Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/monglong0214/commitlore/commitlore-setupnpx skills add MongLong0214/commitlore --skill commitlore-setupgit clone --depth 1 https://github.com/MongLong0214/commitloreWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00129 | $0.01508 |
| Opus 5 | $0.00064 | $0.00754 |
| Sonnet 5 | $0.00026 | $0.00302 |
| Haiku 4.5 | $0.00013 | $0.00151 |
Grade A, and why
commitlore-setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 132 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CommitLore setup
Every command below is the commitlore CLI, which arrives with install.sh /
install.ps1. The Claude Code plugin ships the MCP server, the pre-edit hook
and these skills, and puts nothing on PATH — where commitlore is not found,
node <plugin-checkout>/dist/commitlore.mjs takes the same arguments.
Shortcut for a repository that just needs wiring up, nothing broken to diagnose:
commitlore init runs steps 2-4 below (hooks install, index --rebuild, then
doctor --fix as a final check) in one command, reports what it did and what it
could not, and is safe to re-run. Use the four steps below one at a time when
something specific looks broken and you want to isolate which piece.
Four checks, in order. Each one is independent and re-runnable — running any of them twice on an already-configured repo is a no-op, not an error.
1. Diagnose
commitlore doctor
Reports ok, warn, or skipped for: whether the origin remote fetches
refs/notes/commitlore (records that live only in the notes mirror never
reach a teammate whose fetch config omits that ref), whether there is a local
notes mirror to push, whether the commit-msg hook is installed, and whether
the local git build parses trailers the way the spec expects. warn lines
carry their own fix directly underneath — read that before doing anything
else. Example, run against a repo that has a remote but nothing else set up:
warn notes fetch refspec — origin does not fetch refs/notes/commitlore, so records pushed by others stay invisible here
fix: git config --add remote.origin.fetch '+refs/notes/commitlore:refs/notes/commitlore'
ok notes push — no local mirror yet — nothing to push (git push origin refs/notes/commitlore, once there is)
warn commit-msg hook — no commit-msg hook at .git/hooks/commit-msg
fix: commitlore hooks install
ok git interpret-trailers — git version 2.50.1 (Apple Git-155) parses trailers as the spec expects
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 132 lines · 129 tokens per session scan A f821d6dcc532
commitlore-setup is a skill published in the GitHub repository MongLong0214/commitlore (9 stars, last pushed 3d ago), licensed MIT. It adds 129 tokens to every session and 1,508 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
Effective Memory
The essential habits for an AI agent with memory — session bookends, learning triggers, verification, safety, and the operational discipline that turns raw recall into compounding intelligence. Pinned, always-injected.
recall
Recall this repository's OwnMem local memory before changing code, and keep it healthy. Use when a repository contains .ownmem/, when past debugging lessons could apply ("have we hit this before", "why is it done this way"), or when the user mentions ownmem, project memory, or recalling across sessions.
mnemo-cortex
Installs and wires Mnemo Cortex (local-first persistent memory) into OpenClaw and other MCP-capable agents. Use for cross-session recall, decision history, or multi-agent shared memory.
init
Install or update OwnMem in the current repository. Use when the user asks to set up OwnMem, add local project memory for coding agents, or refresh an existing OwnMem installation after a version bump.
ori-memory
Persistent agent memory with learning retrieval. Knowledge graph on markdown files — capture insights, decisions, research, and learnings during work, then retrieve them weeks or months later. Use when knowledge is too valuable to lose but too much to inject into every prompt.
ogham-research
Structured memory capture for Ogham shared memory. Use when the user wants to store findings, remember something, save what was learned, or capture a decision. Triggers on "remember this", "store this", "save this finding", "save what we learned", "capture this decision", "log this", or any request to persist…