Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/christopherkahler/paul/plan-fixgit clone --depth 1 https://github.com/ChristopherKahler/paulWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/christopherkahler/paul/plan-fix)<a href="https://agentmods.dev/commands/christopherkahler/paul/plan-fix"><img src="https://agentmods.dev/badge/commands/christopherkahler/paul/plan-fix.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00015 | $0.01252 |
| Opus 5 | $0.00008 | $0.00626 |
| Sonnet 5 | $0.00003 | $0.00250 |
| Haiku 4.5 | $0.00002 | $0.00125 |
Grade A, and why
paul:plan-fix scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 217 lines — stays where its author put it; the contents beside it link to each section on GitHub.
When to use: After /paul:verify logs issues to phase-scoped UAT file.
Output: {plan}-FIX.md in the phase directory, ready for execution.
<execution_context>
@/.claude/paul-framework/references/plan-format.md
@/.claude/paul-framework/references/checkpoints.md
</execution_context>
@.paul/STATE.md @.paul/ROADMAP.md
$ARGUMENTS should be a plan number like "04-02" or "10-01". Extract phase number (XX) and plan number (NN).
If no argument provided:
Error: Plan number required.
Usage: /paul:plan-fix 04-02
This creates a fix plan from .paul/phases/XX-name/{plan}-UAT.md
Exit.
Search for matching UAT file:
ls .paul/phases/*/{plan}-UAT.md 2>/dev/null
If not found:
No UAT.md found for plan {plan}.
UAT.md files are created by /paul:verify when testing finds issues.
If no issues were found during testing, no fix plan is needed.
Exit.
Read the UAT.md file. Parse each issue:
- ID (UAT-NNN)
- Title
- Severity (Blocker/Major/Minor/Cosmetic)
- Description/steps to reproduce
- AC reference
Count total issues by severity.
For each issue (or logical group):
- Create one task per issue OR
- Group related minor issues into single task
Task structure:
<task type="auto">
<name>Fix UAT-001: [issue title]</name>
<files>[affected files from issue]</files>
<action>
[What to fix based on issue description]
[Reference original acceptance criteria]
</action>
<verify>[Test that issue is resolved]</verify>
<done>[Issue acceptance criteria met]</done>
</task>
Prioritize: Blocker → Major → Minor → Cosmetic
Create .paul/phases/XX-name/{plan}-FIX.md:
---
phase: XX-name
plan: {plan}-FIX
type: fix
wave: 1
depends_on: []
files_modified: [files from issues]
autonomous: true
---
<objective>
## Goal
Fix {N} UAT issues from plan {plan}.
## Purpose
Address issues discovered during user acceptance testing.
## Output
All issues resolved, ready for re-verification.
Source: {plan}-UAT.md
Priority: {blocker count} blocker, {major count} major, {minor count} minor, {cosmetic count} cosmetic
</objective>
<context>
@.paul/STATE.md
@.paul/ROADMAP.md
**Issues being fixed:**
@.paul/phases/XX-name/{plan}-UAT.md
**Original plan for reference:**
@.paul/phases/XX-name/{plan}-PLAN.md
</context>
<acceptance_criteria>
[Generate AC from issues - each issue becomes an AC]
</acceptance_criteria>
<tasks>
[Generated fix tasks]
</tasks>
<boundaries>
## DO NOT CHANGE
- Files not related to the issues
- Core functionality that passed testing
## SCOPE LIMITS
- Only fix issues from {plan}-UAT.md
- No scope creep or additional improvements
</boundaries>
<verification>
Before declaring plan complete:
- [ ] All blocker issues fixed
- [ ] All major issues fixed
- [ ] Minor/cosmetic issues fixed or documented as deferred
- [ ] Original acceptance criteria from issues met
</verification>
<success_criteria>
- All UAT issues from {plan}-UAT.md addressed
- Ready for re-verification with /paul:verify
</success_criteria>
<output>
After completion, create `.paul/phases/XX-name/{plan}-FIX-SUMMARY.md`
</output>
════════════════════════════════════════
FIX PLAN CREATED
════════════════════════════════════════
{plan}-FIX.md — {N} issues to fix
| Severity | Count |
|----------|-------|
| Blocker | {n} |
| Major | {n} |
| Minor | {n} |
| Cosmetic | {n} |
────────────────────────────────────────
Continue to APPLY?
[1] Approved, run APPLY | [2] Review first | [3] Pause here
────────────────────────────────────────
Use AskUserQuestion to get response.
If approved: /paul:apply .paul/phases/XX-name/{plan}-FIX.md
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 217 lines · 15 tokens per session scan A 7c05d190bf09
paul:plan-fix is a command published in the GitHub repository ChristopherKahler/paul (1,212 stars, last pushed 12d ago), licensed MIT. It adds 15 tokens to every session and 1,252 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
safe-refactor
Safe refactoring with automated review, testing, and rollback capabilities.
security-review
Comprehensive security analysis with multi-layer vulnerability detection.
test
Smart test runner with filtering, coverage, and health monitoring.
implement-spec
Implement specification with full traceability and test-driven development.
refactor
Interactive refactoring assistant based on Martin Fowler's refactoring catalog.
deploy_to_docker
Build Docker image and start/redeploy the MCP Task Orchestrator container, reusing the last-used config by default.