Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/toejough/engram/recallnpx skills add toejough/engram --skill recallgit clone --depth 1 https://github.com/toejough/engramWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00054 | $0.06285 |
| Opus 5 | $0.00027 | $0.03143 |
| Sonnet 5 | $0.00011 | $0.01257 |
| Haiku 4.5 | $0.00005 | $0.00628 |
Grade A, and why
recall scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 341 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Recall from Unified Memory
Surface relevant memories — raw conversation/doc chunks AND crystallized vault lessons in one ranking — lay your planned actions against them, and report, out loud, whether memory changed the plan.
Overview
Memory has two layers retrieved in ONE call: raw chunks (every past conversation and doc, embedded mechanically) and vault notes (lessons crystallized from them). Recall's jobs, in order:
- Make your plan visible before retrieving anything — an unstated plan cannot be tested against memory.
- Sweep, then run ONE unified
engram query. Items taggedkind: chunkare raw fragments;kind: fact/feedback/runbookare crystallized lessons. They compete in the same top-N. - Crystallize — when several near-match chunks evidence the same principle and no note states it yet, write the vault note now.
- Explore-sample and ride-along — the binary samples additional notes from vocab-term centroids near the query (budget sized to the matched-note count) and inserts superseded-note supersessors at the next rank; the agent judges the surfaced candidates, never links.
- Synthesize impact on the plan — confirm / adjust / contradict / silent, per planned action.
- Re-enter for emergent recommendations — a recommendation conceived mid-work gets its own
lever-keyed query and a
Re-entry:line directly above it before it ships (Step 3.5).
The binary resolves the vault and chunk index automatically ($XDG_DATA_HOME/engram/...;
ENGRAM_VAULT_PATH / ENGRAM_CHUNKS_DIR override). Do not pass --vault or --chunks-dir.
Modes — glance vs deep (the depth dial)
Recall runs in one of two modes, selected by the caller (the mode word is the skill argument; absent → deep):
deep(default). The full procedure below — all 10 phrases and the write side (Steps 2.5C, Step 4). It both applies memory to this decision and grows the vault (crystallizes, persists synthesis). Use it when the decision is weighty or irreversible, when you want recall to also learn, or when in doubt.glance(opt-in, cheap — for firing often). A pass that is read-only with respect to vault knowledge (Step 2.7activatestill bumps the used-notes recency metadata — that is kept, not a knowledge write). Run Steps 0–3.5 with ~3 phrases (not 10) and keep the read side — Step 2.5A (read candidates), Step 2.5B (apply the recency weight), Step 2.7 (activate used notes), the Step 3 synthesis, and Step 3.5 (the re-entry query, when triggered) — but skip the write side: Step 2.5C (coverage amend/learn), Step 4 (synthesis-persist). Glance applies memory to this decision; it does not grow the vault's knowledge.
What ships with it
6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 341 lines · 54 tokens per session scan A 121f21188018
recall is a skill published in the GitHub repository toejough/engram (8 stars, last pushed 3d ago), licensed Apache-2.0. It adds 54 tokens to every session and 6,285 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
notion
Notion API for creating and managing pages, databases, and blocks. Use when the user wants to create a Notion page, query a Notion database, update Notion properties, search Notion, add content to Notion, manage Notion blocks, or interact with Notion data sources and workspaces via the API.
agentic-supply-chain-detection
Detect agentic supply-chain risks: compromised dependencies, malicious plugins/tools/models, and untrusted update sources.
skill-vetter
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
ondb
A logical analysis and reasoning tool for AI. Use when decomposing documents into structured knowledge, querying entities and relations, validating consistency, or indexing files. Trigger on "remember", "what do I know about", "link X to Y", "show dependencies", "analyze this document", entity CRUD, or cross-skill…
finding-protocol
Operational-tier finding template — minimal fields for sub-agent decision support. Heavyweight deliverable promotion lives in skills/decepticon/final-report.
babysit
Same-session monitoring loop for PRs, CI runs, tickets, and deployments using the monitorstart / monitorupdate / autonudgestop MCP tools. The loop re-injects your check instructions into THIS session on an idle interval — same context, same tools — and works from dashboard chat, Slack threads, and Discord DMs. Use…