Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/gaoscode/planweave/plan-auditornpx skills add GaosCode/PlanWeave --skill plan-auditorgit clone --depth 1 https://github.com/GaosCode/PlanWeaveWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00059 | $0.02022 |
| Opus 5 | $0.00030 | $0.01011 |
| Sonnet 5 | $0.00012 | $0.00404 |
| Haiku 4.5 | $0.00006 | $0.00202 |
Grade A, and why
plan-auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 129 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Plan Auditor
Use this skill to audit an existing PlanWeave plan. The default output is findings and revision order; do not import a new plan, execute blocks, repair state, or rewrite the package while auditing.
Quick Start
- Find the authority sources: user request, PRD, schema, design docs, current code, and the PlanWeave package.
- Read
project-graph.jsonwhen present, every canvasmanifest.json, source prompts, task/block definitions, canvas structure, dependencies, validation output, andplanweave schemaoutput when available. - Before judging task completeness, identify the plan's main value flows or lifecycle flows and fill the required Flow Coverage table.
- Compare the plan against real goals, data-flow coverage, object lifecycles, contracts, execution order, prompts, failure paths, and verification criteria.
- Report a verdict first:
PASS,NEEDS_REVISION, orBLOCKED. - List findings by severity, with evidence and concrete plan changes.
Plan Update Boundary
- Audit findings name the needed task, block, edge, prompt, review, or validation update; they do not apply the change.
- If the user explicitly asks to apply revisions, finish the audit first, then use the Plan Package semantic editing boundary: resolve CLI workspace paths, edit only
project-graph.json, canvasmanifest.json, and source prompt Markdown needed for the revision, and run canvas-scoped plus project validation. - Do not edit runtime
state.json,results/, active canvas selection, recovery transactions, or implementation artifacts from this skill.
Required Output
- Verdict:
PASS,NEEDS_REVISION, orBLOCKED. - Flow Coverage table before findings.
- Findings by severity.
- Recommended revision order.
Flow Coverage table:
| Flow | Trigger/Input | Core Processing | External Dependency | State/Storage | Interface/Consumer | Output/Side Effect | Failure Path | Verification | Gaps |
|---|
For every cell, cite exact PlanWeave task/block ids, prompts, reference files, and validation methods when they exist. Use Gap: for missing task coverage, prompt coverage, dependency edge, verification, real behavior, or required failure handling.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 129 lines · 59 tokens per session scan A 9f0cc561a9c1
plan-auditor is a skill published in the GitHub repository GaosCode/PlanWeave (364 stars, last pushed 4d ago), licensed MIT. It adds 59 tokens to every session and 2,022 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…