Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/caspian-sun/claude-code-workflow/plan-checkgit clone --depth 1 https://github.com/Caspian-Sun/claude-code-workflowWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.02072 |
| Opus 5 | $0.00000 | $0.01036 |
| Sonnet 5 | $0.00000 | $0.00414 |
| Haiku 4.5 | $0.00000 | $0.00207 |
Grade A, and why
plan-check scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 150 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are now a task list completeness checker. Run hard-gate checks against the input tasks.json and output whether it can proceed to the /code coding phase.
Applicable Scenarios
- User wants to verify if a task list is executable — quick health check after
/plangenerates it - Mandatory pre-check for
/code—/codemust run this command first; if it fails, coding is refused
Input
@docs/tasks/tasks-xxx.jsonpath → read directly- No path → stop and ask: "Please specify the task list path, e.g.: /plan-check @docs/tasks/tasks-login-2026-04-15.json"
Checks (run in order, no short-circuit — report all issues at once)
Check 1: Valid Structure (P0)
Validate JSON structure:
- Required fields:
moduleCode/prdRef/tasks[]/createdAt - Each item in
tasks[]must contain:taskId/type/name/filePath/description/prdRef/businessRules/acceptanceCriteria/status typemust be one of:precondition | gen-api | api | mock | constants | utils | locale | config | model | store | hook | wrapper | component | pagestatusmust be one of:pending | in-progress | done | blockedtaskIdmust be globally unique (no duplicates)
Note: Infrastructure types (
precondition/constants/utils/locale/config/model/wrapper) are for i18n, route guards, access config, constants, utilities, runtime config, and other non-api/component/page engineering files.
On failure: list the violating taskIds and specific field issues
Check 2: Valid Dependency Graph (P0)
Perform graph-theory validation on tasks[].dependencies arrays:
- No dangling references: every taskId in dependencies must actually exist
- No circular dependencies: detect cycles via topological sort
- No forward references: dependent taskId must appear before the current taskId in array order
On failure: list problematic edges (A → B does not exist / A → B → A cycle / A appears before B but depends on B)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 150 lines · 0 tokens per session scan A 66c82e1d3108
plan-check is a command published in the GitHub repository Caspian-Sun/claude-code-workflow (10 stars, last pushed 5d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 2,072 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
vibe-agents
Step 4 of the vibe-coding workflow: generate AGENTS.md + tool configs so the AI builder stays on track.
mass-line
用群众路线收集多源信息、整合反馈并返回验证。.
sync-linear
Sync current work with Linear ticket status.
ship
Deliver the increment. Then go live with a rollback you have run.
fest-show
Show festival progression (in-progress tasks, roadmap, and dependency view).
generate-rules
Generate development rules and standards into RULES.md.