Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/omrikais/cctally/setupgit clone --depth 1 https://github.com/omrikais/cctallyWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.03467 |
| Opus 5 | $0.00000 | $0.01733 |
| Sonnet 5 | $0.00000 | $0.00693 |
| Haiku 4.5 | $0.00000 | $0.00347 |
Grade B, and why
setup scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
`~/.claude/settings.json` when Claude Code is initialized, and independently How it starts
The opening of the file, as written. The whole thing — 241 lines — stays where its author put it; the contents beside it link to each section on GitHub.
cctally setup
Install cctally into each available local provider. It symlinks user-facing
binaries into ~/.local/bin/, adds Claude hook entries to
~/.claude/settings.json when Claude Code is initialized, and independently
manages native Codex handlers in every configured Codex home. A Codex-only
machine does not need a ~/.claude/ directory.
Modes
| Mode | What it does |
|---|---|
cctally setup |
Install (default) |
cctally setup --dry-run |
Show planned changes; modify nothing |
cctally setup --status |
Report current install state |
cctally setup --uninstall |
Remove hooks + symlinks; keep history |
cctally setup --uninstall --purge |
Also wipe ~/.local/share/cctally/ |
Common flags
--yes/-y— skip confirmations--json— emit machine-readable output--force-dev— allow setup to run from a git checkout (see Dev-checkout refusal)--migrate-legacy-hooks— auto-accept the legacy-hook migration prompt (install-mode only)--no-migrate-legacy-hooks— auto-decline the legacy-hook migration prompt (install-mode only)
Dev-checkout refusal
When run from a git checkout (a .git entry at the repo root), cctally setup — both install and --uninstall — refuses with exit code 2 and
prints a message explaining why, without touching ~/.claude/settings.json.
The hooks in settings.json point at your installed (npm/brew) cctally;
rewriting them from a dev checkout would repoint them at the dev binary (or
remove them), breaking the installed instance. Run setup from the installed
binary instead, or pass --force-dev to override when you intend to install
dev-pointing hooks. The refusal is independent of CCTALLY_DATA_DIR: setting
that env var relocates the dev data dir but still does not let setup rewrite
the prod hooks.
Upgrade self-heal (new symlinks)
When you upgrade via npm install -g cctally@<newer> and that release ships a
new cctally-<subcmd> binary, its ~/.local/bin/ symlink would normally be
missing until you re-ran cctally setup (doctor would warn about the missing
link in the meantime). The npm postinstall now best-effort runs an internal
repair-symlinks pass to close that gap: it additively creates ~/.local/bin/
symlinks for any newly added subcommands, so they become reachable immediately
after the upgrade with no manual step.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 241 lines · 0 tokens per session scan B 8c48b197e930
setup is a command published in the GitHub repository omrikais/cctally (5 stars, last pushed 3d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 3,467 tokens. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
checklist
Generate a custom checklist for the current feature based on user requirements.
clarify
Identify underspecified areas in the current feature spec by asking up to 5 highly targeted clarification questions and encoding answers back into the spec.
specify
Create or update the feature specification from a natural language feature description.
analyze
Perform a non-destructive cross-artifact consistency and quality analysis across spec.md, plan.md, and tasks.md after task generation.
converge
Assess the current codebase against the feature's spec, plan, and tasks, then append any remaining unbuilt work as new tasks to tasks.md so implement can complete it.
implement
Execute the implementation plan by processing and executing all tasks defined in tasks.md.