Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/lookatitude/guild/configgit clone --depth 1 https://github.com/lookatitude/guildWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00421 | $0.07208 |
| Opus 5 | $0.00211 | $0.03604 |
| Sonnet 5 | $0.00084 | $0.01442 |
| Haiku 4.5 | $0.00042 | $0.00721 |
Grade A, and why
config scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 448 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/guild:config — project config surface (.guild/settings.json)
.guild/settings.json is the single v2 config file. It carries every Guild
option; CLI flags always override it (full 7-source precedence ladder,
lowest to highest: builtin < workspace < workspace-local < project < project-local < rigor < CLI).
It replaces the v1
.guild/config.yml; the runtime config.yml reader was removed in v2.0 —
config.yml is never read at runtime. To convert an old config.yml, run
/guild:migrate. The schema is closed-key: unknown defaults.* keys are
rejected so a typo surfaces.
The sub-verb is the first positional argument.
init — scaffold .guild/settings.json (= reconcile sync)
config init is now a wrapper around reconcile sync (P1-L9). It materializes the
config with every key set to its schema default plus a self-documenting _help block,
but goes through the reconciler so it is never-clobber + provenance-aware: on a FRESH
repo the output is byte-identical to the legacy scaffold (golden-tested, default==today);
on a repo that already has .guild/settings.json it fills only missing keys, never
overwrites a user-set value, and records provenance + a last_reconciled_at timestamp.
# config init == reconcile sync (never-clobber; fills missing keys to defaults)
npx tsx ${GUILD_PLUGIN_ROOT:-${CLAUDE_PLUGIN_ROOT:-$HOME/.local/share/guild/dist/claude-code}}/scripts/config-cmd.ts reconcile sync --cwd "$(pwd)"
Steps:
- Ensure
.guild/exists. - Run
config-cmd.ts reconcile sync— it writes/updates.guild/settings.json, filling missing keys to their defaults without clobbering any user-set value (no--forceneeded; the never-clobber guard replaces it), and stamps provenance +last_reconciled_at. On a fresh repo this equals the old--scaffoldoutput byte-for-byte. - If a legacy
.guild/config.ymlis present, tell the operator to run/guild:migrateto convert it tosettings.json—config.ymlis not read at runtime in v2 (the back-compat reader was removed in v2.0).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 448 lines · 421 tokens per session scan A b436d28f20c2
config is a command published in the GitHub repository lookatitude/guild (7 stars, last pushed 2d ago), licensed MIT. It adds 421 tokens to every session and 7,208 once invoked, about $0.0021 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
checklist
Generate a custom checklist for the current feature based on user requirements.
clarify
Identify underspecified areas in the current feature spec by asking up to 5 highly targeted clarification questions and encoding answers back into the spec.
specify
Create or update the feature specification from a natural language feature description.
analyze
Perform a non-destructive cross-artifact consistency and quality analysis across spec.md, plan.md, and tasks.md after task generation.
converge
Assess the current codebase against the feature's spec, plan, and tasks, then append any remaining unbuilt work as new tasks to tasks.md so implement can complete it.
implement
Execute the implementation plan by processing and executing all tasks defined in tasks.md.