gum-call

A command-line command for running named catalog operations through the gum tool. It accepts key-value, JSON, or file-based arguments, checks that the requested risk level matches the operation, and can format results in several ways.

In plain words
What is it for?
Use it to run catalog operations, pass their arguments, confirm destructive variants, select fields, and output results as tables, JSON, CSV, Markdown, or other supported formats.
Why use it?
It provides one controlled entry point for catalog requests and helps prevent using the wrong safety level for an operation.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/ehmo/gum/gum-call
Clone the repo
git clone --depth 1 https://github.com/ehmo/gum
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 669 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00669
Opus 5 $0.00000 $0.00334
Sonnet 5 $0.00000 $0.00134
Haiku 4.5 $0.00000 $0.00067

Measured yesterday against content hash 12c2658faba5, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

gum-call scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

docs/commands/gum-call.md · 55 lines

How it starts

The opening of the file, as written. The whole thing — 55 lines — stays where its author put it; the contents beside it link to each section on GitHub.

gum call

Generated from gum schema --json. Do not edit this page by hand; run make docs-commands.

gum call is the deterministic CLI entry point for catalog operations. Positional args use key=value, key:=json, and @file forms. The risk flag MUST match the resolved variant's risk_class or the call returns RISK_TOOL_MISMATCH before any upstream request.

Usage

gum call <op_id> --risk=<read|write|destructive> [args...] [flags]

Parent

Arguments

Name Help
op_id
args

Flags

Flag Type Default Help
--confirmed bool false Set the signed-confirmation flag for destructive variants
--csv bool false Render output as CSV
--fields string Field mask sent to the upstream API (host control)
--json bool false Render output as JSON (default when piped)
--markdown bool false Render output as Markdown
--no-field-mask bool false Disable upstream field_mask injection
-o--output string Output format: table|json|toon|csv|markdown|raw|value() (default: table on a terminal, json when piped)
--page-size int 0 Page size for paginated reads (host control)
--page-token string Page token for paginated reads (host control)
--raw bool false Return the raw upstream JSON without shaping
--risk string Risk path: read|write|destructive (required)
--skeleton bool false Print a fillable template of the op's request fields and exit (no upstream call)
--token string HMAC-SHA256 confirmation token returned by a prior destructive attempt
--toon bool false Render output as TOON
--variant-id string Pin variant_id (default: op's default_variant_id)
--yes bool false Deprecated: destructive variants require --confirmed --token
--log-format string json Log format: json|text
--log-level string info Log level: debug|info|warn|error (overrides GUM_LOG_LEVEL)
--profile string default Profile name to read/write config under

Read the full file on GitHub · 55 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 55 lines · 0 tokens per session scan A 12c2658faba5

Subscribe to this mod's changes

gum-call is a command published in the GitHub repository ehmo/gum (31 stars, last pushed 24d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 669 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.