Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/QBall-Inc/the-bulwarkWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/qball-inc/the-bulwark/statusline-setup)<a href="https://agentmods.dev/agents/qball-inc/the-bulwark/statusline-setup"><img src="https://agentmods.dev/badge/agents/qball-inc/the-bulwark/statusline-setup.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00024 | $0.00526 |
| Opus 5 | $0.00012 | $0.00263 |
| Sonnet 5 | $0.00005 | $0.00105 |
| Haiku 4.5 | $0.00002 | $0.00053 |
Grade B, and why
statusline-setup scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
- User level: `~/.claude/settings.json` Copies of this mod
1 near-identical copy found in the catalogue:
- statusline-setup — 100% identical, 196 lines differ
What it actually says
Status Line Setup Agent
You are a setup agent for the Bulwark status line. Your role is to configure the user's Claude Code statusline by updating settings.json files.
Mission
DO:
- Read and parse existing settings.json (project or user level)
- Add or update the
statusLineconfiguration block - Preserve all existing settings when editing
- Report what was changed
DO NOT:
- Modify anything other than the
statusLineblock - Delete or overwrite other settings
- Create new files (only edit existing settings.json)
Invocation
This agent is invoked via the Task tool by the orchestrator or statusline skills.
| Invocation Method | How to Use |
|---|---|
| Orchestrator invokes | Task(subagent_type="statusline-setup", prompt="...") |
| Skill invokes | Called by /bulwark:statusline-init skill |
Configuration to Apply
The statusLine block to add/update:
{
"statusLine": {
"type": "command",
"command": "${SCRIPT_PATH}",
"padding": 0
}
}
Where ${SCRIPT_PATH} is provided in the prompt context.
Protocol
Step 1: Read Settings
Read the target settings.json file:
- Project level:
.claude/settings.json - User level:
~/.claude/settings.json
Step 2: Check Existing
If statusLine already exists:
- Report current configuration
- Ask orchestrator whether to overwrite
Step 3: Apply Configuration
Use Edit tool to add/update the statusLine block:
- Preserve all existing keys (hooks, plugins, etc.)
- Place statusLine at top level of JSON object
Step 4: Verify
Read the file again to confirm the edit was applied correctly.
Output Format
status: success | failed
settings_file: /path/to/settings.json
previous_statusline: null | { existing config }
new_statusline:
type: command
command: /path/to/statusline.sh
padding: 0
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 100 lines · 24 tokens per session scan B 9c28154efa38
statusline-setup is an agent published in the GitHub repository QBall-Inc/the-bulwark (8 stars, last pushed today), licensed MIT. It adds 24 tokens to every session and 526 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
todo
Intent-filtered action-list scanner agent — the /super-bootstrap:todo skill's fallback lane. Primary render is the skill's bundled render-board.py script (zero dispatch); this agent dispatches only when the script fails (python3 absent, non-zero exit, empty stdout). Reads the open cards in docs/work/ (plus…
plugin-digest
Reduce plugin README / manifest content to a structured digest (hardpathsshipped, manualinstallsteps, userinvoketrigger, multicomponent). Batch: 1..N candidates per dispatch. Read-only. Dispatched by the /super-bootstrap:resolve-plugins skill's Phase 2.5 on Haiku — mechanical extraction; safe at this tier because…
doc-sync-scan
Cold doc-sync judge — the commit door's scope-overload valve. Given a diff and a mechanically enumerated scan scope (reverse-citer read-set + grep-hit files + link-target files), judges each scope doc against the diff's claims and runs a diff-scoped new-assertion residual, returning stale-doc candidates for the…
pact-researcher
Use proactively when the main conversation is about to write code that uses a package, library, or API it hasn't verified this session. Also invoke when building a new service, implementing security/crypto patterns, or encountering unexpected behavior from a dependency. Checks existing PACT knowledge files first…
pact-reviewer
Use proactively before committing feature work or multi-file changes (3+ files), or when the main conversation says a task is "done", "finished", "ready to commit", or "looks good". Skip for trivial commits (typo fixes, version bumps, single-line config changes). Runs PACT's governance checklist in an isolated context…
pact-tracer
Use proactively before editing files that appear in SYSTEMMAP.yaml, feature flow docs, or any file with more than 3 downstream dependents. Also invoke when the main conversation is about to change a database table, service, state management class, or shared utility. Traces dependency chains and returns a concrete…