Agent skill

Skill Graph Audit

by athola in athola/claude-night-market

Audit Skill() refs; detect hubs, isolates, and dangling targets.

MITAuto-check passedDevelopment

Install Skill Graph Audit

skills CLI
$ npx skills add athola/claude-night-market --skill skill-graph-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install athola/claude-night-market skill-graph-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/abstract/skills/skill-graph-audit .claude/skills/skill-graph-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-graph-audit
GitHub stars
341
Token cost
~1.3k tokens
SKILL.md length
482 words
Files
3
Skills in repo
154
Repo updated
First seen
Licence
MIT

At a glance

Audit Skill() refs; detect hubs, isolates, and dangling targets.

  • Works in 2 steps: Test-suite correctness check: Run… → Round-trip smoke check: Note the…
  • Auditing skills
  • SKILL.md covers Overview, When To Use, When NOT To Use and Quick Start, plus 6 more sections
  • Calls python3, uv and pytest

What it does

Skill Graph Audit is an agent skill from athola/claude-night-market. Audit Skill() refs; detect hubs, isolates, and dangling targets. Use when auditing skills.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `modules/interpretation.md` and `modules/usage.md`).

It sits in Development. The repository describes itself as: 23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context… The licence is MIT.

When your agent uses it

  • Auditing skills

Example prompts

  • “/skill-graph-audit”

Requirements

  • Python 3

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Test-suite correctness check: Run `pytest -o addopts=
  2. Round-trip smoke check: Note the dangling-ref count from a

What it can do on your machine

Read from SKILL.md and the folder at commit 9f3eb00. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • uv
    • pytest

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Skill Graph Audit loads about 1.3k tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 482 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~27
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from athola/claude-night-market at commit 9f3eb00, republished under its MIT licence (© athola). 482 words, ~1,255 tokens.

Download SKILL.mdSave it as .claude/skills/skill-graph-audit/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
skill-graph-audit
description
Audit Skill() refs; detect hubs, isolates, and dangling targets. Use when auditing skills.
role
library
category
skill-management
alwaysApply
false
modules
modules/usage.md, modules/interpretation.md

Skill Graph Audit

Overview

Build a directed graph of Skill(plugin:name) invocations across the marketplace and surface composition patterns: which skills are heavily referenced (hubs), which orchestrate many others (orchestrators), which have no incoming or outgoing references (isolates), and which point at non-existent skills (dangling references).

The federation graph is now derivable from source rather than hand-curated.

When To Use

  • Before a documentation pass on skill composition
  • After a renaming or retirement to catch broken Skill() references
  • During quarterly audits to spot orphaned skills
  • When evaluating consolidation candidates (hubs are higher-risk to merge)
  • When a new skill's outbound references should be sanity-checked

When NOT To Use

  • For per-skill quality scoring, use Skill(abstract:skills-eval) instead
  • For frontmatter/structure validation, use Skill(abstract:plugin-review)
  • For hook-specific audits, use Skill(abstract:hooks-eval)

Quick Start

bash
# Positive control first. The fixture tree has a known answer (1
# bug-class dangling ref, 1 isolate, 2 edges); a regex that stopped
# matching would report plugins/ as clean, and this catches it.
uv run pytest -o addopts= -q plugins/abstract/tests/scripts/test_skill_graph.py -k Planted

python3 plugins/abstract/scripts/skill_graph.py \
  --plugins-root plugins --top-n 10

For machine-readable output:

bash
python3 plugins/abstract/scripts/skill_graph.py \
  --plugins-root plugins --format json --output reports/skill-graph.json

See modules/usage.md for full CLI reference and example workflows.

Core Outputs

OutputMeaningAction when high
HubsMost-referenced skillsTreat as core API; retire with extreme care
OrchestratorsSkills that call many othersVerify each ref still resolves
IsolatesZero in / zero outCheck role: library? entrypoint? typo?
Dangling: bugsMissing internal targetFix immediately (typo or retired skill)
Dangling: externalReference to external pluginDocument plugin dependency
Dangling: placeholdersTemplate text like -NAMEVerify intentional

See modules/interpretation.md for false-positive guidance and isolation taxonomy.

Dogfood Evidence

This skill itself was scaffolded TDD-first; on first run against plugins/, it caught two genuine dangling refs that the manual audit (2026-04-25) had missed:

  • attune:makefile-generation -> abstract:makefile-dogfooder (script name confused with skill name)
  • imbue:karpathy-principles -> spec-kit:speckit-clarify (command referenced as skill)

Both were converted to correct command-style references in the same session.

Show full SKILL.md (220 more words)Show less

Verification

Two ways to validate the audit output is trustworthy:

  1. Test-suite correctness check: Run pytest -o addopts= plugins/abstract/tests/scripts/test_skill_graph.py to confirm extraction, graph construction, ranking, isolate detection, and dangling-ref classification all pass on the current code. The -o addopts= flag bypasses the package-wide coverage gate, which would otherwise fail on a single-file run.
  2. Round-trip smoke check: Note the dangling-ref count from a baseline run, fix one or more flagged references, then rerun and verify the count drops by at least the number fixed. If the count does not move, the report is stale or the regex missed a syntax variant.

Exit Criteria

  • The planted fixture test passed before the audit ran; a clean report on plugins/ is not reportable without it
  • The graph builds: skill_graph.py runs against plugins/ without error and emits a node/edge count.
  • Dangling references are classified into bugs, external, and placeholders (the three Core Outputs rows resolve).
  • Every Dangling: bugs entry is either fixed in the same session or filed as a tracked issue.
  • pytest -o addopts= plugins/abstract/tests/scripts/test_skill_graph.py passes.
  • The round-trip smoke check shows the dangling-ref count drops by at least the number of references fixed.
  • Skill(abstract:skills-eval): per-skill quality scoring
  • Skill(abstract:plugin-review): plugin manifest and structure
  • Skill(abstract:hooks-eval): hook-specific validation
  • Skill(abstract:rules-eval): rules directory validation

References

  • Implementation: plugins/abstract/scripts/skill_graph.py
  • Tests: plugins/abstract/tests/scripts/test_skill_graph.py
  • Composition documentation: docs/quality-gates.md#skill-level-quality-gate-composition
  • Skill role taxonomy: docs/skill-integration-guide.md#skill-role-taxonomy

© athola, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in plugins/abstract/skills/skill-graph-audit of athola/claude-night-market.

  • SKILL.md
  • modules/interpretation.md
  • modules/usage.md

Open the folder on GitHubat commit 9f3eb00

Compare with similar skills

Skill Graph Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skill Graph Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skill Graph Audit this skillathola/claude-night-market341—~1.3kAutomated safety check: PassMIT
Vercel Composition Patternssupabase/supabase111k58 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 58 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from athola/claude-night-market

All 154 skills in this repo
  • Night Market Diagnostics Toolkit

    athola/claude-night-market

    Run and interpret repo diagnostic scripts (ratchets, validators, token stats).

    341 GitHub stars~3.4k tokensUpdated 3 days ago
    Auto-check passed
  • Skills Eval

    athola/claude-night-market

    Evaluate Claude skill quality through auditing. An agent skill from athola/claude-night-market.

    341 GitHub stars~1.6k tokensUpdated 3 days ago
    Auto-check passed
  • Agent Teams

    athola/claude-night-market

    Coordinates Claude agent teams via filesystem protocol. An agent skill from athola/claude-night-market.

    341 GitHub stars~2.5k tokensUpdated 3 days ago
    Auto-check passed
  • Delegation Core

    athola/claude-night-market

    Delegates execution to eight CLIs (Gemini, Qwen, MiniMax, GLM, Muse, Codex, OpenCode, Glimmer).

    341 GitHub stars~2.5k tokensUpdated 3 days ago
    Auto-check passed
  • Elegant Code

    athola/claude-night-market

    Guide minimal code via a decision ladder with full safety, edge, and negative-case coverage.

    341 GitHub stars~2.1k tokensUpdated 3 days ago
    Auto-check passed
  • Skill Library Mission

    athola/claude-night-market

    Build a project skill library in .claude/skills/ via discovery, parallel authoring, and review.

    341 GitHub stars~1.6k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Skill Graph Audit

What does Skill Graph Audit do?

Audit Skill() refs; detect hubs, isolates, and dangling targets. Skill Graph Audit is an agent skill from athola/claude-night-market. Audit Skill() refs; detect hubs, isolates, and dangling targets.

When should I use Skill Graph Audit?

Skill Graph Audit fits situations like: auditing skills.

How do I install Skill Graph Audit in Claude Code?

Run `npx skills add athola/claude-night-market --skill skill-graph-audit -a claude-code`. Or copy the skill folder (plugins/abstract/skills/skill-graph-audit in athola/claude-night-market) into .claude/skills/skill-graph-audit in your project. Claude Code loads it when a task matches its description.

How do I install Skill Graph Audit in Codex?

Run `npx skills add athola/claude-night-market --skill skill-graph-audit -a codex`. Or copy the skill folder (plugins/abstract/skills/skill-graph-audit in athola/claude-night-market) into .agents/skills/skill-graph-audit in your project. Codex loads it when a task matches its description.

Can I use Skill Graph Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add athola/claude-night-market --skill skill-graph-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-graph-audit, .gemini/skills/skill-graph-audit, .github/skills/skill-graph-audit and .opencode/skills/skill-graph-audit in your project.

What does Skill Graph Audit need to run?

Going by SKILL.md and its folder, Skill Graph Audit needs the command-line tools its instructions call (python3, uv and pytest). Our summary lists: Python 3.

Does Skill Graph Audit access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Skill Graph Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Skill Graph Audit use?

Skill Graph Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skill Graph Audit use?

About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Skill Graph Audit?

Skills that share tags, products or a category with Skill Graph Audit: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skill Graph Audit?

athola (a GitHub user) maintains it in athola/claude-night-market, which has 341 GitHub stars. The repository holds 154 skills in this directory. The repository was last updated on October 6, 2026.

Source: athola/claude-night-market on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.