Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/paullukic/coograph/coograph-debuggit clone --depth 1 https://github.com/paullukic/coographWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/paullukic/coograph/coograph-debug)<a href="https://agentmods.dev/commands/paullukic/coograph/coograph-debug"><img src="https://agentmods.dev/badge/commands/paullukic/coograph/coograph-debug.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00985 |
| Opus 5 | $0.00000 | $0.00492 |
| Sonnet 5 | $0.00000 | $0.00197 |
| Haiku 4.5 | $0.00000 | $0.00098 |
Grade A, and why
coograph-debug scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 84 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Diagnose the bug or build error below. Find the root cause with minimal investigation, then apply the smallest possible fix.
Phase 0 — Orient with Code-Graph (MANDATORY — non-negotiable)
Before reading any file or running any search, this is the HARD RULE — code-graph first, no exceptions:
- Call
get_minimal_context(task="debug <symptom>")thendetect_changes(). ALWAYS start here. Usedetect_changes()risk scores first — recent high-risk changes are the most likely culprit. Use the returned file list to focus investigation. - Fall back to
sqlite3 .code-graph/graph.dbONLY when the MCP code-graph server is not registered (tools literally do not exist) OR every attempted MCP call returned an error. - Fall back to standard search/read tools ONLY when Step 1 AND Step 2 are both impossible because the code-graph DB is absent from the workspace.
"Slow", "unwieldy", "it's a simple bug" are NOT valid reasons to bypass. When tracing call chains use query_graph("callers_of", fn) and query_graph("callees_of", fn) before reading files. Validate every hypothesis directly in source regardless of graph output.
Protocol
For Runtime Bugs
- REPRODUCE: Can you trigger it reliably? What is the minimal reproduction? Consistent or intermittent?
- GATHER EVIDENCE (parallel when possible):
- Read full error messages and stack traces — every word, not just the first line.
- Check recent changes:
git log --oneline -10,git blameon suspect lines. - Find working examples of similar code in the codebase.
- Read the actual code at error locations.
- HYPOTHESIZE: Compare broken vs working code. Trace data flow from input to error. Document one hypothesis before investigating further. Identify what test would prove/disprove it.
- FIX: Apply ONE change. Predict the test that proves the fix. Check for the same pattern elsewhere.
- VERIFY: Run the failing test/build to confirm the fix works. Verify no regressions.
For Build/Compilation Errors
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 84 lines · 0 tokens per session scan A 1220147a90c9
coograph-debug is a command published in the GitHub repository paullukic/coograph (17 stars, last pushed 28d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 985 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
component-gen
Generate React or Vue components with prop types, styling, accessibility, and tests.
prune
Trim transcript clutter to extend session lifetime — analyze, prune a copy, or toggle the after-each-turn service. Dry-run by default; gains land at resume/compaction, not the current turn.
code-review
Review staged git changes for bugs, security issues, and style violations.
pr-description
Generate a PR title and description from the current branch diff against main.
add-dep
Vet a new or changed third-party dependency for license, provenance, and supply-chain risk before any install runs.
conflict
Stop everything and surface a rule conflict — persona vs. docs vs. code. Present both sides and the conflict-hierarchy level; the user resolves. No silent reconciliation.