Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/piyushkhemka/sip/sip-setupgit clone --depth 1 https://github.com/piyushkhemka/sipWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/piyushkhemka/sip/sip-setup)<a href="https://agentmods.dev/commands/piyushkhemka/sip/sip-setup"><img src="https://agentmods.dev/badge/commands/piyushkhemka/sip/sip-setup.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00021 | $0.00388 |
| Opus 5 | $0.00010 | $0.00194 |
| Sonnet 5 | $0.00004 | $0.00078 |
| Haiku 4.5 | $0.00002 | $0.00039 |
Grade B, and why
sip-setup scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
description: Enable the Sip main status line by wiring it into your ~/.claude/settings.json. What it actually says
Set up Sip 💧
Wire this plugin's sip.sh into the user's main Claude Code status line.
Steps:
-
Determine the absolute path to the plugin's
sip.sh. If theCLAUDE_PLUGIN_ROOTenvironment variable is available, it is${CLAUDE_PLUGIN_ROOT}/sip.sh. Otherwise locate the installed plugin directory (it containssip.shand.claude-plugin/plugin.json). -
Run the bundled setup script. It installs a stable, self-contained copy of
sip.shto~/.claude/sip.shand idempotently sets thestatusLinekey in~/.claude/settings.jsonto point there (backing up the current file first). Because the copy is location-independent, the status line keeps working even if the plugin's versioned cache directory changes on update — just re-run this command after updating to refresh the copy."${CLAUDE_PLUGIN_ROOT}"/scripts/enable.shIf
CLAUDE_PLUGIN_ROOTis not set, runscripts/enable.shfrom the plugin directory, or pass the path explicitly:SIP_PATH="/abs/path/to/sip.sh" /abs/path/to/scripts/enable.sh -
Confirm the result to the user and tell them to reload Claude Code (the status line refreshes on the next interaction). Report the exact
commandpath that was written.
To remove it later, delete the statusLine key from ~/.claude/settings.json
or restore one of the settings.json.bak.* backups the script created.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 41 lines · 21 tokens per session scan B 3615c5b98cfb
sip-setup is a command published in the GitHub repository piyushkhemka/sip (3 stars, last pushed 1mo ago), licensed MIT. It adds 21 tokens to every session and 388 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
timestamps
Configure claude-timestamp (timezone, clock format, colour, elapsed time).
profile
Show or change which Claude account this directory uses.
tmux-squad
Open a grid of panes for watching several agents at once — one primary plus N workers.
setup
Configure the statusline in Claude Code settings.
tmux-project
Open (or reuse) a project workspace session — server / agent / editor.
tmux-status
Show every live tmux session, pane, and exit code, with attach commands.