melaya

melaya is a skill for Claude Code from melaya-labs/melaya-mcp. It costs 154 tokens per session (2,078 once invoked), scanned A, original, Apache-2.0.

A guide for operating Melaya, a platform where AI agents run pipelines that can research, handle documents, update spreadsheets, send email, and use connected services. It routes the agent to more specific instructions when needed.

In plain words
What is it for?
Use it to build, run, fix, and hand over Melaya pipelines and multi-step agent systems.
Why use it?
It sets safety rules for connections, approvals, configuration updates, and checking real outputs rather than trusting a reported run status.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin. Also seen: mentions Claude Code; mentions Codex.

Part of the melaya plugin — 2 skills, 1 command, 1 MCP server shipped together

Good fit Use it to build, run, fix, and hand over Melaya pipelines and multi-step agent systems.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/melaya-labs/melaya-mcp/melaya
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add melaya-labs/melaya-mcp --skill melaya
Clone the repo
git clone --depth 1 https://github.com/melaya-labs/melaya-mcp

Made for: Claude Code.

Or install melaya, the plugin that ships this one along with the rest of its 2 skills, 1 command, 1 MCP server.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for melaya

README.md
[![agentmods](https://agentmods.dev/badge/skills/melaya-labs/melaya-mcp/melaya/github.svg)](https://agentmods.dev/skills/melaya-labs/melaya-mcp/melaya)
Your own site
<a href="https://agentmods.dev/skills/melaya-labs/melaya-mcp/melaya"><img src="https://agentmods.dev/badge/skills/melaya-labs/melaya-mcp/melaya/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for melaya

Your own site · 80×15
<a href="https://agentmods.dev/skills/melaya-labs/melaya-mcp/melaya"><img src="https://agentmods.dev/badge/skills/melaya-labs/melaya-mcp/melaya.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 154 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,078 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00154 $0.02078
Opus 5.5 $0.00062 $0.00831
Sonnet 5.5 $0.00031 $0.00416
Haiku 4.5 $0.00015 $0.00208

Measured today against content hash 5538e97ded9f, method: parsed. Prices are Anthropic first-party input rates as of 2026-10-07, from the pricing page.

Security

Grade A, and why

melaya scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.

The scan reads SKILL.md. This mod also ships 1 executable file (modules/pipeline-authoring/templates/build_configs.py), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/melaya/SKILL.md · 71 lines

How it starts

The opening of the file, as written. The whole thing — 71 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Melaya

Melaya runs AI agent pipelines for a user: agents that research, read documents, write designed reports, update spreadsheets, send email, and operate phones or browsers. You drive it through the Melaya MCP tools (melaya_*). This file is a router: it holds the rules that always apply and tells you which module to open. Open a module only when the task needs it.

Rules that always apply

  1. Start every session with melaya_setup_status and act on its gaps before anything else.
  2. Never ask for, repeat or store passwords or API keys in chat. Services are connected by the user in the app (melaya_connector_connect gives the link).
  3. Never approve, reject or edit an approval on the user's behalf. Show what is waiting (melaya_approval_list) and point them to the app or their phone.
  4. melaya_pipeline_save in update mode replaces the WHOLE config: always melaya_pipeline_get first, change the copy, melaya_pipeline_preview, save, then read it back.
  5. Judge a run by outcome, never by status, and verify real artifacts (the sheet rows, the document, the email) before you say it worked.
  6. Do not invent tool names or parameters: load the schema (tool search) or check melaya_pipeline_registry / melaya_connector_tools.
  7. Confirm before anything irreversible or outward-facing (sending, posting, deleting, paying). Connector writes over MCP (melaya_connector_call) need the user's melaya:connectors.write permission and run at once, with no approval card: confirm the exact send or change first. Anything that moves money or trades is never run over MCP; it stays an approval in the Melaya app.
  8. If a capability is missing, the user did not grant it or has not connected it: say so and offer the fix. Never look for a workaround.

Who are you helping?

The user Start with
Non-technical: wants to run, watch, approve, schedule or tweak existing pipelines modules/quickstart/GUIDE.md
Integrator or builder: wants a complete multi-pipeline system for a client, from requirements to handover modules/agentic-systems/GUIDE.md (the end-to-end method; it routes to the others by phase)
Anyone with one specific task the intent table below

Read the full file on GitHub · 71 lines

Files

What ships with it

60 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. today Changed · +2 lines 5538e97ded9f
  2. yesterday Changed · +1 lines 6058004da8eb
  3. 2d ago First seen · 68 lines · 154 tokens per session scan A 9333deaac5df

Subscribe to this mod's changes

melaya is a skill published in the GitHub repository melaya-labs/melaya-mcp (0 stars, last pushed today), licensed Apache-2.0. It adds 154 tokens to every session and 2,078 once invoked, about $0.0006 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-10-05.

Related

Other skills, from other repositories

skill

Skill "skill" from activeing123/mcptoon, covering mcptoon — mcp tool-catalog compression, when to use what, managing a skill catalog (mcptoon as the skill center), stop reading the whole doc tree (mcptoon as the doc router) and when another manager already runs the catalog.

activeing123/mcptoon · 0 tokens

cortex-profile

View and manage your cognitive profile — how you think, work patterns, blind spots, and cross-domain connections. Use when the user says 'show my profile', 'how do I work', 'what are my patterns', 'cognitive style', 'blind spots', 'methodology', or at the start of a session to load context. Also use 'rebuild profile'…

cdeust/Cortex · 98 tokens

quantum-guide-algorithms-linear-systems

A guide for quantum methods that estimate solutions to linear equations, such as A x = b. It routes the task to open-source implementations using Qiskit or PennyLane and includes classical checks in some cases.

xi-zhao/OpenQuantum · 38 tokens

triage-inbox

Use this skill to walk the user through their unfiled or stale tasks and move them into the right Eisenhower quadrant.

vscarpenter/gsd-task-manager · 0 tokens

helmdeck-hyperframes-authoring

Author render-deterministic hyperframes compositions. Use when generating HTML/CSS/JS for hyperframes.compose, hyperframes.render, or any pipeline that produces a programmatic MP4 via hyperframes — including builtin.scaffolded-narrated-video, builtin.prompt-video, builtin.prompt-narrated-video. The framework's "render…

tosin2013/helmdeck · 132 tokens

signed-in-browser

Drive the browser the user is already signed into, instead of a cold automation profile. Use when a task lives behind a login — a dashboard, an admin console, an internal tool, a ticket queue, a bank or billing page, webmail, a social account — or when a scripted login is failing on SSO, MFA, CAPTCHA or bot detection.…

t3ratech/mcp-session-bridge · 109 tokens