Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add melaya-labs/melaya-mcp --skill melayagit clone --depth 1 https://github.com/melaya-labs/melaya-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/melaya-labs/melaya-mcp/melaya)<a href="https://agentmods.dev/skills/melaya-labs/melaya-mcp/melaya"><img src="https://agentmods.dev/badge/skills/melaya-labs/melaya-mcp/melaya/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/melaya-labs/melaya-mcp/melaya"><img src="https://agentmods.dev/badge/skills/melaya-labs/melaya-mcp/melaya.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00154 | $0.02078 |
| Opus 5.5 | $0.00062 | $0.00831 |
| Sonnet 5.5 | $0.00031 | $0.00416 |
| Haiku 4.5 | $0.00015 | $0.00208 |
Grade A, and why
melaya scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 71 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Melaya
Melaya runs AI agent pipelines for a user: agents that research, read documents, write designed reports, update spreadsheets, send email, and operate phones or browsers. You drive it through the Melaya MCP tools (melaya_*). This file is a router: it holds the rules that always apply and tells you which module to open. Open a module only when the task needs it.
Rules that always apply
- Start every session with
melaya_setup_statusand act on its gaps before anything else. - Never ask for, repeat or store passwords or API keys in chat. Services are connected by the user in the app (
melaya_connector_connectgives the link). - Never approve, reject or edit an approval on the user's behalf. Show what is waiting (
melaya_approval_list) and point them to the app or their phone. melaya_pipeline_savein update mode replaces the WHOLE config: alwaysmelaya_pipeline_getfirst, change the copy,melaya_pipeline_preview, save, then read it back.- Judge a run by
outcome, never bystatus, and verify real artifacts (the sheet rows, the document, the email) before you say it worked. - Do not invent tool names or parameters: load the schema (tool search) or check
melaya_pipeline_registry/melaya_connector_tools. - Confirm before anything irreversible or outward-facing (sending, posting, deleting, paying). Connector writes over MCP (
melaya_connector_call) need the user'smelaya:connectors.writepermission and run at once, with no approval card: confirm the exact send or change first. Anything that moves money or trades is never run over MCP; it stays an approval in the Melaya app. - If a capability is missing, the user did not grant it or has not connected it: say so and offer the fix. Never look for a workaround.
Who are you helping?
| The user | Start with |
|---|---|
| Non-technical: wants to run, watch, approve, schedule or tweak existing pipelines | modules/quickstart/GUIDE.md |
| Integrator or builder: wants a complete multi-pipeline system for a client, from requirements to handover | modules/agentic-systems/GUIDE.md (the end-to-end method; it routes to the others by phase) |
| Anyone with one specific task | the intent table below |
What ships with it
60 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- modules/agentic-systems/GUIDE.md 25 KB
- modules/agentic-systems/references/phase-checklists.md 6.2 KB
- modules/agentic-systems/references/system-design-template.md 3.7 KB
- modules/agentic-systems/references/worked-example.md 9.6 KB
- modules/automation-governance/GUIDE.md 23 KB
- modules/automation-governance/references/cost-security.md 7.6 KB
- modules/automation-governance/references/hitl-modes.md 7.2 KB
- modules/automation-governance/references/memory-policy.md 3.4 KB
- modules/automation-governance/references/plan-limits.md 4.1 KB
- modules/automation-governance/references/trigger-sources.md 19 KB
- modules/automation-governance/references/triggers-ui-walkthrough.md 55 KB
- modules/automation-governance/references/triggers.md 27 KB
- modules/client-handover/GUIDE.md 17 KB
- modules/client-handover/templates/00-overview.md 6.3 KB
- modules/client-handover/templates/01-how-it-works.md 5.0 KB
- modules/client-handover/templates/02-run-inputs-schedules-triggers.md 3.5 KB
- modules/client-handover/templates/03-tools-catalogue.md 2.4 KB
- modules/client-handover/templates/04-data-model-and-provenance.md 4.1 KB
- modules/client-handover/templates/05-branded-documents.md 3.1 KB
- modules/client-handover/templates/06-security-human-control.md 5.0 KB
- modules/client-handover/templates/pipeline-note.md 5.3 KB
- modules/data-spine/GUIDE.md 22 KB
- modules/data-spine/references/recorder-pattern.md 7.2 KB
- modules/data-spine/references/schema-design.md 8.2 KB
- modules/data-spine/references/scoring-from-files.md 9.6 KB
- modules/data-spine/references/status-lifecycle.md 4.6 KB
- modules/devices-browser/GUIDE.md 19 KB
- modules/devices-browser/references/browser-setup-and-operation.md 14 KB
- modules/devices-browser/references/devices-in-pipelines-and-assistant.md 12 KB
- modules/devices-browser/references/phone-setup-and-operation.md 15 KB
- modules/devices-browser/references/troubleshooting.md 7.7 KB
- modules/discovery/GUIDE.md 21 KB
- modules/discovery/references/connectors-playbook.md 19 KB
- modules/discovery/references/keyless-tool-catalogue.md 15 KB
- modules/discovery/references/requirement-mapping-template.md 5.3 KB
- modules/discovery/references/service-families.md 12 KB
- modules/pipeline-authoring/GUIDE.md 24 KB
- modules/pipeline-authoring/references/config-schema.md 11 KB
- modules/pipeline-authoring/references/context-and-memory.md 10 KB
- modules/pipeline-authoring/references/designed-documents.md 10 KB
- modules/pipeline-authoring/references/instruction-patterns.md 15 KB
- modules/pipeline-authoring/references/limits-costs-languages.md 6.0 KB
- modules/pipeline-authoring/references/quality-loop.md 6.4 KB
- modules/pipeline-authoring/references/run-inputs.md 7.8 KB
- modules/pipeline-authoring/references/step-kinds.md 11 KB
- modules/pipeline-authoring/templates/build_configs.py 24 KB runs code
- modules/projects-templates/GUIDE.md 18 KB
- modules/projects-templates/references/app-gallery-and-sharing.md 8.7 KB
- modules/projects-templates/references/template-standards.md 8.0 KB
- modules/quickstart/GUIDE.md 23 KB
- modules/quickstart/references/app-map.md 3.6 KB
- modules/quickstart/references/glossary.md 4.6 KB
- modules/quickstart/references/troubleshooting.md 6.8 KB
- modules/runners-models/GUIDE.md 21 KB
- modules/runners-models/references/choosing-models.md 5.8 KB
- modules/runners-models/references/failures.md 8.4 KB
- modules/runners-models/references/local-models.md 5.1 KB
- modules/runners-models/references/runner-setup.md 5.2 KB
- modules/runners-models/references/subscription-cli-providers.md 5.1 KB
- modules/validate-debug/GUIDE.md 17 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed · +2 lines 5538e97ded9f
- yesterday Changed · +1 lines 6058004da8eb
- 2d ago First seen · 68 lines · 154 tokens per session scan A 9333deaac5df
melaya is a skill published in the GitHub repository melaya-labs/melaya-mcp (0 stars, last pushed today), licensed Apache-2.0. It adds 154 tokens to every session and 2,078 once invoked, about $0.0006 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-10-05.
Other skills, from other repositories
skill
Skill "skill" from activeing123/mcptoon, covering mcptoon — mcp tool-catalog compression, when to use what, managing a skill catalog (mcptoon as the skill center), stop reading the whole doc tree (mcptoon as the doc router) and when another manager already runs the catalog.
cortex-profile
View and manage your cognitive profile — how you think, work patterns, blind spots, and cross-domain connections. Use when the user says 'show my profile', 'how do I work', 'what are my patterns', 'cognitive style', 'blind spots', 'methodology', or at the start of a session to load context. Also use 'rebuild profile'…
quantum-guide-algorithms-linear-systems
A guide for quantum methods that estimate solutions to linear equations, such as A x = b. It routes the task to open-source implementations using Qiskit or PennyLane and includes classical checks in some cases.
triage-inbox
Use this skill to walk the user through their unfiled or stale tasks and move them into the right Eisenhower quadrant.
helmdeck-hyperframes-authoring
Author render-deterministic hyperframes compositions. Use when generating HTML/CSS/JS for hyperframes.compose, hyperframes.render, or any pipeline that produces a programmatic MP4 via hyperframes — including builtin.scaffolded-narrated-video, builtin.prompt-video, builtin.prompt-narrated-video. The framework's "render…
signed-in-browser
Drive the browser the user is already signed into, instead of a cold automation profile. Use when a task lives behind a login — a dashboard, an admin console, an internal tool, a ticket queue, a bank or billing page, webmail, a social account — or when a scripted login is failing on SSO, MFA, CAPTCHA or bot detection.…