Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/msinclair25/mdevolved/mdevolved-obsidian-mindnpx skills add msinclair25/mdevolved --skill mdevolved-obsidian-mindgit clone --depth 1 https://github.com/msinclair25/mdevolvedWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00040 | $0.00448 |
| Opus 5 | $0.00020 | $0.00224 |
| Sonnet 5 | $0.00008 | $0.00090 |
| Haiku 4.5 | $0.00004 | $0.00045 |
Grade A, and why
mdevolved-obsidian-mind scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
MDevolved + Obsidian Mind
Use this pack only when vault-manifest.json has
"template": "obsidian-mind". Keep Obsidian Mind's local qmd/om MCP
servers beside MDevolved; never replace or proxy them.
MDevolved provides the remote OAuth boundary, exact Project, current Work Packet, owner decisions, provenance, and handoffs. Obsidian Mind provides local search, scoped recall, reasoning, and owner-authorized capture. Do not upload raw Mind memories, private notes, scripts, or runtime state as ordinary Project context.
Connect or resume
Read .mdevolvedignore first. If it is absent, read .owdignore as a legacy
fallback. If both exist and disagree, stop and ask the owner to resolve the
conflict. Never substitute .om-project, a folder name, or a display label for
the MDevolved Project UUID.
For a receipt, call mdevolved__mdevolved_resume first and treat
localVaultAccess.role as unconfirmed until it returns. Without a receipt,
call mdevolved__open_project with the owner's visible Project name. Keep
native note locations and select only concrete, relevant source roots.
Use Mind read tools for local discovery and MDevolved tools for shared durable
state. Before an implementation decision, carry the cited Mind result or an
explicit “nothing applicable” statement into the MDevolved Artifact or
Handoff. Direct Mind writes (record_work, remember), shell, and filesystem
writes require the returned owner-authorized writer role.
Legacy compatibility
Existing pre-MD9 owd MCP entries, protocol names, and .owdignore receipts
remain readable. Preserve them and do not silently re-authorize or delete them;
new setup should use the canonical mdevolved server and receipt names.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 41 lines · 40 tokens per session scan A f8dd09ee70ec
mdevolved-obsidian-mind is a skill published in the GitHub repository msinclair25/mdevolved (2 stars, last pushed yesterday), licensed Apache-2.0. It adds 40 tokens to every session and 448 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-01.
Other skills, from other repositories
backups
Use when designing or auditing a backup-and-restore program that must survive a real disaster: setting defensible RPO/RTO targets, laying out 3-2-1-1-0 copies that are offsite and immutable, wiring point-in-time recovery, and proving restores work on a schedule. NOT tuning Postgres internals or writing the…
tfw-identity
Внутренний fail-closed механизм профилей и локальной привязки Assisted; отделяет участника, роли, task owner и роль ИИ.
tfw-init
Command /tfw-init initializes Trace-First Workflow or attaches and repairs TFW tooling in an existing project. Use for /tfw-init, first-time setup, project discovery, adapter installation, or Codex adapter repair.
tfw-update
Command /tfw-update upgrades and synchronizes local Trace-First Workflow files and adapters while preserving project state. Use for /tfw-update, upstream upgrades, version comparison, migration, or adapter repair.
tfw-config
Command /tfw-config audits or changes Trace-First Workflow configuration and propagates values to every registered inline location. Use for /tfw-config, config verification, projectconfig.yaml changes, or Config Sync Registry updates.
tfw-docs
Command /tfw-docs updates Trace-First Workflow project documentation and technical debt after review. Use for /tfw-docs or updates to KNOWLEDGE.md sections 1-3 or TECHDEBT.md from RF/REVIEW results.