Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add toroleapinc/claude-brain/plugin install claude-brainWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/toroleapinc/claude-brain/brain-init)<a href="https://agentmods.dev/skills/toroleapinc/claude-brain/brain-init"><img src="https://agentmods.dev/badge/skills/toroleapinc/claude-brain/brain-init.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00023 | $0.01173 |
| Opus 5 | $0.00012 | $0.00587 |
| Sonnet 5 | $0.00005 | $0.00235 |
| Haiku 4.5 | $0.00002 | $0.00117 |
Grade B, and why
brain-init scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
MACHINE_ID=$(cat ~/.claude/brain-config.json | jq -r '.machine_id') How it starts
The opening of the file, as written. The whole thing — 131 lines — stays where its author put it; the contents beside it link to each section on GitHub.
The user wants to initialize their Claude Brain sync network.
Parse arguments:
- If arguments contain "--encrypt", enable encryption
- The first non-flag argument is the Git remote URL
Arguments provided: $ARGUMENTS
Steps
-
First, check dependencies by running:
"${CLAUDE_PLUGIN_ROOT}/scripts/common.sh" && echo "OK"If jq and git are missing, tell the user what to install.
-
Validate the remote URL for security:
source "${CLAUDE_PLUGIN_ROOT}/scripts/common.sh" validate_remote_url "$ARGUMENTS"If the URL is detected as pointing to a PUBLIC repository, STOP and warn the user:
- "WARNING: This repository appears to be PUBLIC. Your brain data (memory, skills, settings, and potentially sensitive information) will be visible to anyone."
- "Please use a PRIVATE repository."
- Ask the user if they want to continue anyway.
-
Show the user their current brain inventory by running:
bash "${CLAUDE_PLUGIN_ROOT}/scripts/status.sh" -
IMPORTANT: Show the user a security notice before proceeding: Tell the user:
- "Brain sync will export the following to the Git remote:"
- " - CLAUDE.md, rules, skills, agents (your instructions and workflows)"
- " - Auto memory and agent memory (learned patterns from your sessions)"
- " - Settings (hooks, permissions — NOT env vars)"
- " - MCP server configurations (command/args only — env vars with API keys are STRIPPED)"
- " - Keybindings"
- ""
- "What is NEVER exported: OAuth tokens, API keys in env vars, ~/.claude.json, session transcripts"
- ""
- "Note: Memory files may contain information from your conversations. Review ~/.claude/projects/*/memory/ if concerned."
-
Ask the user to confirm they want to initialize brain sync with the provided remote.
-
Run the initialization sequence:
# Parse arguments for encryption flag ENABLE_ENCRYPTION=false REMOTE_URL="" for arg in $ARGUMENTS; do case "$arg" in --encrypt) ENABLE_ENCRYPTION=true ;; *) if [ -z "$REMOTE_URL" ]; then REMOTE_URL="$arg"; fi ;; esac done # Create brain repo directory mkdir -p ~/.claude/brain-repo # Initialize git repo cd ~/.claude/brain-repo git init git remote add origin "$REMOTE_URL" 2>/dev/null || git remote set-url origin "$REMOTE_URL" # Create directory structure mkdir -p machines consolidated meta # Initialize meta files echo '{"entries":[]}' > meta/merge-log.json # Set up encryption if requested if [ "$ENABLE_ENCRYPTION" = "true" ]; then echo "Setting up age encryption..." # Check if age is installed if ! command -v age-keygen &>/dev/null; then echo "ERROR: age not found. Install it from https://github.com/FiloSottile/age" echo "On macOS: brew install age" echo "On Ubuntu/Debian: apt install age" exit 1 fi # Generate age keypair source "${CLAUDE_PLUGIN_ROOT}/scripts/common.sh" IDENTITY_FILE="${HOME}/.claude/brain-age-key.txt" RECIPIENTS_FILE="${HOME}/.claude/brain-repo/meta/recipients.txt" generate_age_keypair "$IDENTITY_FILE" "$RECIPIENTS_FILE" echo "Age encryption configured:" echo " Private key: $IDENTITY_FILE" echo " Public key: $RECIPIENTS_FILE" fi # Register this machine (with encryption settings) if [ "$ENABLE_ENCRYPTION" = "true" ]; then bash "${CLAUDE_PLUGIN_ROOT}/scripts/register-machine.sh" "$REMOTE_URL" --encrypt else bash "${CLAUDE_PLUGIN_ROOT}/scripts/register-machine.sh" "$REMOTE_URL" fi # Export initial brain snapshot MACHINE_ID=$(cat ~/.claude/brain-config.json | jq -r '.machine_id') mkdir -p "machines/${MACHINE_ID}" bash "${CLAUDE_PLUGIN_ROOT}/scripts/export.sh" --output "machines/${MACHINE_ID}/brain-snapshot.json" # Copy as initial consolidated brain cp "machines/${MACHINE_ID}/brain-snapshot.json" consolidated/brain.json # Commit and push (specific paths, not -A) git add machines/ consolidated/ meta/ git commit -m "Initialize brain: $(hostname)" git branch -M main git push -u origin main
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 131 lines · 23 tokens per session scan B fddf8145536e
brain-init is a skill published in the GitHub repository toroleapinc/claude-brain (85 stars, last pushed 2mo ago), licensed MIT. It adds 23 tokens to every session and 1,173 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
llm-wiki
Build and maintain an LLM-curated personal knowledge base — the "LLM Wiki" pattern from Andrej Karpathy's April 2026 gist. Use this skill whenever the user wants to ingest a source (paper, article, transcript, PDF, notes) into a persistent compounding knowledge base, ask a question against accumulated notes, lint or…
alive:save
The human wants to checkpoint. Or: the stash has grown heavy — 5+ items, 30+ minutes, a natural pause in the work. The squirrel doesn't decide when to save. It surfaces the need and lets the human pull the trigger. Runs the full save protocol: confirms stash, writes log, updates state, generates projections…
alive:capture-context
Use when external content arrives in the session — emails, transcripts, screenshots, documents, files, or in-session research worth keeping. Also use when there's nothing obvious to capture — the skill checks 03Inbox/ for unrouted files and enters inbox scan mode. Stores raw content, routes to bundles, extracts tasks…
alive:load-context
The human mentions a walnut to work on, asks about a specific venture/experiment/project, or wants to check status — not just explicit 'load X'. Load the brief pack (3 files), resolve the people involved, check the active bundle — then surface one observation and ask what to work on. Context loads in tiers: walnut and…
alive:session-history
Revive sessions (quick or heavy), browse, and search — 'what happened recently?', 'find the session where we discussed X', 'revive yesterday's session'. For single-session recall and multi-session browsing. If the human needs to merge multiple sessions into one working context or detect conflicts between parallel…
alive:mine-for-context
Deep context extraction from source material. Creates reference bundles, builds extraction plans, tracks what's been extracted, and discovers new targets — people, subjects, patterns, connections. The archaeologist that turns raw sources into structured knowledge. Can be invoked by alive:session-history for targeted…