Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/xiaomimimo/mimo-code/drive-mimonpx skills add XiaomiMiMo/MiMo-Code --skill drive-mimogit clone --depth 1 https://github.com/XiaomiMiMo/MiMo-CodeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00091 | $0.04945 |
| Opus 5 | $0.00046 | $0.02472 |
| Sonnet 5 | $0.00018 | $0.00989 |
| Haiku 4.5 | $0.00009 | $0.00494 |
Grade D, and why
drive-mimo scanned grade D with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Asks the agent to reveal its instructionsmediumSystem prompt leakage
Directions to print, repeat or translate the system prompt extract configuration the operator did not intend to expose.
# Screen should still show prompt (not exit) Recursive force deletehighDestructive command
rm -rf with a variable or a broad path is one typo away from removing the wrong tree.
rm -rf "$MHOME" "$WORKSPACE" How it starts
The opening of the file, as written. The whole thing — 458 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Drive MiMo
Overview
Two interfaces for driving a separate mimo process:
| Interface | Command | Use when |
|---|---|---|
| Headless | mimo run --format json |
Scripted tasks, CI, event validation |
| TUI | mimo in tmux |
Interactive flow, permission dialogs, keybindings, visual regression |
Core principle: Every run produces parseable evidence. No eyeballing.
Always drive an isolated instance: give each run a fresh MIMOCODE_HOME and a throwaway workspace so it never touches your own config, memory, or session DB.
Two ways to launch — orthogonal to interface
The interface (headless vs TUI, above) is what you drive. How the process is launched is a separate axis — either can be launched either way:
| Launcher | Command | Use when |
|---|---|---|
| Installed binary | mimo … |
Testing a released/installed build |
| Dev (from source) | bun dev … |
Debugging mimocode itself — runs src/index.ts directly, no build step, picks up local code changes |
Everything below uses mimo for brevity. To drive a dev build instead,
substitute bun dev for mimo and run from the repo root — every flag,
JSON event, and tmux technique is identical. See the Dev Mode section.
Prerequisites
# mimo binary must be on PATH (installed-binary launcher)
which mimo || echo "mimo not found on PATH"
# OR: dev launcher — run from the mimocode repo root, needs bun
which bun || echo "bun not found — needed for dev mode"
# tmux (for TUI interface)
which tmux || echo "tmux not found — install it for TUI mode"
Running the
wait-for-text.shhelper: invoke it as./scripts/wait-for-text.sh …from this skill's directory. The repository copy is executable and can be called directly.
Dev Mode (debugging mimocode itself)
When the goal is to debug mimocode's own code, launch from source with
bun dev instead of the installed mimo binary. It runs
packages/opencode/src/index.ts directly — no build step — so local edits take
effect on the next launch.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 458 lines · 91 tokens per session scan D 56df45543fa4
drive-mimo is a skill published in the GitHub repository XiaomiMiMo/MiMo-Code (12,904 stars, last pushed 2d ago), licensed MIT. It adds 91 tokens to every session and 4,945 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it D with 2 findings (asks the agent to reveal its instructions, recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
xiaomi-tts
Use this skill when the user wants to convert text to speech using Xiaomi MiMo's TTS models (mimo-v2.5-tts). Uses OpenAI-compatible chat/completions API with audio response. Supports multiple preset voices and custom voice design. Use when 用户提到 语音合成、文字转语音、TTS、朗读、读出来、生成语音、 生成音频、文本转音频、配音、念出来、小米语音、MiMo 语音、小米 TTS。.
byok-custom-model
Register a custom LLM endpoint with your own API key for chat in Starchild. Use when adding a personal Anthropic, OpenAI, Grok, Qwen, DeepSeek, Meta (Muse Spark), NEAR AI, or Venice key as a chat model (e.g. add my Claude key, register DeepSeek, use Muse Spark 1.1).
deepseek-vision
MUST use when the user sends or asks about images, photos, screenshots, pictures, audio, video, or mixed media documents, including requests to OCR/read text from an image. Route all media through Xiaomi MiMo V2.5 (mimo-v2.5) and mimo-v2.5-asr via scripts/mimo.py; never use local OCR, viewimage, native vision…
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…