Borrowing it
Nothing to install: this file belongs to paullukic/coograph. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/paullukic/coograph/main/.claude/commands/coograph-search.mdgit clone --depth 1 https://github.com/paullukic/coographWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/paullukic/coograph/coograph-search)<a href="https://agentmods.dev/commands/paullukic/coograph/coograph-search"><img src="https://agentmods.dev/badge/commands/paullukic/coograph/coograph-search/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/paullukic/coograph/coograph-search"><img src="https://agentmods.dev/badge/commands/paullukic/coograph/coograph-search.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00673 |
| Opus 5 | $0.00000 | $0.00336 |
| Sonnet 5 | $0.00000 | $0.00135 |
| Haiku 4.5 | $0.00000 | $0.00067 |
Grade A, and why
coograph-search scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 51 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Fast read-only codebase search and Q&A. Answer the question below with evidence. You explore — you do not edit files or implement changes.
Thoroughness Levels
The caller specifies one — default to medium if unspecified:
- Quick: 1-2 targeted searches. For "where is X?" or "what type does Y return?"
- Medium: Search broadly, read relevant files, cross-reference. For "how does feature X work?" or "find all usages of Y."
- Thorough: Exhaustive — walk every file in scope, trace call chains, map dependencies. For "audit all places that do X" or "map the data flow from A to Z."
Phase 0 — Orient with Code-Graph (MANDATORY — non-negotiable)
Before reading any file or running any search, this is the HARD RULE — code-graph first, no exceptions:
- Call
get_minimal_context(task="<question being explored>"). ALWAYS start here. Use the returned file list as your starting point; read only those files. - Fall back to
sqlite3 .code-graph/graph.dbONLY when the MCP code-graph server is not registered (tools literally do not exist) OR every attempted MCP call returned an error. - Fall back to Grep/Glob/Read ONLY when Step 1 AND Step 2 are both impossible because the code-graph DB is absent from the workspace.
"Slow", "unwieldy", "I already know the file", or "it's a simple lookup" are NOT valid reasons to bypass. Additional queries: query_graph("callers_of", fn), query_graph("importers_of", file).
Protocol
- Understand what the caller needs and what format to return.
- Search efficiently (after Phase 0):
- Grep for exact text/regex matches.
- Glob for files by name/path pattern.
- Read files for code (use large ranges — avoid many small reads).
- Report with evidence: every claim cites
file:linewith a verbatim code quote. - Stay in scope: answer what was asked. Do not suggest improvements unless explicitly asked.
Output Structure
- Summary (1-3 sentences directly answering the question)
- Evidence (file:line references with verbatim code quotes)
- Details (additional context, related findings, counts — only if needed)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 51 lines · 0 tokens per session scan A a113a7ab52ab
coograph-search is a command published in the GitHub repository paullukic/coograph (17 stars, last pushed 1mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 673 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
bootstrap
Verifies and repairs the Claude Code Toolkit installation.
performance-audit
Find performance bottlenecks across the stack — queries, rendering, bundle size, memory.
debug
Systematic debugging — reproduce, isolate, fix, verify, and add regression test.
health-check
Run diagnostics on Claude Code toolkit configuration and status.
validate
Validate a finding — runs 7-Question Gate + 4-gate checklist. Kills weak findings before report writing. Prevents N/A submissions that hurt validity ratio. Usage: /validate.
cg-indie-observability
Set up production observability for indie-scale apps — structured logging, uptime monitoring, error tracking, and basic metrics. Use when the user mentions logging, monitoring, alerts, error tracking, uptime checks, "how do I know if my app is down", Sentry, journalctl, structured logs, or wants to know what's…