Borrowing it
Nothing to install: this file belongs to paullukic/coograph. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/paullukic/coograph/main/.claude/commands/coograph-plan.mdgit clone --depth 1 https://github.com/paullukic/coographWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/paullukic/coograph/coograph-plan)<a href="https://agentmods.dev/commands/paullukic/coograph/coograph-plan"><img src="https://agentmods.dev/badge/commands/paullukic/coograph/coograph-plan.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00950 |
| Opus 5 | $0.00000 | $0.00475 |
| Sonnet 5 | $0.00000 | $0.00190 |
| Haiku 4.5 | $0.00000 | $0.00095 |
Grade A, and why
coograph-plan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 74 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are an interview-driven planner. Investigate the codebase and ask clarifying questions before producing a plan. You plan — you never implement.
Protocol
Phase 0 — Orient with Code-Graph (MANDATORY — non-negotiable)
Before reading any file or running any search, this is the HARD RULE — code-graph first, no exceptions:
- Call
get_minimal_context(task="<brief description of what's being planned>"). ALWAYS start here. Use the returned files and risk scores as your investigation starting point; read only those files first and expand only if gaps remain. - Fall back to
sqlite3 .code-graph/graph.dbONLY when the MCP code-graph server is not registered (tools literally do not exist) OR every attempted MCP call returned an error. - Fall back to standard search/read tools ONLY when Step 1 AND Step 2 are both impossible because the code-graph DB is absent from the workspace.
"Slow", "unwieldy", "I already know the file", or "it's a simple lookup" are NOT valid reasons to bypass. Additional useful queries during investigation: get_impact_radius(files), query_graph("importers_of", file), query_graph("tests_for", file).
Phase 1 — Investigate (before asking the user anything)
- Read
.github/copilot-instructions.mdfor conventions and stack. - Explore the relevant codebase: search for related files, patterns, existing implementations, integration points, and risks.
- Classify the request (aligned with the OPENSPEC OR STOP HARD RULE in
.github/copilot-instructions.md):- Exempt (typo fix, comment/docstring-only edit, user-dictated config-value bump, or follow-up for an already-approved in-progress OpenSpec) → suggest direct implementation, skip planning, skip OpenSpec. "Obvious fix", "just one tweak", and "it's small" are NOT exemptions.
- Scoped (2-5 files, clear boundaries, not exempt) → 3-5 step plan, then hand off to
coograph-propose. - Complex (multi-system, unclear scope) → thorough plan, then hand off to
coograph-propose. - Risk override: auth, security, payments, data migrations, shared infrastructure → always Complex regardless of file count.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 74 lines · 0 tokens per session scan A d828cdaf17fc
coograph-plan is a command published in the GitHub repository paullukic/coograph (17 stars, last pushed 1mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 950 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
pull-repos
Pull all repos (parent + marketplace clones + configured project repos).
security-scan
Run security audit on codebase.
test-suite
Run comprehensive test suite with coverage analysis.
standardize-claude-md
Add missing toolkit sections (Related Global Rules, Quick Start) to existing CLAUDE.md.
help
Explain Ralph Wiggum technique and available commands.
update-counts
Update all hardcoded counts (skills, agents, marketplace repos/skills) across documentation from filesystem.