Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/timurgaleev/memexnpx agentmods add skills/timurgaleev/memex/skillpack-harvestWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/timurgaleev/memex/skillpack-harvest)<a href="https://agentmods.dev/skills/timurgaleev/memex/skillpack-harvest"><img src="https://agentmods.dev/badge/skills/timurgaleev/memex/skillpack-harvest.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00079 | $0.02643 |
| Opus 5 | $0.00039 | $0.01321 |
| Sonnet 5 | $0.00016 | $0.00529 |
| Haiku 4.5 | $0.00008 | $0.00264 |
Grade C, and why
skillpack-harvest scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Recursive force deletehighDestructive command
rm -rf with a variable or a broad path is one typo away from removing the wrong tree.
retains its skill. Don't `rm -rf` the source after harvesting. How it starts
The opening of the file, as written. The whole thing — 274 lines — stays where its author put it; the contents beside it link to each section on GitHub.
skillpack-harvest — Editorial workflow for lifting host skills into the pack
Convention: see _brain-filing-rules.md for file placement rules. This skill writes into the skillpack's own tree, not brain pages.
This skill is the inverse of memex skillpack scaffold. Scaffold ships
skills downstream (pack → host workspace). Harvest lifts proven patterns
upstream (host workspace → pack) so they become references every other
client of the brain can scaffold.
Contract
A harvest is "properly done" when:
- The host skill is mature (used in production, recent routing-eval cases pass).
- The editorial genericization in Phase 3 has scrubbed every workspace-specific reference (names, real entities, internal channels).
memex skillpack harvest --dry-runpreviewed the file set.- The real
memex skillpack harvest <slug> --from <host>succeeded withstatus: harvested(no privacy-lint hits). memex skillpack checkpasses on the newskills/<slug>/SKILL.md.- The user has reviewed the diff in the pack checkout and explicitly approved the commit.
If any of these is incomplete, the skill is NOT yet harvested — the files may sit in the pack's working tree, but they're not landed.
Output Format
This skill produces two artifacts in the pack's working tree:
skills/<harvested-slug>/SKILL.md(and any sibling files likerouting-eval.jsonl)- Paired source files at their mirror paths (e.g.
src/commands/<slug>.ts) when the host SKILL.md declared them in frontmattersources:
Nothing else in the pack needs editing — the slug becomes visible to
list_skills on the strength of its directory, and memex skillpack
regenerates the bundle's .manifest.json from the tree at bundle time.
The session output to the user is a one-line success summary plus
a list of files written. JSON mode (--json) returns the full
HarvestResult shape for machine consumption.
Anti-Patterns
- Skipping the dry-run. Always preview first. Files land in
the pack's working tree; cleanup is a
git checkoutaway, but you shouldn't need to. - Trusting the linter alone. The default regex set catches the common cases. It doesn't catch every proper noun. Phase 3 (the editorial pass) is the primary defense.
- Harvesting
--no-lintwithout justification. The lint exists for a reason. If you bypass it, document why in the commit. - Harvesting a skill that's still in flux. Wait until the host version stabilizes. Otherwise you'll harvest, then re-harvest, then re-harvest, and that churns the pack for no benefit.
- Moving files instead of copying. Harvest is a copy. The host
retains its skill. Don't
rm -rfthe source after harvesting. - Harvesting batch (multiple skills at once). Not supported, and for good reason — the editorial review per skill is real work.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 274 lines · 79 tokens per session scan C 4af9d750a8be
skillpack-harvest is a skill published in the GitHub repository timurgaleev/memex (8 stars, last pushed today), licensed MIT. It adds 79 tokens to every session and 2,643 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it C with 1 finding (recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
design-mcp-server
Design the tool surface, resources, and service layer for a new MCP server. Use when starting a new server, planning a major feature expansion, or when the user describes a domain/API they want to expose via MCP. Produces a design doc at docs/design.md that drives implementation.
api-context
Canonical reference for the unified Context object passed to every tool and resource handler in @cyanheads/mcp-ts-core. Covers the full interface, its RequestContext base, all sub-APIs (ctx.log, ctx.state, ctx.requestInput, ctx.inputs, ctx.enrich, ctx.content), and when to use each.
api-canvas
DataCanvas primitive reference — a Tier 3 SQL/analytical workspace for tabular MCP servers, backed by DuckDB. Use when registering tables from upstream APIs, running ad-hoc SQL across them, and exporting results. Covers the acquire → register → query → export flow, per-table TTL, the token-sharing pattern for…
api-testing
Testing patterns for MCP tool/resource handlers using createMockContext and Vitest. Covers mock context options, handler testing, McpError assertions, format testing, Vitest config setup, and test isolation conventions.
field-test
Exercise tools, resources, and prompts against a live HTTP server via MCP JSON-RPC over curl. Starts the server, surfaces the catalog, runs real and adversarial inputs, and produces a tight report with concrete findings and numbered follow-up options. Use after adding or modifying definitions, or when the user asks to…
orchestrations
Pick and run a multi-phase workflow that chains foundational task skills (git-wrapup, release-and-publish, maintenance, field-test, setup, etc.) end-to-end. Routes user intent to a workflow file under workflows/ — greenfield builds, maintenance + release, field-test + fix, or known-work + release. Single source for…