Agent skill

Control Flow Abstraction Generator

by ArabelaTso in ArabelaTso/Skills-4-SE

Generate abstract Control Flow Graph (CFG) representations of programs showing loops, branches, and function calls for static analysis or verification.

Apache-2.0Auto-check passedSecurity

Install Control Flow Abstraction Generator

skills CLI
$ npx skills add ArabelaTso/Skills-4-SE --skill control-flow-abstraction-generator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ArabelaTso/Skills-4-SE control-flow-abstraction-generator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/control-flow-abstraction-generator .claude/skills/control-flow-abstraction-generator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
control-flow-abstraction-generator
GitHub stars
253
Token cost
~2.8k tokens
SKILL.md length
868 words
Files
2 (incl. references)
Skills in repo
150
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generate abstract Control Flow Graph (CFG) representations of programs showing loops, branches, and function calls for static analysis or verification.

  • Works in 5 steps: Parse Program Structure → Create CFG Nodes → Create CFG Edges → …
  • Visualize program control flow structure
  • SKILL.md covers Overview, How to Use, CFG Generation Workflow and Example: Simple Conditional, plus 7 more sections
  • Calls node

What it does

Control Flow Abstraction Generator is an agent skill from ArabelaTso/Skills-4-SE. Generate abstract Control Flow Graph (CFG) representations of programs showing loops, branches, and function calls for static analysis or verification. Use when users need to: (1) Visualize program control flow structure, (2) Generate CFGs for static analysis tools, (3) Create control flow abstractions for formal verification, (4) Analyze program paths and reachability, (5) Document program structure. Supports both function-level (intraprocedural) and program-level (interprocedural) analysis with multiple output…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/cfg_patterns.md`).

It sits in Security, covering Static analysis and SAST. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.

When your agent uses it

  • Visualize program control flow structure
  • Generate CFGs for static analysis tools
  • Create control flow abstractions for formal verification
  • Analyze program paths and reachability

Example prompts

  • “/control-flow-abstraction-generator”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Parse Program Structure
  2. Create CFG Nodes
  3. Create CFG Edges
  4. Handle Special Constructs
  5. Generate Output

What it can do on your machine

Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Control Flow Abstraction Generator loads about 2.8k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 148 tokens; SKILL.md has 868 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~148
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 868 words, ~2,844 tokens.

Download SKILL.mdSave it as .claude/skills/control-flow-abstraction-generator/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
control-flow-abstraction-generator
description
Generate abstract Control Flow Graph (CFG) representations of programs showing loops, branches, and function calls for static analysis or verification. Use when users need to: (1) Visualize program control flow structure, (2) Generate CFGs for static analysis tools, (3) Create control flow abstractions for formal verification, (4) Analyze program paths and reachability, (5) Document program structure. Supports both function-level (intraprocedural) and program-level (interprocedural) analysis with multiple output formats (textual, DOT/Graphviz, JSON).

Control Flow Abstraction Generator

Generate abstract Control Flow Graph representations of programs.

Overview

This skill analyzes program code and generates Control Flow Graphs (CFGs) that abstract the program's control flow structure. CFGs show how execution flows through the program via nodes (statements, conditions) and edges (control transfers), making them suitable for static analysis, formal verification, and program understanding.

How to Use

Provide:

  1. Program code: Function or program to analyze
  2. Analysis scope: Function-level or program-level
  3. Output format (optional): Textual, DOT, JSON, or multiple

The skill will generate:

  • CFG with nodes and edges
  • Node types (entry, exit, statement, condition, merge)
  • Edge types (sequential, true/false branches, back edges, calls)
  • Optional: DOT format for visualization, JSON for tool integration

CFG Generation Workflow

Step 1: Parse Program Structure

Identify program constructs:

  • Sequential statements: Assignments, expressions, declarations
  • Conditional statements: if-then-else, switch-case
  • Loop statements: while, for, do-while
  • Function calls: Direct calls, recursive calls
  • Control transfers: break, continue, return, goto
  • Exception handling: try-catch-finally
Step 2: Create CFG Nodes

Generate nodes for each construct:

Entry Node: Function/program start

  • Label: ENTRY or function name
  • Type: entry
  • Successors: First statement

Exit Node: Function/program end

  • Label: EXIT or return
  • Type: exit
  • Predecessors: All return points

Statement Node: Regular statement

  • Label: Statement text or line number
  • Type: statement
  • Represents: Assignment, call, expression

Condition Node: Branch decision

  • Label: Boolean expression
  • Type: condition
  • Successors: True branch, false branch

Merge Node: Branch join point

  • Label: MERGE or empty
  • Type: merge
  • Predecessors: Multiple branches
Step 3: Create CFG Edges

Connect nodes with appropriate edges:

Sequential Edge: Normal flow

  • From: Statement/node
  • To: Next statement/node
  • Label: None or →

True Edge: Condition true branch

  • From: Condition node
  • To: True branch first statement
  • Label: T or true

False Edge: Condition false branch

  • From: Condition node
  • To: False branch first statement
  • Label: F or false

Back Edge: Loop iteration

  • From: Loop body end
  • To: Loop header
  • Label: ↶ or back

Call Edge: Function invocation (interprocedural)

  • From: Call site
  • To: Called function entry
  • Label: ⇒ or call

Return Edge: Function return (interprocedural)

  • From: Called function exit
  • To: Call site return point
  • Label: ⇐ or return
Step 4: Handle Special Constructs

Loops: Create back edges from body to header

Break: Create edge from break statement to loop exit

Continue: Create back edge from continue to loop header

Return: Create edge from return to EXIT node

Exceptions: Create exception edges from try block to catch handlers

Step 5: Generate Output

Produce CFG in requested format(s):

  • Textual representation
  • DOT format for Graphviz
  • JSON for tool integration

Example: Simple Conditional

Code:

python
def max_value(x, y):
    if x > y:
        result = x
    else:
        result = y
    return result

CFG (Textual):

Node 1 (ENTRY):
  Label: max_value
  Successors: [2]

Node 2 (x > y):
  Type: condition
  Predecessors: [1]
  Successors: [3 (true), 4 (false)]

Node 3 (result = x):
  Type: statement
  Predecessors: [2]
  Successors: [5]

Node 4 (result = y):
  Type: statement
  Predecessors: [2]
  Successors: [5]

Node 5 (MERGE):
  Type: merge
  Predecessors: [3, 4]
  Successors: [6]

Node 6 (return result):
  Type: statement
  Predecessors: [5]
  Successors: [7]

Node 7 (EXIT):
  Predecessors: [6]

CFG (Visual):

    ENTRY
      ↓
   [x > y]
    ↓   ↓
   T↓   ↓F
    ↓   ↓
[result=x] [result=y]
    ↓       ↓
    └→MERGE←┘
        ↓
  [return result]
        ↓
      EXIT

CFG (DOT):

dot
digraph CFG {
  node [shape=box];

  n1 [label="ENTRY", shape=ellipse];
  n2 [label="x > y", shape=diamond];
  n3 [label="result = x"];
  n4 [label="result = y"];
  n5 [label="MERGE", shape=circle];
  n6 [label="return result"];
  n7 [label="EXIT", shape=ellipse];

  n1 -> n2;
  n2 -> n3 [label="T", color=green];
  n2 -> n4 [label="F", color=red];
  n3 -> n5;
  n4 -> n5;
  n5 -> n6;
  n6 -> n7;
}

Example: While Loop

Code:

python
def sum_to_n(n):
    sum = 0
    i = 0
    while i < n:
        sum += i
        i += 1
    return sum

CFG (Visual):

    ENTRY
      ↓
   [sum = 0]
      ↓
   [i = 0]
      ↓
      ┌─────────┐
      ↓         ↑
   [i < n]      ↑ (back edge)
    ↓   ↓       ↑
   T↓   ↓F      ↑
    ↓   ↓       ↑
[sum += i]      ↑
      ↓         ↑
  [i += 1]──────┘
      ↓F
[return sum]
      ↓
    EXIT

Key Features:

  • Loop header: [i < n]
  • Back edge: From [i += 1] to [i < n]
  • Exit edge: False branch from condition to return

CFG (Textual):

Node 1 (ENTRY)
  → Node 2

Node 2 (sum = 0)
  → Node 3

Node 3 (i = 0)
  → Node 4

Node 4 (i < n) [LOOP HEADER]
  →T Node 5
  →F Node 7

Node 5 (sum += i)
  → Node 6

Node 6 (i += 1)
  → Node 4 [BACK EDGE]

Node 7 (return sum)
  → Node 8

Node 8 (EXIT)

Example: Nested Control Flow

Code:

python
def process(arr, threshold):
    result = []
    for item in arr:
        if item > threshold:
            result.append(item * 2)
        else:
            if item < 0:
                continue
            result.append(item)
    return result

CFG (Visual):

ENTRY
  ↓
[result = []]
  ↓
[i = 0]
  ↓
  ┌──────────────────────┐
  ↓                      ↑
[i < len(arr)]           ↑
  ↓T                     ↑
[item = arr[i]]          ↑
  ↓                      ↑
[item > threshold]       ↑
  ↓T            ↓F       ↑
[result.append  [item<0] ↑
 (item*2)]        ↓T     ↑
  ↓               └──────┘ (continue)
  ↓              ↓F
  ↓         [result.append(item)]
  ↓               ↓
  └──→MERGE←──────┘
       ↓
   [i += 1]───────┘
       ↓F
  [return result]
       ↓
     EXIT

Key Features:

  • Outer loop: for loop over array
  • Inner conditional: if-else with nested if
  • Continue statement: back edge to loop header
  • Multiple merge points

Example: Function Calls (Interprocedural)

Code:

python
def factorial(n):
    if n <= 1:
        return 1
    return n * factorial(n-1)

def compute(x):
    result = factorial(x)
    return result + 1

Intraprocedural CFG (factorial only):

factorial:ENTRY
      ↓
   [n <= 1]
    ↓     ↓
   T↓     ↓F
    ↓     ↓
[return 1] [call factorial(n-1)]
    ↓           ↓
    ↓      [return n * result]
    ↓           ↓
    └──→EXIT←───┘

Interprocedural CFG (with call edges):

compute:ENTRY
      ↓
[call factorial(x)] ⇒ factorial:ENTRY
      ↓                     ↓
      ↓                [n <= 1]
      ↓                  ↓   ↓
      ↓                 ...  ...
      ↓                     ↓
[result = ...] ⇐ factorial:EXIT
      ↓
[return result + 1]
      ↓
compute:EXIT

Key Features:

  • Call edge: From call site to callee entry
  • Return edge: From callee exit to call site
  • Recursive call: Edge back to same function
Show full SKILL.md (348 more words)Show less

Output Formats

Textual Format

Human-readable node and edge listing:

Node <id> (<label>):
  Type: <type>
  Predecessors: [<ids>]
  Successors: [<ids>]
DOT Format (Graphviz)

Graph visualization format:

dot
digraph CFG {
  node [shape=box];
  n1 [label="...", shape=...];
  n1 -> n2 [label="...", color=...];
}

Generate PNG/SVG with: dot -Tpng cfg.dot -o cfg.png

JSON Format

Machine-readable for tool integration:

json
{
  "nodes": [
    {"id": 1, "label": "...", "type": "..."}
  ],
  "edges": [
    {"from": 1, "to": 2, "type": "..."}
  ]
}

Analysis Levels

Function-Level (Intraprocedural)

Scope: Single function Nodes: Statements within function Edges: Control flow within function Calls: Treated as single statement nodes

Use cases:

  • Function-level analysis
  • Loop detection
  • Path analysis within function
Program-Level (Interprocedural)

Scope: Multiple functions Nodes: Statements across all functions Edges: Control flow + call/return edges Calls: Explicit call and return edges

Use cases:

  • Whole-program analysis
  • Call graph construction
  • Interprocedural dataflow

CFG Properties

Dominance

Node A dominates node B if every path from ENTRY to B passes through A.

Uses: Loop header identification, optimization

Post-Dominance

Node A post-dominates node B if every path from B to EXIT passes through A.

Uses: Control dependence, merge point identification

Reachability

Node B is reachable from node A if there exists a path from A to B.

Uses: Dead code detection, path analysis

Strongly Connected Components

Maximal set of nodes where every node is reachable from every other.

Uses: Loop detection, cycle analysis

Common Patterns

Sequential Statements

Pattern: Linear flow See: cfg_patterns.md

If-Then-Else

Pattern: Diamond shape with merge See: cfg_patterns.md

While Loop

Pattern: Back edge from body to header See: cfg_patterns.md

Break/Continue

Pattern: Direct edges to exit/header See: cfg_patterns.md

Try-Catch

Pattern: Exception edges to handlers See: cfg_patterns.md

References

Detailed CFG construction patterns:

  • cfg_patterns.md: Comprehensive patterns for all control flow constructs with examples

Load this reference when:

  • Need detailed patterns for specific constructs
  • Working with complex nested structures
  • Want to see all output format examples
  • Need CFG property definitions

Tips

  1. Start with entry/exit: Always create ENTRY and EXIT nodes first
  2. Handle loops carefully: Identify loop headers and create back edges
  3. Merge branches: Create explicit merge nodes after conditionals
  4. Label edges clearly: Use T/F for branches, mark back edges
  5. Consider scope: Choose function-level or program-level based on use case
  6. Visualize complex CFGs: Use DOT format for large graphs
  7. Validate structure: Check that all nodes are reachable from ENTRY
  8. Document assumptions: Note how you handle language-specific constructs

© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/control-flow-abstraction-generator of ArabelaTso/Skills-4-SE.

  • SKILL.md
  • references/cfg_patterns.md

Open the folder on GitHubat commit 4f38503

Compare with similar skills

Control Flow Abstraction Generator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Control Flow Abstraction Generator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Control Flow Abstraction Generator this skillArabelaTso/Skills-4-SE253—~2.8kAutomated safety check: PassApache-2.0
Semgrepvigolium/piolium1401 repos~2.4kAutomated safety check: NotesMIT
C To AstNarwhal-Lab/MagicSkills316—~1.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
LLM Sast ScannerSunWeb3Sec/llm-sast-scanner286—~6.2kAutomated safety check: PassNone
Sast SemgrepAgentSecOps/SecOpsAgentKit2202 repos~2.4kAutomated safety check: PassCustom licence

Similar skills

  • Semgrep

    vigolium/piolium

    Run Semgrep static analysis scan on a codebase using parallel subagents.

    140 GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes
  • C To Ast

    Narwhal-Lab/MagicSkills

    Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.

    316 GitHub stars~1.1k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • LLM Sast Scanner

    SunWeb3Sec/llm-sast-scanner

    General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis.

    286 GitHub stars~6.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Sast Semgrep

    AgentSecOps/SecOpsAgentKit

    Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

    220 GitHub starsUsed in 2 repos~2.4k tokens
    SecurityAuto-check passed
  • Triage Codeql

    netdata/netdata

    Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.

    81k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes

More from ArabelaTso/Skills-4-SE

All 150 skills in this repo
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Metamorphic Test Generator

    ArabelaTso/Skills-4-SE

    Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.

    253 GitHub stars~798 tokensUpdated 1 mo ago
    Auto-check passed
  • Reproduction Trace Instrumenter

    ArabelaTso/Skills-4-SE

    Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.

    253 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Spring Mvc To Boot Migrator

    ArabelaTso/Skills-4-SE

    Automatically migrate Spring MVC applications to Spring Boot.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • State Snapshot Instrumenter

    ArabelaTso/Skills-4-SE

    Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Control Flow Abstraction Generator

What does Control Flow Abstraction Generator do?

Generate abstract Control Flow Graph (CFG) representations of programs showing loops, branches, and function calls for static analysis or verification. Control Flow Abstraction Generator is an agent skill from ArabelaTso/Skills-4-SE. Generate abstract Control Flow Graph (CFG) representations of programs showing loops, branches, and function calls for static analysis or verification.

When should I use Control Flow Abstraction Generator?

Control Flow Abstraction Generator fits situations like: visualize program control flow structure; generate CFGs for static analysis tools; create control flow abstractions for formal verification; analyze program paths and reachability.

How do I install Control Flow Abstraction Generator in Claude Code?

Run `npx skills add ArabelaTso/Skills-4-SE --skill control-flow-abstraction-generator -a claude-code`. Or copy the skill folder (skills/control-flow-abstraction-generator in ArabelaTso/Skills-4-SE) into .claude/skills/control-flow-abstraction-generator in your project. Claude Code loads it when a task matches its description.

How do I install Control Flow Abstraction Generator in Codex?

Run `npx skills add ArabelaTso/Skills-4-SE --skill control-flow-abstraction-generator -a codex`. Or copy the skill folder (skills/control-flow-abstraction-generator in ArabelaTso/Skills-4-SE) into .agents/skills/control-flow-abstraction-generator in your project. Codex loads it when a task matches its description.

Can I use Control Flow Abstraction Generator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill control-flow-abstraction-generator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/control-flow-abstraction-generator, .gemini/skills/control-flow-abstraction-generator, .github/skills/control-flow-abstraction-generator and .opencode/skills/control-flow-abstraction-generator in your project.

What does Control Flow Abstraction Generator need to run?

Going by SKILL.md and its folder, Control Flow Abstraction Generator needs the command-line tools its instructions call (node). Our summary lists: Python 3.

Does Control Flow Abstraction Generator access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Control Flow Abstraction Generator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Control Flow Abstraction Generator use?

Control Flow Abstraction Generator is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Control Flow Abstraction Generator use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.6k tokens, read only when the agent opens those files.

What are the alternatives to Control Flow Abstraction Generator?

Skills that share tags, products or a category with Control Flow Abstraction Generator: Semgrep (vigolium/piolium, 140 stars), C To Ast (Narwhal-Lab/MagicSkills, 316 stars), Semgrep Security Scan (trailofbits/skills, 7.4k stars) and LLM Sast Scanner (SunWeb3Sec/llm-sast-scanner, 286 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Control Flow Abstraction Generator?

ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on August 21, 2026.

Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.