Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/quantumwars/project-graphx/setup-globalgit clone --depth 1 https://github.com/QuantumWars/project-graphxWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00018 | $0.01463 |
| Opus 5 | $0.00009 | $0.00732 |
| Sonnet 5 | $0.00004 | $0.00293 |
| Haiku 4.5 | $0.00002 | $0.00146 |
Grade B, and why
setup-global scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
`~/.claude/settings.json`: How it starts
The opening of the file, as written. The whole thing — 133 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Point every project at a single shared graph, so a skill catalogued once is visible everywhere and a note written in one project is readable from another.
Decide this first, out loud
The default is one graph per project, and that is the right default for most people: two projects never see each other's data, and nothing follows you between unrelated repos. Going global trades that away deliberately. Say so before changing anything, and get an explicit yes.
Going global means:
- Every project on this machine reads and writes the same
graph-data.jsonandoverlay.json. - Per-project graphs already built are not deleted, but they stop being read. They are still on disk
at
<project>/.claude/graph/and become live again if the setting is removed. - Notes, ratings and tags become machine-wide rather than belonging to one repo.
- One build serves everything, so
/skill-graph:buildfrom any project rebuilds the shared graph.
If the user only wants "the same skills visible everywhere" and does not want shared notes, stop
here and use /skill-graph:setup instead with absolute source roots — relative roots resolve
against the project, absolute ones do not, so several projects can catalogue the same folders while
keeping separate graphs. That needs no settings change and no restart.
1. Choose where the shared graph lives
Ask. Offer ~/.claude/graph as the default, and say plainly what it means: this is machine-wide
state living in the home directory rather than travelling with any repository. If the user keeps
agent data inside projects as a rule, this is the deliberate exception, and it is worth them saying
yes to rather than discovering later.
Anywhere writable works — a Dropbox folder, a synced directory, a path already under backup.
2. Find every source on the machine
Sources here must be absolute paths, because this config is read from every project and a relative root would resolve somewhere different each time.
Search the user's code directories for **/.claude/agents, **/.claude/skills, and any agents/
or skills/ folder belonging to a plugin, pruning node_modules. Show what you found with counts
and let the user cut the list before writing it — a machine-wide search finds vendored copies and
abandoned experiments as readily as the real thing.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 133 lines · 18 tokens per session scan B 0ae26ab55d92
setup-global is a command published in the GitHub repository QuantumWars/project-graphx (1 stars, last pushed 13d ago), licensed MIT. It adds 18 tokens to every session and 1,463 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
checklist
Generate a custom checklist for the current feature based on user requirements.
clarify
Identify underspecified areas in the current feature spec by asking up to 5 highly targeted clarification questions and encoding answers back into the spec.
specify
Create or update the feature specification from a natural language feature description.
analyze
Perform a non-destructive cross-artifact consistency and quality analysis across spec.md, plan.md, and tasks.md after task generation.
converge
Assess the current codebase against the feature's spec, plan, and tasks, then append any remaining unbuilt work as new tasks to tasks.md so implement can complete it.
implement
Execute the implementation plan by processing and executing all tasks defined in tasks.md.