Agent skill

Icpg

by alinaqi in alinaqi/maggy

Intent-Augmented Code Property Graph — tracks WHY code exists via ReasonNodes with formal contracts, 6-dimension drift detection, and 3 canonical pre-task queries for autonomous development

MITAuto-check passedDevOps & Cloud

Install Icpg

skills CLI
$ npx skills add alinaqi/maggy --skill icpg -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alinaqi/maggy icpg --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alinaqi/maggy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/icpg .claude/skills/icpg && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
icpg
GitHub stars
707
Token cost
~2.9k tokens
SKILL.md length
615 words
Files
1
Skills in repo
71
Repo updated
First seen
Licence
MIT

At a glance

Intent-Augmented Code Property Graph — tracks WHY code exists via ReasonNodes with formal contracts, 6-dimension drift detection, and 3 canonical pre-task queries for autonomous development

  • Works in 6 steps: Get commits from last 90 days → Cluster by temporal proximity (2-hour… → Infer intent via LLM (Claude or OpenAI)… → …
  • Tasks that involve GitOps
  • SKILL.md covers Core Principle, The 3 Canonical Pre-Task Queries, ReasonNode — The Core Primitive and Six Edge Types, plus 9 more sections
  • Calls pip

What it does

Icpg is an agent skill from alinaqi/maggy. Intent-Augmented Code Property Graph — tracks WHY code exists via ReasonNodes with formal contracts, 6-dimension drift detection, and 3 canonical pre-task queries for autonomous development

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering GitOps. The repository describes itself as: What started as an opinionated Claude Code setup kit is now an autonomous AI engineering command center. The licence is MIT.

When your agent uses it

  • Tasks that involve GitOps

Example prompts

  • “/icpg”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Get commits from last 90 days
  2. Cluster by temporal proximity (2-hour window)
  3. Infer intent via LLM (Claude or OpenAI) or commit message parsing
  4. Create ReasonNodes with source: "inferred", confidence: 0.6-0.8
  5. Extract symbols from changed files, create CREATES edges
  6. Run duplicate detection against existing ReasonNodes

What it can do on your machine

Read from SKILL.md and the folder at commit 72a456e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Icpg loads about 2.9k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 615 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alinaqi/maggy at commit 72a456e, republished under its MIT licence (© alinaqi). 615 words, ~2,871 tokens.

Download SKILL.mdSave it as .claude/skills/icpg/SKILL.md (or your agent's skills folder).
name
icpg
description
Intent-Augmented Code Property Graph — tracks WHY code exists via ReasonNodes with formal contracts, 6-dimension drift detection, and 3 canonical pre-task queries for autonomous development
when-to-use
Before any code change — query the reason graph for intent, constraints, and risk
user-invocable
false
effort
high

iCPG Skill (Intent-Augmented Code Property Graph)

Purpose: Add a Reason Graph layer on top of code structure so every function, class, and module is traceable to the goal that created it, the agent or human that owns it, and whether it's still doing what it was supposed to do.

┌────────────────────────────────────────────────────────────────┐
│  iCPG = AST + CFG + PDG + RG (Reason Graph)                    │
│  ─────────────────────────────────────────────────────────────│
│  AST  = Abstract Syntax Tree (structure)      ← existing       │
│  CFG  = Control Flow Graph (execution paths)  ← existing       │
│  PDG  = Program Dependency Graph              ← existing       │
│  RG   = Reason Graph (WHY layer)              ← THIS SKILL     │
│                                                                │
│  The RG stores ReasonNodes (goals/tasks), links them to code   │
│  symbols via typed edges, enforces contracts (DbC), and        │
│  detects when code drifts from its original purpose.           │
│                                                                │
│  Storage: .icpg/reason.db (SQLite, per-project, gitignored)   │
│  CLI: icpg init | create | record | query | drift | bootstrap │
└────────────────────────────────────────────────────────────────┘

Core Principle

Intent first, code second. Before writing or modifying code, query the reason graph to understand WHY existing code was written, WHAT constraints it must preserve, and WHETHER your change duplicates prior work.


The 3 Canonical Pre-Task Queries

Every agent MUST run these before writing code:

#QueryCommandWhat It Answers
1search_prior_workicpg query prior "<goal>"Has this been attempted before? Prevents duplication.
2get_constraintsicpg query constraints <file>What invariants apply to files I'll touch? Prevents breakage.
3get_risk_profileicpg query risk <symbol>Is this symbol fragile? Drift history, ownership changes.

ReasonNode — The Core Primitive

Each ReasonNode captures a stated purpose with a formal contract:

id              UUID
goal            Natural language: what is this trying to achieve
decision_type   business_goal | arch_decision | task | workaround | constraint | patch
scope           Files/modules expected to be touched
owner           Human or agent accountable
status          proposed | executing | fulfilled | drifted | abandoned
source          manual | commit | inferred | agent-session

FORMAL CONTRACT (Design by Contract):
  preconditions    What must be true before this intent executes
  postconditions   What must be true when fulfilled
  invariants       What must remain true throughout and after

Drift = predicate failure. A symbol has drifted when its current behavior no longer satisfies the postconditions of the ReasonNode that created it, or when an invariant is violated.


Six Edge Types

CREATES      Reason  → Symbol   (this intent created this function)
MODIFIES     Reason  → Symbol   (this intent changed this function)
REQUIRES     Reason  → Reason   (B depends on A being done first)
DUPLICATES   Reason  → Reason   (these two goals overlap)
VALIDATED_BY Reason  → Test     (this test proves the intent was satisfied)
DRIFTS_FROM  Symbol  → Reason   (this symbol no longer does what it was made for)

6-Dimension Drift Model

DimensionWhat It MeansDetection
Spec driftSymbol checksum changed without a MODIFIES edgeCompare stored vs current checksum
Decision driftPostconditions no longer holdEvaluate predicates against codebase
Ownership drift>3 different owners without coherent oversightCount unique owners on edges
Test driftVALIDATED_BY tests missing or failingCheck test file existence + run
Usage driftSymbol used outside original scopeGrep for imports beyond scope
Dependency driftDownstream REQUIRES reasons have driftedTraverse REQUIRES edges

Run icpg drift check to scan all dimensions. Each produces a 0-1 severity score.


CLI Reference

Setup
bash
icpg init                          # Create .icpg/ and database
icpg bootstrap --days 90           # Infer ReasonNodes from git history
icpg bootstrap --days 90 --no-llm  # Without LLM (commit-message only)
Create & Record
bash
icpg create "Add JWT auth" --scope src/auth/ --owner feature-auth --type task
icpg record --reason <id> --base main         # Record symbols from git diff
icpg record --reason <id> --edge-type MODIFIES # Record as modifications
Query (the 3 canonical queries)
bash
icpg query prior "user authentication"     # 1. Duplicate detection
icpg query constraints src/auth/service.ts  # 2. Invariants for file
icpg query risk validateToken              # 3. Symbol risk profile
icpg query context src/auth/service.ts     # All intents for a file
icpg query blast <reason-id>               # Full blast radius
Drift
bash
icpg drift check          # Full scan across all dimensions
icpg drift resolve <id>   # Mark drift event resolved
Status
bash
icpg status               # Stats: reasons, symbols, edges, drift

Storage

Per-project, gitignored, zero infrastructure:

.icpg/
  reason.db       SQLite database (4 tables: reasons, symbols, edges, drift_events)
  .gitignore      Contains: *
  chroma/         ChromaDB vectors (if chromadb installed)
  tfidf_cache.json  TF-IDF fallback cache
  .current-intent   Marker file for active intent (used by Stop hook)

Install options:

bash
pip install ./scripts/icpg            # Core (zero deps)
pip install "./scripts/icpg[vectors]"  # + ChromaDB for duplicate detection
pip install "./scripts/icpg[all]"      # + ChromaDB + scikit-learn + openai

Workflow: Before Any Code Change

0. INTENT       → icpg create (or identify existing intent)
1. DEDUP        → icpg query prior (check for duplicate work)
2. CONSTRAINTS  → icpg query constraints (understand invariants)
3. RISK         → icpg query risk (check fragile symbols)
4. LOCATE       → search_graph to find symbols (code-graph skill)
5. CHANGE       → Make the edit (PreToolUse hook shows context)
6. RECORD       → icpg record (link symbols to intent)
7. DRIFT CHECK  → icpg drift check (verify no unintended drift)
8. VERIFY       → Run tests, lint, typecheck

Step 0 is non-negotiable for autonomous agents. Every change must be linked to a stated purpose. Without an intent, there's nothing to measure drift against.


Hook Integration

PreToolUse Hook (automatic context injection)

Add to .claude/settings.json:

json
{
  "hooks": {
    "PreToolUse": [{
      "matcher": "Edit|Write",
      "hooks": [{
        "type": "command",
        "command": "scripts/icpg-pre-edit.sh",
        "timeout": 3,
        "statusMessage": "Checking intent context..."
      }]
    }]
  }
}

Before every file edit, agents see:

═══ iCPG CONTEXT ═══
INTENTS for src/auth/service.ts:
  [>] a1b2c3d4 — User authentication with JWT tokens
      Owner: feature-auth | Status: executing
      Invariants: 2
CONSTRAINTS for src/auth/service.ts:
  From intent: User authentication with JWT tokens
    INV: file_exists("src/auth/middleware.ts")
    POST: test_exists("src/auth/__tests__/service.test.ts")
PRESERVE function signatures unless your task requires changing them.
═══════════════════
Stop Hook (automatic symbol recording)

After implementation passes tests, auto-records symbols:

json
{
  "hooks": {
    "Stop": [{
      "hooks": [
        {"type": "command", "command": "scripts/tdd-loop-check.sh", "timeout": 60},
        {"type": "command", "command": "scripts/icpg-stop-record.sh", "timeout": 5}
      ]
    }]
  }
}

Agent Teams Integration

Updated Pipeline (agent-teams + iCPG)
 0. INTENT       Team lead creates ReasonNode from feature spec
 0b. DEDUP       icpg query prior — check for duplicate intents
 1. SPEC         Feature agent writes spec
 2. SPEC-REVIEW  Quality agent reviews spec + intent alignment
 3. TESTS (RED)  Feature agent writes tests
 4. RED-VERIFY   Quality agent verifies tests fail
 5. IMPLEMENT    Feature agent codes (PreEdit hook shows context)
 5b. RECORD      Auto-record symbols → intent (Stop hook)
 5c. DRIFT-CHECK Quality agent verifies no scope drift
 6. GREEN-VERIFY Quality agent verifies tests pass + coverage
 7. VALIDATE     Lint + typecheck + full suite
 8. CODE-REVIEW  Review agent (sees intent context per file)
 9. SECURITY     Security agent
10. BRANCH-PR    Merger agent (PR includes intent traceability)
Show full SKILL.md (251 more words)Show less
Agent Responsibilities
AgentiCPG Action
Team Leadicpg create when creating task chains. icpg query prior to check duplicates.
Feature Agenticpg query constraints before implementing. Writes .icpg/.current-intent for auto-recording.
Quality Agenticpg drift check during GREEN verify. Verifies scope alignment.
Review AgentSees intent context via PreToolUse hook when reviewing files.
Merger AgentIncludes intent traceability in PR description.

Bootstrapping from Git History

For existing codebases, infer ReasonNodes from commit history:

bash
icpg bootstrap --days 90 --verbose

This will:

  1. Get commits from last 90 days
  2. Cluster by temporal proximity (2-hour window)
  3. Infer intent via LLM (Claude or OpenAI) or commit message parsing
  4. Create ReasonNodes with source: "inferred", confidence: 0.6-0.8
  5. Extract symbols from changed files, create CREATES edges
  6. Run duplicate detection against existing ReasonNodes

Quality note: Inferred intents are marked low-confidence. Review and promote high-value ones manually.


Contract Predicates

Predicates are structured assertions over codebase state:

file_exists("src/auth/middleware.ts")
test_exists("src/auth/__tests__/service.test.ts")
symbol_count("src/auth/") <= 15
function_signature("validateToken") == "(token: string) => Promise<User>"

Contracts can be:

  • Hand-authored for high-risk ReasonNodes
  • LLM-inferred via icpg create --infer-contracts
  • Heuristic (scope → file_exists, test → test_exists)

Anti-Patterns

Anti-PatternDo This Instead
Coding without stating intenticpg create before every non-trivial change
Assuming your change is isolatedicpg query constraints + icpg query risk first
Rebuilding what already existsicpg query prior to check for prior work
Leaving intent in 'executing' foreverUpdate status to 'fulfilled' when done
Ignoring drift eventsicpg drift check weekly, resolve or create new intents
Storing full source in symbolsStore signature + checksum only — read source from files
Skipping bootstrap on existing reposicpg bootstrap --days 90 to build initial graph

© alinaqi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/icpg of alinaqi/maggy.

Open the folder on GitHubat commit 72a456e

Compare with similar skills

Icpg next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Icpg compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Icpg this skillalinaqi/maggy707—~2.9kAutomated safety check: PassMIT
Kubernetes SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT
Kubernetes ArchitectCybereason-Public/owLSM2809 repos~2.6kAutomated safety check: PassGPL-2.0
Docs Corpus Auditmicrosoft/apm4k—~2.6kAutomated safety check: PassMIT
Devopsnicepkg/auto-company1942 repos~814Automated safety check: PassMIT
Gitops Repo Auditfluxcd/agent-skills231—~3.8kAutomated safety check: PassApache-2.0

Similar skills

  • Kubernetes Specialist

    Jeffallan/claude-skills

    Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    DevOps & CloudAuto-check passed
  • Kubernetes Architect

    Cybereason-Public/owLSM

    Expert Kubernetes architect specializing in cloud-native infrastructure, advanced GitOps workflows (ArgoCD/Flux), and enterprise container orchestration.

    280 GitHub starsUsed in 9 repos~2.6k tokens
    DevOps & CloudAuto-check passed
  • Docs Corpus Audit

    microsoft/apm

    Official

    A skill your agent uses to run a holistic regrounding pass on the entire microsoft/apm documentation corpus against current source code, page-by-page, and emit surgical fixes for stale claims.

    4k GitHub stars~2.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Devops

    nicepkg/auto-company

    Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).

    194 GitHub starsUsed in 2 repos~814 tokens
    DevOps & CloudAuto-check passed
  • Gitops Repo Audit

    fluxcd/agent-skills

    Audit and validate Flux CD GitOps repositories by scanning local repo files (not live clusters) — runs Kubernetes schema validation, detects deprecated Flux APIs, reviews RBAC/multi-tenancy/secrets…

    231 GitHub stars~3.8k tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed
  • Sets up GitOps continuous delivery for Kubernetes with ArgoCD or Flux, covering installation, repository layout, sync policies, progressive delivery and secrets.

    40k GitHub starsUsed in 12 repos~1.5k tokens
    DevOps & CloudAuto-check passed

More from alinaqi/maggy

All 71 skills in this repo
  • Aeo Optimization

    alinaqi/maggy

    AI Engine Optimization - semantic triples, page templates, content clusters for AI citations

    707 GitHub stars~3.7k tokensUpdated 15 days ago
    Auto-check passed
  • Agent Teams

    alinaqi/maggy

    Claude Code Agent Teams - default team-based development with strict TDD pipeline enforcement

    707 GitHub stars~5k tokensUpdated 15 days ago
    Auto-check: notes
  • AI Models

    alinaqi/maggy

    Latest AI models reference - Claude, OpenAI, Gemini, Eleven Labs, Replicate

    707 GitHub stars~4.1k tokensUpdated 15 days ago
    Auto-check passed
  • Android Java

    alinaqi/maggy

    Android Java development with MVVM, ViewBinding, and Espresso testing

    707 GitHub stars~3.9k tokensUpdated 15 days ago
    Auto-check: notes
  • Android Kotlin

    alinaqi/maggy

    Android Kotlin development with Coroutines, Jetpack Compose, Hilt, and MockK testing

    707 GitHub stars~3k tokensUpdated 15 days ago
    Auto-check passed
  • Autonomous Testing

    alinaqi/maggy

    AI-driven testing agent that auto-discovers, generates, executes, evaluates, and fixes tests for any project type

    707 GitHub stars~1.1k tokensUpdated 15 days ago
    Auto-check passed

Categories

Questions about Icpg

What does Icpg do?

Intent-Augmented Code Property Graph — tracks WHY code exists via ReasonNodes with formal contracts, 6-dimension drift detection, and 3 canonical pre-task queries for autonomous development. Icpg is an agent skill from alinaqi/maggy.

When should I use Icpg?

Icpg fits situations like: tasks that involve GitOps.

How do I install Icpg in Claude Code?

Run `npx skills add alinaqi/maggy --skill icpg -a claude-code`. Or copy the skill folder (skills/icpg in alinaqi/maggy) into .claude/skills/icpg in your project. Claude Code loads it when a task matches its description.

How do I install Icpg in Codex?

Run `npx skills add alinaqi/maggy --skill icpg -a codex`. Or copy the skill folder (skills/icpg in alinaqi/maggy) into .agents/skills/icpg in your project. Codex loads it when a task matches its description.

Can I use Icpg in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alinaqi/maggy --skill icpg -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/icpg, .gemini/skills/icpg, .github/skills/icpg and .opencode/skills/icpg in your project.

What does Icpg need to run?

Going by SKILL.md and its folder, Icpg needs the command-line tools its instructions call (pip). Our summary lists: Python 3.

Does Icpg access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Icpg safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Icpg use?

Icpg is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Icpg use?

About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Icpg?

Skills that share tags, products or a category with Icpg: Kubernetes Specialist (Jeffallan/claude-skills, 12k stars), Kubernetes Architect (Cybereason-Public/owLSM, 280 stars), Docs Corpus Audit (microsoft/apm, 4k stars) and Devops (nicepkg/auto-company, 194 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Icpg?

alinaqi (a GitHub user) maintains it in alinaqi/maggy, which has 707 GitHub stars. The repository holds 71 skills in this directory. The repository was last updated on September 24, 2026.

Source: alinaqi/maggy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.