Agent skill

Quota Cache Architecture

by kunchenguid in kunchenguid/quota-axi

Documents how quota-axi keeps its disk cache: location, strict file permissions, no stored secrets, and context-scoped identifiers that stop snapshots crossing accounts.

MITAuto-check passedBackend & APIs

Install Quota Cache Architecture

skills CLI
$ npx skills add kunchenguid/quota-axi --skill cache-architecture -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kunchenguid/quota-axi cache-architecture --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kunchenguid/quota-axi.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cache-architecture .claude/skills/cache-architecture && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cache-architecture
GitHub stars
144
Token cost
~1.3k tokens
SKILL.md length
635 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Documents how quota-axi keeps its disk cache: location, strict file permissions, no stored secrets, and context-scoped identifiers that stop snapshots crossing accounts.

  • Changing how quota-axi caches provider quota snapshots
  • SKILL.md covers Cache Storage & Security, Context-Scoped Providers…, Cache Lifecycle & Exclusions and Keychain Access Markers
  • Needs META_API_KEY
  • Adding a provider and deciding whether it needs context scoping

What it does

The skill describes the disk cache implemented in src/cache.ts of quota-axi. Quota snapshots live at ~/.cache/quota-axi/quotas.json, or under $XDG_CACHE_HOME when that variable is set, with files created at 0600 and directories at 0700. Records hold only normalized, non-secret snapshot structures. Raw HTTP responses, headers, bearer tokens, refresh tokens, API keys and browser cookies must never be persisted.

To prevent cross-account or cross-environment cache poisoning, providers whose identity depends on configuration are enrolled in CONTEXT_SCOPED_PROVIDERS: Claude, Kimi, Command Code, MiniMax, ElevenLabs, Devin, Muse and Codex. Each snapshot carries an opaque SHA-256 context identifier derived from the answering configuration, such as a hashed profile or credential source, a host, or a one-way digest of the key, never the key itself. Kimi's identifier uses the home path plus the slot and base URL, so mainland China snapshots cannot serve as global fallbacks.

When your agent uses it

  • Changing how quota-axi caches provider quota snapshots
  • Adding a provider and deciding whether it needs context scoping
  • Reviewing cache code to be sure no secrets reach disk

Example prompts

  • “Add a new provider to quota-axi and tell me if it needs a context identifier.”
  • “Check that the cache code never writes tokens or raw responses to disk.”
  • “Why was a Kimi snapshot reused across accounts? Look at how context scoping works.”

Requirements

  • The quota-axi source, including src/cache.ts

What it can do on your machine

Read from SKILL.md and the folder at commit 0f524bd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • META_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Quota Cache Architecture loads about 1.3k tokens when it runs. Until then it costs about 32 tokens; SKILL.md has 635 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kunchenguid/quota-axi at commit 0f524bd, republished under its MIT licence (© kunchenguid). 635 words, ~1,271 tokens.

Download SKILL.mdSave it as .claude/skills/cache-architecture/SKILL.md (or your agent's skills folder).
name
cache-architecture
description
Cache storage locations, permissions, context scoping, isolation rules, and lifecycle management in quota-axi.
user-invocable
false

Quota Cache Architecture & Context Scoping

This document details the disk caching architecture, file permissions, context-scoping mechanism, and data retention policies implemented in src/cache.ts.


Cache Storage & Security

  • Path: ~/.cache/quota-axi/quotas.json, or $XDG_CACHE_HOME/quota-axi/quotas.json if XDG_CACHE_HOME is set.
  • File Permissions: Cache files and parent directories must be created with strict 0600 (read/write by owner only) and 0700 permissions.
  • Normalized Data Only: Cache records contain only normalized, non-secret quota snapshot structures.
  • Strict Prohibition: Never persist raw HTTP responses, headers, authorization bearers, refresh tokens, API keys, or browser cookies.

Context-Scoped Providers (CONTEXT_SCOPED_PROVIDERS)

To prevent cross-account or cross-environment cache poisoning, providers whose identity is configuration-dependent or slot-shared are enrolled in CONTEXT_SCOPED_PROVIDERS in src/cache.ts:

  • Enrolled Providers: Claude, Kimi, Command Code, MiniMax, ElevenLabs, Devin, Muse, and Codex.
  • Context Identifiers: Snapshots carry an opaque SHA-256 context identifier derived from the answering configuration:
    • Claude: Hashed profile and credential-storage selection. claudeCredentialContextId appends an env marker so environment-token readings cannot be served as stale cache for stored-token accounts.
    • Kimi: Home path plus the slot and base URL resolved from config.toml (never the file contents, which contain keys). Prevents mainland China snapshots from serving as global fallbacks.
    • Command Code: Winning source plus the account identity validated by whoami.
    • MiniMax: Answering credential source plus deployment host.
    • ElevenLabs: Credential source plus a one-way SHA-256 digest of the answering API key.
    • Devin: Answering source, the first-party host it was sent to, and a one-way SHA-256 digest of the answering API key; the key never enters the cache.
    • Muse: Answering source plus a one-way SHA-256 digest of the credential that answered (the Muse CLI's stored OAuth access token or an exported META_API_KEY); a since-refreshed token is a cache miss, never a cross-attribution between accounts.
    • Codex: Hashed ChatGPT account ID stored by the specific credential that produced the reading (resolving collisions between lone discovered lanes and Pi entries).
  • Fallback Verification: Stale cache fallback rejects legacy unstamped snapshots or snapshots whose context ID does not match the active configuration.
  • Codex exception: Codex stamps are optional at write time, but stale serving requires ownership. readCachedCodexProvider withholds an unstamped snapshot, and withholds a snapshot whose stored account id is not among the ids the failed reading's tried credentials actually named; a sibling never probed does not vouch for it, and a transient failure is vouched for only by its own credential. A reading whose tried credentials name no account establishes nothing and is withheld from stale fallback. Contract: README Cache.
  • Skip on Unconfirmed: If a reading cannot confirm context identity (e.g. unreadable configuration), quota-axi skips both writing to cache and clearing the cache slot.

Show full SKILL.md (213 more words)Show less

Cache Lifecycle & Exclusions

The following fields and statuses are never cached:

  • Non-fresh or empty reads: Only readings with state.status: "fresh", at least one window, and a source other than cache are written (toCacheProvider); every other status and every cache-served report is skipped. failed is an attempt status, not a provider state.status.
  • Stale reads: Stale data is never re-persisted as fresh.
  • Account identities: Explicit account objects are scrubbed before writing.
  • Source attempts: The report's attempts list and attempt diagnostic logs are excluded.
  • Derived pace & runway: pace, runway, and selection signals are dynamic derivations computed from generatedAt vs current time. They must never be frozen into cache.

PHI-safe job counts (jobs.sampled / completed / failed / other) are stored with the snapshot the same way credits is. A snapshot that never carried jobs stays without them; prompts, URLs, ids, and account identity never enter the cache. Higgsfield is excluded from --max-age fresh reuse (excludeFromFreshReuse), matching Muse: a CLI login switch is not a traced file, and the status payload has no stable non-email account discriminator.


Keychain Access Markers

  • Stored alongside the cache directory in ~/.cache/quota-axi/.
  • Must have 0600 permissions.
  • Filename is keyed by a hash of the selected service and account name. Contains no secret material.
  • Permits non-prompting subsequent Keychain value reads once an initial grant is confirmed.

© kunchenguid, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cache-architecture of kunchenguid/quota-axi.

Open the folder on GitHubat commit 0f524bd

Compare with similar skills

Quota Cache Architecture next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Quota Cache Architecture compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Quota Cache Architecture this skillkunchenguid/quota-axi144—~1.3kAutomated safety check: PassMIT
Frontmcp Configagentfront/frontmcp146—~7kAutomated safety check: PassApache-2.0
Roo Fix Volatile MsgOnlyTerp/prompt-cache-skills114—~1kAutomated safety check: PassCustom licence
WordPress Code GuardamElnagdy/guard-skills1.3k—~2.4kAutomated safety check: PassMIT
WordPress ProJeffallan/claude-skills12k—~1.6kAutomated safety check: PassMIT
Reasoning Serialization Teststailcallhq/forgecode7.6k—~1kAutomated safety check: PassApache-2.0

Similar skills

  • Frontmcp Config

    agentfront/frontmcp

    A skill your agent uses when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options.

    146 GitHub stars~7k tokensUpdated today
    Backend & APIsAuto-check passed
  • Roo Fix Volatile Msg

    OnlyTerp/prompt-cache-skills

    Ladder-aware Roo Code Anthropic caching — verify the rolling read/write ladder on the wire, then close the real gaps (Vertex 4-block budget, MiniMax path).

    114 GitHub stars~1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • WordPress Code Guard

    amElnagdy/guard-skills

    Reviews WordPress plugin, theme and block code after an agent writes or edits it, catching missing escaping, nonces, capability checks and unprepared queries.

    1.3k GitHub stars~2.4k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • WordPress Pro

    Jeffallan/claude-skills

    Develops WordPress themes, plugins, Gutenberg blocks and WooCommerce features with nonce, escaping and capability checks, phpcs linting and caching tuned for speed.

    12k GitHub stars~1.6k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Reasoning Serialization Tests

    tailcallhq/forgecode

    Checks that ReasoningConfig fields are serialized into the right provider-specific JSON for OpenRouter, Anthropic, GitHub Copilot and Codex requests.

    7.6k GitHub stars~1k tokensUpdated today
    Testing & QAAuto-check passed
  • Subagent

    ethanhq/cc-fleet

    Fan out a one-shot or flat parallel batch of cc-fleet PROVIDER subagents (headless cc-fleet subagent) that return a result — DeepSeek / GLM / Kimi / Qwen / MiniMax, or a Codex/Claude subscription.

    215 GitHub stars~4.9k tokensUpdated 8 days ago
    Agent WorkflowsAuto-check passed

More from kunchenguid/quota-axi

  • quota-axi Release and CI Rules

    kunchenguid/quota-axi

    Documents release automation, CI workflow constraints, the contribution gate and generated-file rules for the quota-axi repository, driven by release-please.

    144 GitHub stars~934 tokensUpdated today
    Auto-check passed
  • Quota Provider Adapter Notes

    kunchenguid/quota-axi

    Reference of credential sources, quota windows, endpoint shapes, error recovery and quirks for each provider supported by the quota-axi tool.

    144 GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • Quota Provider Onboarding

    kunchenguid/quota-axi

    Sets the rules and checklist for adding a new quota provider, or changing an existing adapter, in quota-axi, covering credential sources, liveness probes and tests.

    144 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Quota Interpretation Rules

    kunchenguid/quota-axi

    Specifies how quota-axi reads LLM subscription quota windows, derives pace and runway, computes a selection signal and renders output in TOON, JSON and TUI tiers.

    144 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Quota Axi

    kunchenguid/quota-axi

    Report local Claude, Codex, Cursor, GitHub Copilot, Grok, Kimi, Z.AI, Alibaba, OpenCode Go, Antigravity, Command Code, MiniMax, MiMo, DeepSeek, OpenRouter, ElevenLabs, Devin, Muse, and Higgsfield…

    144 GitHub stars~547 tokensUpdated today
    Auto-check passed

Questions about Quota Cache Architecture

What does Quota Cache Architecture do?

Documents how quota-axi keeps its disk cache: location, strict file permissions, no stored secrets, and context-scoped identifiers that stop snapshots crossing accounts. ts of quota-axi.json, or under $XDG_CACHE_HOME when that variable is set, with files created at 0600 and directories at 0700.

When should I use Quota Cache Architecture?

Quota Cache Architecture fits situations like: changing how quota-axi caches provider quota snapshots; adding a provider and deciding whether it needs context scoping; reviewing cache code to be sure no secrets reach disk.

How do I install Quota Cache Architecture in Claude Code?

Run `npx skills add kunchenguid/quota-axi --skill cache-architecture -a claude-code`. Or copy the skill folder (skills/cache-architecture in kunchenguid/quota-axi) into .claude/skills/cache-architecture in your project. Claude Code loads it when a task matches its description.

How do I install Quota Cache Architecture in Codex?

Run `npx skills add kunchenguid/quota-axi --skill cache-architecture -a codex`. Or copy the skill folder (skills/cache-architecture in kunchenguid/quota-axi) into .agents/skills/cache-architecture in your project. Codex loads it when a task matches its description.

Can I use Quota Cache Architecture in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kunchenguid/quota-axi --skill cache-architecture -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cache-architecture, .gemini/skills/cache-architecture, .github/skills/cache-architecture and .opencode/skills/cache-architecture in your project.

What does Quota Cache Architecture need to run?

Going by SKILL.md and its folder, Quota Cache Architecture needs credentials named META_API_KEY. Our summary lists: The quota-axi source, including src/cache.ts.

Does Quota Cache Architecture access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Quota Cache Architecture safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Quota Cache Architecture use?

Quota Cache Architecture is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Quota Cache Architecture use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Quota Cache Architecture?

Skills that share tags, products or a category with Quota Cache Architecture: Frontmcp Config (agentfront/frontmcp, 146 stars), Roo Fix Volatile Msg (OnlyTerp/prompt-cache-skills, 114 stars), WordPress Code Guard (amElnagdy/guard-skills, 1.3k stars) and WordPress Pro (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Quota Cache Architecture?

kunchenguid (a GitHub user) maintains it in kunchenguid/quota-axi, which has 144 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 7, 2026.

Source: kunchenguid/quota-axi on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.