setup

An installer and manager for connecting cctally to the local Claude Code and Codex setups. It creates command links and configures the relevant hooks or handlers.

In plain words
What is it for?
Use it to install cctally, preview planned changes, check installation status, migrate older hooks, or uninstall the connections.
Why use it?
It removes the need to connect each coding-agent provider by hand and keeps their integrations managed separately. It can also show the current state or remove the integration while keeping history.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/omrikais/cctally/setup
Clone the repo
git clone --depth 1 https://github.com/omrikais/cctally
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 3,467 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.03467
Opus 5 $0.00000 $0.01733
Sonnet 5 $0.00000 $0.00693
Haiku 4.5 $0.00000 $0.00347

Measured yesterday against content hash 8c48b197e930, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

setup scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Reads agent configuration directoriesmediumAgent snooping

.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.

`~/.claude/settings.json` when Claude Code is initialized, and independently
docs/commands/setup.md · 241 lines

How it starts

The opening of the file, as written. The whole thing — 241 lines — stays where its author put it; the contents beside it link to each section on GitHub.

cctally setup

Install cctally into each available local provider. It symlinks user-facing binaries into ~/.local/bin/, adds Claude hook entries to ~/.claude/settings.json when Claude Code is initialized, and independently manages native Codex handlers in every configured Codex home. A Codex-only machine does not need a ~/.claude/ directory.

Modes

Mode What it does
cctally setup Install (default)
cctally setup --dry-run Show planned changes; modify nothing
cctally setup --status Report current install state
cctally setup --uninstall Remove hooks + symlinks; keep history
cctally setup --uninstall --purge Also wipe ~/.local/share/cctally/

Common flags

  • --yes / -y — skip confirmations
  • --json — emit machine-readable output
  • --force-dev — allow setup to run from a git checkout (see Dev-checkout refusal)
  • --migrate-legacy-hooks — auto-accept the legacy-hook migration prompt (install-mode only)
  • --no-migrate-legacy-hooks — auto-decline the legacy-hook migration prompt (install-mode only)

Dev-checkout refusal

When run from a git checkout (a .git entry at the repo root), cctally setup — both install and --uninstall — refuses with exit code 2 and prints a message explaining why, without touching ~/.claude/settings.json. The hooks in settings.json point at your installed (npm/brew) cctally; rewriting them from a dev checkout would repoint them at the dev binary (or remove them), breaking the installed instance. Run setup from the installed binary instead, or pass --force-dev to override when you intend to install dev-pointing hooks. The refusal is independent of CCTALLY_DATA_DIR: setting that env var relocates the dev data dir but still does not let setup rewrite the prod hooks.

When you upgrade via npm install -g cctally@<newer> and that release ships a new cctally-<subcmd> binary, its ~/.local/bin/ symlink would normally be missing until you re-ran cctally setup (doctor would warn about the missing link in the meantime). The npm postinstall now best-effort runs an internal repair-symlinks pass to close that gap: it additively creates ~/.local/bin/ symlinks for any newly added subcommands, so they become reachable immediately after the upgrade with no manual step.

Read the full file on GitHub · 241 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 241 lines · 0 tokens per session scan B 8c48b197e930

Subscribe to this mod's changes

setup is a command published in the GitHub repository omrikais/cctally (5 stars, last pushed 3d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 3,467 tokens. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.