Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/yc-software/qm/memorynpx skills add yc-software/qm --skill memorygit clone --depth 1 https://github.com/yc-software/qmWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00070 | $0.01122 |
| Opus 5 | $0.00035 | $0.00561 |
| Sonnet 5 | $0.00014 | $0.00224 |
| Haiku 4.5 | $0.00007 | $0.00112 |
Grade A, and why
memory scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -fsS -X POST "$AGENT_API_URL/v1/memory/facts" \ How it starts
The opening of the file, as written. The whole thing — 85 lines — stays where its author put it; the contents beside it link to each section on GitHub.
memory — search, write, and curate what you remember
Everything here goes through the typed memory tool. Memory is NOT a file: writing
memory/MEMORY.md with write or shell commands lands on your computer's disk and is
silently lost — the tool is the one real path.
Every turn already auto-recalls your notebooks into "## What you remember" and auto-extracts facts after you reply. This skill is for what the automatic path misses:
- Search (
action: "search") — what you remember is bigger than what auto-recall injects. Search spans every notebook this conversation may read (personal, channel, org); when more than one is in reach, each hit is tagged with the notebook it came from. Matching is substring-based (all terms must match), so prefer distinctive terms (a name, a project) over sentences. An empty result is a real answer: you have nothing recorded, so don't assert a memory. - Write now (
action: "remember") — when the user corrects you or tells you something they'll expect you to know later, persist it immediately instead of hoping post-turn extraction catches it. Write self-contained facts (who/what, with enough context to be useful cold). Duplicates are dropped;addedin the reply is the count actually new. - Curate (
action: "read", thenaction: "rewrite") — read your whole notebook and rewrite it without stale, duplicate, or wrong lines. A rewrite replaces the entire notebook: read first, then write back the full corrected content, never a fragment. Curation is for quality — merging duplicates, deleting disproven facts — not for deleting things the user asked you to remember.
The notebook you write is this conversation's own (your personal one in a DM, the channel's in a channel). There is no way to reach anyone else's, by design.
Two targeted writes the tool doesn't carry go through the self-API instead, called with
$AGENT_API_URL and $AGENT_API_TOKEN (both already in your environment on every turn —
if they are unset, this instance has no self-API; say so rather than pretending):
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 85 lines · 70 tokens per session scan A c288d4e518d7
memory is a skill published in the GitHub repository yc-software/qm (14,360 stars, last pushed 3d ago), licensed MIT. It adds 70 tokens to every session and 1,122 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
open-code-review
Performs AI-powered code review on Git changes using the ocr CLI from alibaba/open-code-review. Use when the user asks to review code, review a pull request, review staged/unstaged changes, review a commit, or compare branches for code quality issues. Produces line-level review comments and can automatically apply…
adding-a-provider-api-feature
Add a new provider API capability (prompt caching, strict/structured tool calling, thinking/reasoning effort, service tier, safety settings, logprobs, etc.) to Pydantic AI. Use when wiring a provider feature through the library — it enforces reasoning from the existing cross-provider abstraction before designing…
agent-initialization
Initialize an Agent's settings from a user requirement by writing AGENTS.md, setting identity metadata, and installing only needed Skills.
portfolio
Cross-chain DeFi portfolio discovery, rebalancing suggestions, and NEAR Intent construction. Activates when the user pastes a wallet address or asks about yield/positions/rebalancing. Bootstraps a per-user "portfolio" project, aggregates positions across all the user's addresses inside one project, and offers a…
openclaw-ci-limits
Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe ramp-down/ramp-up changes. Use when tuning .github/workflows/, docs/ci.md, CI runner labels, matrix max-parallel…
release-openclaw-plugin-testing
Plan and run pre-release OpenClaw plugin validation across bundled plugins, package artifacts, lifecycle commands, doctor/fix, config round-trip, gateway startup, SDK compatibility, Docker E2E, Package Acceptance, and Testbox proof.