Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/christopherkahler/paul/configgit clone --depth 1 https://github.com/ChristopherKahler/paulWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/christopherkahler/paul/config)<a href="https://agentmods.dev/commands/christopherkahler/paul/config"><img src="https://agentmods.dev/badge/commands/christopherkahler/paul/config.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00800 |
| Opus 5 | $0.00000 | $0.00400 |
| Sonnet 5 | $0.00000 | $0.00160 |
| Haiku 4.5 | $0.00000 | $0.00080 |
Grade A, and why
config scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
<when_to_use>
- Enable SonarQube after project init
- Disable an integration
- View current configuration
- Change project settings </when_to_use>
Step 1: Check for existing config
ls .paul/config.md 2>/dev/null
If config exists:
Current configuration:
[Display config.md contents]
What would you like to do?
[1] Enable/disable integration
[2] View full config
[3] Reset to defaults
If config doesn't exist:
No configuration found.
Would you like to set up project configuration?
[1] Yes, create config
[2] Cancel
Step 2: Handle user choice
For new config or "Enable/disable integration":
Available integrations:
[1] SonarQube - Code quality scanning
Status: [enabled/disabled/not configured]
[2] Enterprise Plan Audit - Architectural review gate
Status: [enabled/disabled/not configured]
[3] Done - save and exit
If user selects SonarQube:
SonarQube integration:
Current: [enabled/disabled/not configured]
[1] Enable
[2] Disable
[3] Back
If enabling:
- Prompt for project_key (default: directory name)
- Create/update config.md with sonarqube.enabled = true
If disabling:
- Update config.md with sonarqube.enabled = false
If user selects Enterprise Plan Audit:
Enterprise Plan Audit:
Current: [enabled/disabled/not configured]
[1] Enable
[2] Disable
[3] Back
If enabling:
- Create/update config.md with enterprise_plan_audit.enabled = true
- Inform: "After /paul:plan, you'll be prompted to run /paul:audit before APPLY."
If disabling:
- Update config.md with enterprise_plan_audit.enabled = false
- Inform: "Plans will go directly from PLAN to APPLY without audit suggestion."
Step 3: Write config
Create or update .paul/config.md:
# Project Config
**Project:** [project_name]
**Updated:** [timestamp]
## Project Settings
```yaml
project:
name: [project_name]
version: [version or "0.0.0"]
Integrations
SonarQube
sonarqube:
enabled: [true/false]
project_key: [key]
Enterprise Plan Audit
enterprise_plan_audit:
enabled: [true/false]
Preferences
preferences:
auto_commit: false
verbose_output: false
Config updated: [timestamp]
**Step 4: Confirm**
════════════════════════════════════════ CONFIG UPDATED ════════════════════════════════════════
Integrations: SonarQube: [enabled/disabled] Enterprise Plan Audit: [enabled/disabled]
Config saved to: .paul/config.md
──────────────────────────────────────── [If SonarQube just enabled:] ▶ NEXT: /paul:quality-gate Run your first code quality scan.
[If Enterprise Plan Audit just enabled:] ▶ Enterprise audit will run between PLAN and APPLY. After /paul:plan, you'll be prompted to run /paul:audit.
[Otherwise:] Configuration complete. ────────────────────────────────────────
</process>
<output>
- `.paul/config.md` created or updated
- Integration status changed as requested
- Clear next steps if applicable
</output>
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 176 lines · 0 tokens per session scan A bc39f76cc7a1
config is a command published in the GitHub repository ChristopherKahler/paul (1,212 stars, last pushed 13d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 800 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
safe-refactor
Safe refactoring with automated review, testing, and rollback capabilities.
security-review
Comprehensive security analysis with multi-layer vulnerability detection.
test
Smart test runner with filtering, coverage, and health monitoring.
implement-spec
Implement specification with full traceability and test-driven development.
refactor
Interactive refactoring assistant based on Martin Fowler's refactoring catalog.
deploy_to_docker
Build Docker image and start/redeploy the MCP Task Orchestrator container, reusing the last-used config by default.