release for open-pr — an official release if standing on main, an RC if standing on a branch with an open PR (a dev tool specific to this repo, not shipped in the plugin).
vitaecontext-github
Audit or improve GitHub profile and repository SEO.
vitaecontext-vitaegraph
Create, validate, index, or use a private VitaeGraph.
setup
Fetch Kobiton credentials from the authenticated MCP server and write them to /.kobiton/.credentials.