Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Whatsonyourmind/oraclaw --skill oraclaw-banditgit clone --depth 1 https://github.com/Whatsonyourmind/oraclawWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/whatsonyourmind/oraclaw/oraclaw-bandit)<a href="https://agentmods.dev/skills/whatsonyourmind/oraclaw/oraclaw-bandit"><img src="https://agentmods.dev/badge/skills/whatsonyourmind/oraclaw/oraclaw-bandit/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/whatsonyourmind/oraclaw/oraclaw-bandit"><img src="https://agentmods.dev/badge/skills/whatsonyourmind/oraclaw/oraclaw-bandit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00045 | $0.00885 |
| Opus 5 | $0.00023 | $0.00443 |
| Sonnet 5 | $0.00009 | $0.00177 |
| Haiku 4.5 | $0.00005 | $0.00089 |
Grade A, and why
oraclaw-bandit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 101 lines — stays where its author put it; the contents beside it link to each section on GitHub.
OraClaw Bandit — AI-Powered A/B Testing
You are an optimization agent that uses Multi-Armed Bandits to find the best option from a set of choices.
When to Use This Skill
Use this when the user or another agent needs to:
- Choose the best variant from multiple options
- Run A/B tests without predetermined sample sizes
- Optimize feature flags, prompts, email subjects, or any choice
- Make context-aware selections (different best option for different situations)
How to Use
Step 1: Set Up the MCP Connection
Add the OraClaw MCP server to get the optimize_bandit and optimize_contextual tools:
{
"mcpServers": {
"oraclaw": {
"command": "npx",
"args": ["tsx", "path/to/oraclaw-mcp/index.ts"]
}
}
}
Step 2: Use optimize_bandit for Simple A/B Testing
Call with a list of options (arms) and their historical performance:
{
"arms": [
{ "id": "variant-a", "name": "Short Email", "pulls": 500, "totalReward": 175 },
{ "id": "variant-b", "name": "Long Email", "pulls": 300, "totalReward": 126 },
{ "id": "variant-c", "name": "Video Email", "pulls": 100, "totalReward": 48 }
],
"algorithm": "ucb1"
}
The response tells you which variant to show next, balancing exploration (trying new options) and exploitation (using what works).
Step 3: Use optimize_contextual for Personalized Selection
When the best choice depends on CONTEXT (time, user type, situation):
{
"arms": [
{ "id": "deep-work", "name": "Deep Work Block" },
{ "id": "quick-tasks", "name": "Quick Task Batch" },
{ "id": "meetings", "name": "Meeting Block" }
],
"context": [0.75, 0.8, 0.3, 0.0],
"history": [
{ "armId": "deep-work", "reward": 0.9, "context": [0.25, 0.9, 0.1, 0.0] },
{ "armId": "quick-tasks", "reward": 0.7, "context": [0.75, 0.4, 0.8, 1.0] }
]
}
Context vector represents situation features (e.g., time of day, energy, urgency, number of pending items). The algorithm learns which option works best in each context.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 101 lines · 45 tokens per session scan A ce4380317fcd
oraclaw-bandit is a skill published in the GitHub repository Whatsonyourmind/oraclaw (13 stars, last pushed yesterday), licensed MIT. It adds 45 tokens to every session and 885 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
fastify
Production Fastify (TypeScript) patterns: schema validation, plugins, typed routes, error handling, security hardening, logging, testing with inject, and graceful shutdown.
darto-write-middleware
Write and register middleware in a Darto (Dart) app — the Middleware factory pattern, global/path-scoped/route-level registration, short-circuiting, per-request state, and global error/404 handlers. Use when adding cross-cutting behavior (auth, logging, CORS, timing) or configuring app.onError / app.notFound in a…
darto-add-route
Add or modify HTTP endpoints in a Darto (Dart) web app — verbs, path/query params, request-body reading, route groups, and Context response helpers. Use when building or changing API routes in a project that depends on the darto package (import 'package:darto/darto.dart'). Not for Express/Node — Darto handlers take a…
darto-validate-request
Validate the body, query, params, or headers of a Darto (Dart) request using the zValidator middleware and zard (Zod-style) schemas. Use when adding input validation to a Darto endpoint, defining a z.map/z.string/z.int schema, reading validated data with c.req.valid, or customizing the validation error response.…
darto-scaffold-project
Scaffold, run, and build a Darto (Dart) web project using the dartocli — create a new project with a NestJS-style module structure, run a hot-reload dev server, compile a production binary, and generate a typed API client. Use when starting a new Darto app, setting up the project layout, or configuring dev/build…
Express/Fastify Backend Patterns
Use this skill when building Node.js HTTP APIs with Express or Fastify and you want safe request validation, predictable error handling, and maintainable routing/service layering.