Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/kastalien-research/thoughtbox/assumptionsnpx skills add Kastalien-Research/thoughtbox --skill assumptionsgit clone --depth 1 https://github.com/Kastalien-Research/thoughtboxWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/kastalien-research/thoughtbox/assumptions)<a href="https://agentmods.dev/skills/kastalien-research/thoughtbox/assumptions"><img src="https://agentmods.dev/badge/skills/kastalien-research/thoughtbox/assumptions.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00032 | $0.00919 |
| Opus 5 | $0.00016 | $0.00460 |
| Sonnet 5 | $0.00006 | $0.00184 |
| Haiku 4.5 | $0.00003 | $0.00092 |
Grade A, and why
assumptions scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 98 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Manage assumptions: $ARGUMENTS
Commands
Parse the first word of $ARGUMENTS to determine the command:
list — Show all tracked assumptions
- Read all
.assumptions/*.jsonlfiles - Parse each line as a JSON record
- Display sorted by confidence (lowest first) or staleness (oldest verification first)
- Format as a table: ID | Category | Claim | Confidence | Last Verified | Status
add — Register a new assumption
Parse remaining arguments for: --category, --claim, --evidence, --source
Create a new assumption record in .assumptions/registry.jsonl:
{
"id": "<category>-<short-slug>",
"category": "<api|dependency|behavior|environment|tooling>",
"claim": "<what we assume to be true>",
"evidence": "<what supports this assumption>",
"source": "<where this was discovered>",
"confidence": 0.8,
"created": "<ISO 8601>",
"last_verified": "<ISO 8601>",
"verification_method": "<how to test this>",
"failure_history": [],
"status": "active",
"blast_radius": "<what breaks if this assumption is wrong>"
}
verify — Re-verify an assumption
- Read the assumption record by ID
- Execute the verification method (may involve web search, API calls, or code checks)
- Update
last_verifiedtimestamp andconfidencescore - If verification fails, add to
failure_historyand reduce confidence - If confidence drops below 0.3, mark status as
suspectand warn
stale — Show assumptions that need re-verification
- Read all assumption records
- Filter to those where
last_verifiedis more than 14 days ago - Sort by blast_radius (highest first)
- Display with suggested verification actions
seed — Seed registry from MEMORY.md gotchas
- Read MEMORY.md
- Extract entries from "Gotchas", "Known Bugs", and "MCP Knowledge API Gotchas" sections
- For each entry, create an assumption record with:
- category: inferred from content (api, dependency, behavior, etc.)
- claim: the gotcha statement
- evidence: "Discovered empirically" + date from MEMORY.md
- confidence: 0.9 (verified by experience)
- verification_method: suggested test
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 98 lines · 32 tokens per session scan A dd7607981f4e
assumptions is a skill published in the GitHub repository Kastalien-Research/thoughtbox (64 stars, last pushed 1mo ago), licensed MIT. It adds 32 tokens to every session and 919 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
forget
Delete specific observations from agentmemory after showing them and getting explicit confirmation. Use when the user says "forget this", "delete memory", "remove that note", or wants to scrub specific data for privacy.
handoff
Resume the most recent agent session for the current working directory, leading with any unanswered question. Use when the user says "where were we", "resume", "handoff", "pick up where I left off", or starts a session with no fresh context.
agentmemory-agents
How agentmemory wires into host coding agents via the connect command. Use when installing agentmemory into a specific agent, when asked which agents are supported, or when a connect adapter writes the wrong config path.
agentmemory-config
Skill "agentmemory-config" from rohitg00/agentmemory, covering quick start, defaults worth knowing, ports, see also and reference.
agentmemory-hooks
The agentmemory plugin hooks that capture observations automatically across the agent session lifecycle. Use when explaining how memory gets captured without manual saves, when debugging missing observations, or when tuning what gets recorded.
session-history
Show what happened in recent past sessions on this project as a clean timeline. Use when the user asks "what did we do last time", "session history", "past sessions", or wants an overview of previous work.