Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/permit0-ai/permit0/revising-plan-docsnpx skills add permit0-ai/permit0 --skill revising-plan-docsgit clone --depth 1 https://github.com/permit0-ai/permit0Wrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/permit0-ai/permit0/revising-plan-docs)<a href="https://agentmods.dev/skills/permit0-ai/permit0/revising-plan-docs"><img src="https://agentmods.dev/badge/skills/permit0-ai/permit0/revising-plan-docs.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00072 | $0.01098 |
| Opus 5 | $0.00036 | $0.00549 |
| Sonnet 5 | $0.00014 | $0.00220 |
| Haiku 4.5 | $0.00007 | $0.00110 |
Grade A, and why
revising-plan-docs scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 122 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Revising Plan Docs for permit0
When to Use
Use this skill after plan reviews have been written to
docs/plan-reviews/<feature>/. The input is the review docs. The output is
direct edits to the plan docs at docs/plans/<feature>/ -- or an explicit
explanation of why a finding was rejected.
There is no separate output document. The plan docs themselves are the deliverable.
Workflow
Phase 1: Read the Reviews
Read every file in docs/plan-reviews/<feature>/ in order, starting with
00-summary.md. For each finding, note:
- The severity (Critical / Major / Minor / Nit).
- The specific claim the reviewer disputes.
- The evidence the reviewer cites (file paths, line numbers).
- The reviewer's recommendation.
If multiple reviewers submitted reviews (different Reviewer: lines), read
all of them. Note where reviewers agree and where they conflict.
Phase 2: Critically Assess Each Finding
For every finding, do your own independent analysis. Do NOT blindly accept or reject -- verify against the codebase yourself.
For each finding, reach one of three verdicts:
AGREE -- The reviewer is correct. The plan has a real problem.
- State what you verified in the code that confirms the finding.
- Edit the plan doc to fix it.
DISAGREE -- The reviewer is wrong or the finding is not actionable.
- State what you verified in the code that contradicts the finding.
- Explain to the user why the plan is correct as-is. Do not edit the plan.
PARTIALLY AGREE -- The reviewer identified a real issue but the recommendation is wrong or disproportionate.
- State which part is valid and which is not.
- Edit the plan doc with your alternative fix.
Rules for critical assessment:
- Never agree just because the reviewer said so. Read the actual code. Reviewers make mistakes -- they may misread a function signature, miss a serde attribute, or confuse two similar types.
- Never disagree just to preserve the plan. If the reviewer found a real bug (e.g. a wire-format mismatch between two components), the plan must be fixed regardless of how much work it creates.
- Severity matters. Critical and Major findings must be addressed with code-level verification. Minor and Nit findings can be accepted on face value if they are obviously correct (typos, naming, etc.).
- Conflicting reviewers require a tiebreak. If reviewer A says the plan is wrong and reviewer B says it is correct, you must verify independently and pick a side with evidence.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 122 lines · 72 tokens per session scan A f52fa86f0a8f
revising-plan-docs is a skill published in the GitHub repository permit0-ai/permit0 (185 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 72 tokens to every session and 1,098 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
interpret-results
Interprets AIR Blackbox scan results and maps findings to specific EU AI Act articles, recitals, and remediation steps. Use when the user has scan output and wants to understand what to fix, why it matters, or how to prioritize.
compliance-scan
Scans a Python AI project for EU AI Act compliance gaps using AIR Blackbox. Use when the user asks to check compliance, scan their code, audit their AI project, or mentions EU AI Act, Articles 9-15, or compliance checking.
governance
Validates actions, generates receipts, enables rollback.
governance
Validates actions, generates receipts, enables rollback.
Agent Audit Trail
Append-only, hash-chained audit log for AI agents. Records agent actions, tool calls, decisions, and external writes with provenance, timestamps, and sha256 chain integrity. Designed for compliance with EU AI Act Article 12 automatic event recording requirements for high-risk AI systems.
agt-policy-authoring
Create and validate a minimal AGT Copilot CLI policy tailored to the repository being inspected.