Agent skill

Add Relationship

by cartography-cncf in cartography-cncf/cartography

Define a CartographyRelSchema (standard relationship), one-to-many edge, or MatchLink connecting existing nodes.

Apache-2.0Auto-check passed

Install Add Relationship

skills CLI
$ npx skills add cartography-cncf/cartography --skill add-relationship -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cartography-cncf/cartography add-relationship --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/add-relationship .claude/skills/add-relationship && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
add-relationship
GitHub stars
4.1k
Token cost
~1.7k tokens
SKILL.md length
383 words
Files
3 (incl. references)
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

Define a CartographyRelSchema (standard relationship), one-to-many edge, or MatchLink connecting existing nodes.

  • Works in 6 steps: Standard relationship → Pick a direction → One-to-many → …
  • The user asks to add a relationship
  • SKILL.md covers Critical rules, Instructions, Common issues and References (load on demand)
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Add Relationship is an agent skill from cartography-cncf/cartography. Define a CartographyRelSchema (standard relationship), one-to-many edge, or MatchLink connecting existing nodes. Use when the user asks to add a relationship, link nodes, set a RESOURCE / MEMBEROF / ASSOCIATEDWITH edge, share a node across modules, or model a composite node from two intel sources.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/matchlinks.md` and `references/multi-module-patterns.md`).

The repository describes itself as: Cartography is a Python tool that pulls infrastructure assets and their relationships into a Neo4j graph database. The licence is Apache-2.0.

When your agent uses it

  • The user asks to add a relationship
  • Set a RESOURCE / MEMBEROF / ASSOCIATEDWITH edge
  • Share a node across modules
  • Model a composite node from two intel sources

Example prompts

  • “/add-relationship”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Standard relationship
  2. Pick a direction
  3. One-to-many
  4. Decide whether you need a MatchLink
  5. MatchLink schema
  6. Load + cleanup MatchLinks

What it can do on your machine

Read from SKILL.md and the folder at commit fe004c7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Add Relationship loads about 1.7k tokens when it runs, and up to ~4.1k if it reads all its reference files. Until then it costs about 82 tokens; SKILL.md has 383 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cartography-cncf/cartography at commit fe004c7, republished under its Apache-2.0 licence (© cartography-cncf). 383 words, ~1,718 tokens.

Download SKILL.mdSave it as .claude/skills/add-relationship/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
add-relationship
description
Define a `CartographyRelSchema` (standard relationship), one-to-many edge, or `MatchLink` connecting existing nodes. Use when the user asks to add a relationship, link nodes, set a `RESOURCE` / `MEMBER_OF` / `ASSOCIATED_WITH` edge, share a node across modules, or model a composite node from two intel sources.

add-relationship

Add a relationship between Cartography nodes. Cover three flavours:

  1. Standard relationship on a node schema (other_relationships or sub_resource_relationship).
  2. One-to-many with PropertyRef(..., one_to_many=True).
  3. MatchLink for connecting two already-existing nodes — use sparingly.

Critical rules

  1. Prefer standard relationships in node schemas. MatchLinks have a real performance cost (extra MATCH reads).
  2. Use MatchLinks only when: the relationship data comes from a separate source and connects two existing node types, or the relationship needs rich metadata that doesn't belong on either node.
  3. MatchLink relationship properties must include lastupdated, _sub_resource_label, _sub_resource_id (all set_in_kwargs=True).
  4. Always implement cleanup. Standard rels: GraphJob.from_node_schema(). MatchLinks: GraphJob.from_matchlink().
  5. sub_resource_relationship always points to a tenant-like node. See the add-node-type skill.

Instructions

Step 1 — Standard relationship

Define rel properties (typically just lastupdated) and the relationship itself, then attach it to a node schema via sub_resource_relationship (tenant link) or other_relationships (business link).

python
from cartography.models.core.relationships import (
    CartographyRelSchema, CartographyRelProperties, LinkDirection,
    make_target_node_matcher, TargetNodeMatcher,
)


@dataclass(frozen=True)
class YourServiceTenantToUserRelProperties(CartographyRelProperties):
    lastupdated: PropertyRef = PropertyRef("lastupdated", set_in_kwargs=True)


@dataclass(frozen=True)
class YourServiceTenantToUserRel(CartographyRelSchema):
    target_node_label: str = "YourServiceTenant"
    target_node_matcher: TargetNodeMatcher = make_target_node_matcher({
        "id": PropertyRef("TENANT_ID", set_in_kwargs=True),
    })
    direction: LinkDirection = LinkDirection.OUTWARD
    rel_label: str = "RESOURCE"
    properties: YourServiceTenantToUserRelProperties = YourServiceTenantToUserRelProperties()
Step 2 — Pick a direction
  • LinkDirection.OUTWARD: (:Source)-[:REL]->(:Target)
  • LinkDirection.INWARD: (:Source)<-[:REL]-(:Target)

Sub-resource relationships use INWARD ((:Tenant)-[:RESOURCE]->(:Resource) from the tenant's POV is INWARD for the resource side).

Step 3 — One-to-many

Flatten target IDs in transform() and use one_to_many=True:

python
# transform
{"id": "rtb-123", "subnet_ids": ["subnet-abc", "subnet-def"]}

# rel
@dataclass(frozen=True)
class RouteTableToSubnetRel(CartographyRelSchema):
    target_node_label: str = "AWSEC2Subnet"
    target_node_matcher: TargetNodeMatcher = make_target_node_matcher({
        "subnet_id": PropertyRef("subnet_ids", one_to_many=True),
    })
    direction: LinkDirection = LinkDirection.OUTWARD
    rel_label: str = "ASSOCIATED_WITH"
    properties: RouteTableToSubnetRelProperties = RouteTableToSubnetRelProperties()

Cartography expands one_to_many into one edge per ID in the list.

Use a MatchLink when:

  • The relationship comes from a separate API call / data source that maps two already-loaded node types.
  • The relationship needs rich metadata (e.g. CVE remediation details, fix version, file path) that doesn't belong on either node.

Don't use MatchLinks for:

  • Standard parent-child relationships (use other_relationships).
  • Simple one-to-many (use one_to_many=True).
  • Cases where the relationship can be defined inside the node schema.
  • Performance-critical paths.
Show full SKILL.md (119 more words)Show less
python
from cartography.models.core.relationships import (
    CartographyRelSchema, CartographyRelProperties, LinkDirection,
    make_target_node_matcher, TargetNodeMatcher,
    make_source_node_matcher, SourceNodeMatcher,
)


@dataclass(frozen=True)
class RoleAssignmentRelProperties(CartographyRelProperties):
    lastupdated: PropertyRef = PropertyRef("lastupdated", set_in_kwargs=True)
    _sub_resource_label: PropertyRef = PropertyRef("_sub_resource_label", set_in_kwargs=True)
    _sub_resource_id: PropertyRef = PropertyRef("_sub_resource_id", set_in_kwargs=True)


@dataclass(frozen=True)
class RoleAssignmentAllowedByMatchLink(CartographyRelSchema):
    target_node_label: str = "AWSRole"
    target_node_matcher: TargetNodeMatcher = make_target_node_matcher({
        "arn": PropertyRef("RoleArn"),
    })
    source_node_label: str = "AWSSSOUser"
    source_node_matcher: SourceNodeMatcher = make_source_node_matcher({
        "id": PropertyRef("UserId"),
    })
    direction: LinkDirection = LinkDirection.OUTWARD
    rel_label: str = "ALLOWED_BY"
    properties: RoleAssignmentRelProperties = RoleAssignmentRelProperties()
python
load_matchlinks(
    neo4j_session,
    RoleAssignmentAllowedByMatchLink(),
    role_assignments,
    lastupdated=update_tag,
    _sub_resource_label="AWSAccount",
    _sub_resource_id=aws_account_id,
)


def cleanup(neo4j_session, common_job_parameters):
    GraphJob.from_node_schema(YourNodeSchema(), common_job_parameters).run(neo4j_session)
    GraphJob.from_matchlink(
        YourMatchLinkSchema(),
        "AWSAccount",                      # _sub_resource_label
        common_job_parameters["AWS_ID"],   # _sub_resource_id
        common_job_parameters["UPDATE_TAG"],
    ).run(neo4j_session)

For richer MatchLink scenarios (rich rel properties, optional MatchLinkSubResource scoping, multi-module composite nodes), see references/matchlinks.md and references/multi-module-patterns.md.

Common issues

  • Relationship not created — the target node didn't exist when the rel was loaded. Load parent nodes first.
  • Matcher property mismatch — target_node_matcher keys must match the target node's property names (e.g. id, arn).
  • MatchLink misses — both source and target nodes must already exist before load_matchlinks().
  • Cleanup deletes too much — confirm _sub_resource_id and UPDATE_TAG in common_job_parameters.

For the full troubleshooting list, see the troubleshooting skill.

References (load on demand)

  • references/matchlinks.md — MatchLink performance impact, rich-property example (Inspector findings), MatchLinkSubResource scoping.
  • references/multi-module-patterns.md — simple-relationship vs composite-node patterns when multiple intel modules touch the same node label.

© cartography-cncf, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .agents/skills/add-relationship of cartography-cncf/cartography.

  • SKILL.md
  • references/matchlinks.md
  • references/multi-module-patterns.md

Open the folder on GitHubat commit fe004c7

Compare with similar skills

Add Relationship next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Add Relationship compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Add Relationship this skillcartography-cncf/cartography4.1k—~1.7kAutomated safety check: PassApache-2.0
Dce Edgevercel/next.js143k—~1kAutomated safety check: PassMIT
Telemetry Standardssupabase/supabase111k—~2kAutomated safety check: PassApache-2.0
Cpp Coding Standardsaffaan-m/ECC276k4 repos~5.6kAutomated safety check: PassMIT
Java Coding Standardsaffaan-m/ECC276k1 repos~2.9kAutomated safety check: PassMIT
Android Edge To EdgeHoangNguyen0403/agent-skills-standard572—~769Automated safety check: PassMIT

Similar skills

  • Dce Edge

    vercel/next.js

    Official

    DCE-safe require() patterns and edge runtime constraints. An agent skill from vercel/next.js.

    143k GitHub stars~1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Telemetry Standards

    supabase/supabase

    Official

    PostHog event tracking standards for Supabase Studio. An agent skill from supabase/supabase.

    111k GitHub stars~2k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • C++ coding standards based on the C++ Core Guidelines (isocpp.github.io).

    276k GitHub starsUsed in 4 repos~5.6k tokens
    DevelopmentAuto-check passed
  • Java coding standards for Spring Boot and Quarkus services: naming, immutability, Optional usage, streams, exceptions, generics, CDI, reactive patterns, and project layout.

    276k GitHub starsUsed in 1 repo~2.9k tokens
    DevelopmentAuto-check passed
  • Android Edge To Edge

    HoangNguyen0403/agent-skills-standard

    Migrate a Jetpack Compose app to edge-to-edge display and fix system bar inset issues.

    572 GitHub stars~769 tokensUpdated today
    MobileAuto-check passed
  • Coding Standards

    affaan-m/ECC

    适用于TypeScript、JavaScript、React和Node.js开发的通用编码标准、最佳实践和模式. An agent skill from affaan-m/ECC.

    276k GitHub starsUsed in 3 repos~2.6k tokens
    DevelopmentAuto-check passed

More from cartography-cncf/cartography

All 11 skills in this repo
  • Add Node Type

    cartography-cncf/cartography

    Define a new node schema under cartography/models/MODULENAME/, including required properties, sub-resource relationships, extra labels, conditional labels, scoped cleanup, and one-to-many transforms.

    4.1k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Analysis Jobs

    cartography-cncf/cartography

    Add a post-ingestion typed analysis job to a Cartography module to enrich the graph after sync.

    4.1k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Create Module

    cartography-cncf/cartography

    Author a new Cartography intel module end-to-end (entry point, sync GET/TRANSFORM/LOAD/CLEANUP, declarative data model, integration test, schema docs).

    4.1k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Create Rule

    cartography-cncf/cartography

    Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.

    4.1k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Enrich Ontology

    cartography-cncf/cartography

    Map a Cartography node into the Ontology system using semantic labels (UserAccount, DeviceInstance, Tenant, Database, ObjectStorage, FileStorage) or canonical nodes (User, Device).

    4.1k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Promote Ontology Relationship

    cartography-cncf/cartography

    Promote provider-specific relationships to a canonical cross-provider ontology edge using the WORKLOADPARENT pattern (a parallel CartographyRelSchema with the canonical rellabel, the old edge kept…

    4.1k GitHub stars~3.6k tokensUpdated today
    Auto-check passed

Questions about Add Relationship

What does Add Relationship do?

Define a CartographyRelSchema (standard relationship), one-to-many edge, or MatchLink connecting existing nodes. Add Relationship is an agent skill from cartography-cncf/cartography. Define a CartographyRelSchema (standard relationship), one-to-many edge, or MatchLink connecting existing nodes.

When should I use Add Relationship?

Add Relationship fits situations like: the user asks to add a relationship; set a RESOURCE / MEMBEROF / ASSOCIATEDWITH edge; share a node across modules; model a composite node from two intel sources.

How do I install Add Relationship in Claude Code?

Run `npx skills add cartography-cncf/cartography --skill add-relationship -a claude-code`. Or copy the skill folder (.agents/skills/add-relationship in cartography-cncf/cartography) into .claude/skills/add-relationship in your project. Claude Code loads it when a task matches its description.

How do I install Add Relationship in Codex?

Run `npx skills add cartography-cncf/cartography --skill add-relationship -a codex`. Or copy the skill folder (.agents/skills/add-relationship in cartography-cncf/cartography) into .agents/skills/add-relationship in your project. Codex loads it when a task matches its description.

Can I use Add Relationship in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cartography-cncf/cartography --skill add-relationship -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-relationship, .gemini/skills/add-relationship, .github/skills/add-relationship and .opencode/skills/add-relationship in your project.

What does Add Relationship need to run?

SKILL.md names no scripts, command-line tools or credentials: Add Relationship is instructions for the agent only. Our summary lists: Python 3.

Does Add Relationship access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Add Relationship safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Add Relationship use?

Add Relationship is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Add Relationship use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Add Relationship?

Skills that share tags, products or a category with Add Relationship: Dce Edge (vercel/next.js, 143k stars), Telemetry Standards (supabase/supabase, 111k stars), Cpp Coding Standards (affaan-m/ECC, 276k stars) and Java Coding Standards (affaan-m/ECC, 276k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Add Relationship?

cartography-cncf (a GitHub organization) maintains it in cartography-cncf/cartography, which has 4,128 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 10, 2026.

Source: cartography-cncf/cartography on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.