Agent skill

Analysis Jobs

by cartography-cncf in cartography-cncf/cartography

Add a post-ingestion typed analysis job to a Cartography module to enrich the graph after sync.

Apache-2.0Auto-check passed

Install Analysis Jobs

skills CLI
$ npx skills add cartography-cncf/cartography --skill analysis-jobs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cartography-cncf/cartography analysis-jobs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/analysis-jobs .claude/skills/analysis-jobs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analysis-jobs
GitHub stars
4.1k
Token cost
~2k tokens
SKILL.md length
660 words
Files
2 (incl. references)
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

Add a post-ingestion typed analysis job to a Cartography module to enrich the graph after sync.

  • Works in 6 steps: Pick global vs scoped → Author the typed job → Write the queries → …
  • The user asks to compute internet exposure
  • SKILL.md covers When to use analysis jobs, Critical rules, Instructions and Best practices, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Analysis Jobs is an agent skill from cartography-cncf/cartography. Add a post-ingestion typed analysis job to a Cartography module to enrich the graph after sync. Use when the user asks to compute internet exposure, propagate inherited permissions, link Human / canonical ontology nodes, score risk, or add cross-resource analysis after data is loaded.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/examples.md`).

The repository describes itself as: Cartography is a Python tool that pulls infrastructure assets and their relationships into a Neo4j graph database. The licence is Apache-2.0.

When your agent uses it

  • The user asks to compute internet exposure
  • Propagate inherited permissions
  • Link Human / canonical ontology nodes
  • Add cross-resource analysis after data is loaded

Example prompts

  • “/analysis-jobs”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Pick global vs scoped
  2. Author the typed job
  3. Write the queries
  4. Available parameters
  5. Wire the call into your module
  6. Test it

What it can do on your machine

Read from SKILL.md and the folder at commit 0975e95. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Analysis Jobs loads about 2k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 75 tokens; SKILL.md has 660 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cartography-cncf/cartography at commit 0975e95, republished under its Apache-2.0 licence (© cartography-cncf). 660 words, ~2,038 tokens.

Download SKILL.mdSave it as .claude/skills/analysis-jobs/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
analysis-jobs
description
Add a post-ingestion typed analysis job to a Cartography module to enrich the graph after sync. Use when the user asks to compute internet exposure, propagate inherited permissions, link Human / canonical ontology nodes, score risk, or add cross-resource analysis after data is loaded.

analysis-jobs

Analysis jobs are post-ingestion typed Python definitions under cartography/analysis/*/analysis.py that enrich the graph with computed relationships and properties. Custom JSON jobs are still supported for local extensions and legacy cleanup. They run after data is loaded and perform cross-node work that cannot be done during the initial load.

When to use analysis jobs

Use them when you need to:

  1. Compute properties that depend on multiple nodes / relationships.
  2. Create relationships that span across resource types.
  3. Perform transitive closure (e.g. inherited permissions).
  4. Enrich data after all resources of a type are loaded.

Do NOT use analysis jobs for:

  1. Simple node-to-node relationships (use the data model - see add-relationship).
  2. Properties that can be computed during transform().
  3. Relationships already present in the source data.

Critical rules

  1. Pick the right scope. Global typed jobs run after all accounts/projects/tenants. Scoped typed jobs run once per account. Both use run_typed_analysis_job; the scope lives on AnalysisJob.scope. Use dependency checking (run_typed_analysis_and_ensure_deps) when a job needs specific upstream modules.
  2. Use iterative queries for large datasets. They must return COUNT(*) AS TotalCompleted.
  3. Document each query with __comment__.
  4. Clean up stale data that the analysis job creates (don't leave orphan edges between syncs).
  5. Order statements correctly to avoid read windows.
    • Properties: clean up first (REMOVE n.attr), then SET. Cleanup of attributes can usually run in a single transaction.
    • Relationships: MERGE first, then DELETE stale (WHERE r.lastupdated <> $UPDATE_TAG). Iterative DELETE commits per batch, so a leading DELETE of relationships exposes a graph with those edges missing to concurrent readers until the MERGE finishes. MERGE is idempotent and bumps r.lastupdated, so the trailing DELETE only targets edges that genuinely no longer have a current basis. Canonical example: AWS_LAMBDA_ECR in cartography/analysis/aws/analysis.py.

Instructions

Step 1 - Pick global vs scoped
TypeRunsLocationHelper
GlobalOnce after all accounts / projectscartography/analysis/*/analysis.pyrun_typed_analysis_job()
ScopedOnce per account / project / tenantcartography/analysis/*/analysis.pyrun_typed_analysis_job()

Examples:

  • Internet exposure that needs to see all security groups across all accounts -> global.
  • IAM instance profile analysis that runs per AWS account -> scoped.
Step 2 - Author the typed job
python
AnalysisJob(
    name="Human-readable name for logging",
    short_name="your_module_exposure_analysis",
    statements=(
        AnalysisStatement(
            match="MATCH (n:NodeType) WHERE ...",
            effects=(SetProperty("n", "property", True, label="NodeType"),),
        ),
    ),
)

Typed jobs read as:

text
AnalysisJob(scope=CleanupScopedTo(...))
    -> AnalysisStatement(match="MATCH ...", effects=(...))
        -> SetProperty / AddToSet / AddValuesToSet / AddRelationship / SetRelationshipProperty

label is required for node-property effects so cleanup knows which label owns the property. Plain strings become quoted Cypher strings. Use Var("node.property"), Param("UPDATE_TAG"), or RawCypher("coalesce(...)") when the value should compile as Cypher.

CleanupScopedTo(...) on the job defines the account/project/tenant boundary used by generated cleanup. scoped_to="source" or "target" on AddRelationship chooses which endpoint is attached to that scoped resource; keep the default source unless the target node is the scoped resource.

Show full SKILL.md (241 more words)Show less
Step 3 - Write the queries

Non-iterative - single execution, OK for queries touching a manageable number of nodes:

python
AnalysisStatement(
    match="MATCH (instance:GCPInstance) WHERE ...",
    effects=(SetProperty("instance", "exposed_internet", True, label="GCPInstance"),),
)

Iterative raw query - required for large raw statements. Must return TotalCompleted:

python
AnalysisStatement(
    query="MATCH (n:Node) WHERE n.stale = true WITH n LIMIT $LIMIT_SIZE DELETE n RETURN COUNT(*) AS TotalCompleted",
    iterative=True,
    iterationsize=1000,
)
Step 4 - Available parameters

common_job_parameters is forwarded into the query. Typical params:

-- $UPDATE_TAG - current sync timestamp. -- $LIMIT_SIZE - set automatically by the iterative runner.

  • Module-specific ($AWS_ID, $PROJECT_ID, ...).
Step 5 - Wire the call into your module
Pattern A - global analysis at end of ingestion
python
from cartography.util import run_typed_analysis_job
from cartography.analysis.your_module.analysis import YOUR_MODULE_EXPOSURE_ANALYSIS

@timeit
def start_your_module_ingestion(neo4j_session: neo4j.Session, config: Config) -> None:
    common_job_parameters = {"UPDATE_TAG": config.update_tag}

    for account in accounts:
        _sync_one_account(neo4j_session, account, config.update_tag, common_job_parameters)

    run_typed_analysis_job(
        YOUR_MODULE_EXPOSURE_ANALYSIS,
        neo4j_session,
        common_job_parameters,
    )
Pattern B - scoped per account/project
python
from cartography.util import run_typed_analysis_job
from cartography.analysis.your_module.analysis import YOUR_MODULE_ACCOUNT_ANALYSIS

def _sync_one_account(neo4j_session, account_id, update_tag, common_job_parameters):
    common_job_parameters["ACCOUNT_ID"] = account_id

    sync_resources(neo4j_session, account_id, update_tag, common_job_parameters)

    run_typed_analysis_job(
        YOUR_MODULE_ACCOUNT_ANALYSIS,
        neo4j_session,
        common_job_parameters,
    )
Pattern C - conditional with dependency checking
python
from cartography.util import run_typed_analysis_and_ensure_deps
from cartography.analysis.your_module.analysis import YOUR_MODULE_COMBINED_ANALYSIS

def _perform_analysis(requested_syncs, neo4j_session, common_job_parameters):
    run_typed_analysis_and_ensure_deps(
        YOUR_MODULE_COMBINED_ANALYSIS,
        {"ec2:instance", "ec2:security_group"},  # required upstream syncs
        set(requested_syncs),
        common_job_parameters,
        neo4j_session,
    )
Step 6 - Test it

Add an integration test that:

  1. Calls sync() with mocked external boundaries.
  2. Asserts the analysis-produced edges / properties using check_nodes / check_rels.

See the create-module skill for testing conventions.

Best practices

  1. Right scope. Global runs after all accounts; scoped runs per-account.
  2. Use dep-checking (run_typed_analysis_and_ensure_deps) when a typed job requires upstream modules.
  3. Document queries with __comment__.
  4. Test analysis jobs with integration tests.
  5. Use iterative queries for large datasets.
  6. Clean up stale data the job creates.

Common issues

  • Job runs before the upstream module - switch to run_analysis_and_ensure_deps with the right deps.
  • Iterative query never terminates - make sure it returns COUNT(*) AS TotalCompleted and the matched set shrinks each iteration.
  • Wrong scope - global query reading per-account state can be empty if it runs in the wrong place.

For broader troubleshooting, see the troubleshooting skill.

References (load on demand)

  • references/examples.md - GCP, AWS, Semgrep wiring examples plus the audit table of modules with proper analysis-job integration.

© cartography-cncf, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .agents/skills/analysis-jobs of cartography-cncf/cartography.

  • SKILL.md
  • references/examples.md

Open the folder on GitHubat commit 0975e95

Compare with similar skills

Analysis Jobs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Analysis Jobs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Analysis Jobs this skillcartography-cncf/cartography4.1k—~2kAutomated safety check: PassApache-2.0
Rust Path Typesopeninterpreter/openinterpreter69k2 repos~605Automated safety check: PassApache-2.0
Python Type Safetywshobson/agents40k—~1.4kAutomated safety check: PassMIT
Technical Job Searchgithub/awesome-copilot40k—~1.2kAutomated safety check: PassMIT
Pyrefly Type Coveragepytorch/pytorch104k—~3kAutomated safety check: PassCustom licence
Wiki Ingestpaperclipai/paperclip100k—~933Automated safety check: PassMIT

Similar skills

  • Rust Path Types

    openinterpreter/openinterpreter

    Rules for choosing Rust types for filesystem paths in new Codex code, covering protocol types, internal use and model tool arguments.

    69k GitHub starsUsed in 2 repos~605 tokens
    DevelopmentAuto-check passed
  • Python Type Safety

    wshobson/agents

    Python type safety with type hints, generics, protocols, and strict type checking.

    40k GitHub stars~1.4k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Technical Job Search

    github/awesome-copilot

    Official

    A skill your agent uses when a software engineer asks for help with job search tasks: parsing or analyzing a job description, tailoring a CV/resume, writing a cover letter, evaluating a job offer…

    40k GitHub stars~1.2k tokensUpdated 2 days ago
    Business, Finance & HRAuto-check passed
  • Pyrefly Type Coverage

    pytorch/pytorch

    Migrate a file to use stricter Pyrefly type checking with annotations required for all functions, classes, and attributes.

    104k GitHub stars~3k tokensUpdated today
    DevelopmentAuto-check passed
  • Wiki Ingest

    paperclipai/paperclip

    A skill your agent uses when an operation issue asks to ingest a captured raw/ source into the LLM Wiki, or the user says "ingest <slug".

    100k GitHub stars~933 tokensUpdated today
    Knowledge ManagementAuto-check passed
  • Official

    How to add a new ingestion warning type to the event ingestion pipeline.

    40k GitHub stars~3.7k tokensUpdated yesterday
    DatabasesAuto-check passed

More from cartography-cncf/cartography

All 11 skills in this repo
  • Add Node Type

    cartography-cncf/cartography

    Define a new node schema under cartography/models/MODULENAME/, including required properties, sub-resource relationships, extra labels, conditional labels, scoped cleanup, and one-to-many transforms.

    4.1k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Add Relationship

    cartography-cncf/cartography

    Define a CartographyRelSchema (standard relationship), one-to-many edge, or MatchLink connecting existing nodes.

    4.1k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Create Module

    cartography-cncf/cartography

    Author a new Cartography intel module end-to-end (entry point, sync GET/TRANSFORM/LOAD/CLEANUP, declarative data model, integration test, schema docs).

    4.1k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Create Rule

    cartography-cncf/cartography

    Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.

    4.1k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Enrich Ontology

    cartography-cncf/cartography

    Map a Cartography node into the Ontology system using semantic labels (UserAccount, DeviceInstance, Tenant, Database, ObjectStorage, FileStorage) or canonical nodes (User, Device).

    4.1k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Promote Ontology Relationship

    cartography-cncf/cartography

    Promote provider-specific relationships to a canonical cross-provider ontology edge using the WORKLOADPARENT pattern (a parallel CartographyRelSchema with the canonical rellabel, the old edge kept…

    4.1k GitHub stars~3.6k tokensUpdated today
    Auto-check passed

Questions about Analysis Jobs

What does Analysis Jobs do?

Add a post-ingestion typed analysis job to a Cartography module to enrich the graph after sync. Analysis Jobs is an agent skill from cartography-cncf/cartography. Add a post-ingestion typed analysis job to a Cartography module to enrich the graph after sync.

When should I use Analysis Jobs?

Analysis Jobs fits situations like: the user asks to compute internet exposure; propagate inherited permissions; link Human / canonical ontology nodes; add cross-resource analysis after data is loaded.

How do I install Analysis Jobs in Claude Code?

Run `npx skills add cartography-cncf/cartography --skill analysis-jobs -a claude-code`. Or copy the skill folder (.agents/skills/analysis-jobs in cartography-cncf/cartography) into .claude/skills/analysis-jobs in your project. Claude Code loads it when a task matches its description.

How do I install Analysis Jobs in Codex?

Run `npx skills add cartography-cncf/cartography --skill analysis-jobs -a codex`. Or copy the skill folder (.agents/skills/analysis-jobs in cartography-cncf/cartography) into .agents/skills/analysis-jobs in your project. Codex loads it when a task matches its description.

Can I use Analysis Jobs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cartography-cncf/cartography --skill analysis-jobs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analysis-jobs, .gemini/skills/analysis-jobs, .github/skills/analysis-jobs and .opencode/skills/analysis-jobs in your project.

What does Analysis Jobs need to run?

SKILL.md names no scripts, command-line tools or credentials: Analysis Jobs is instructions for the agent only. Our summary lists: Python 3.

Does Analysis Jobs access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Analysis Jobs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Analysis Jobs use?

Analysis Jobs is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Analysis Jobs use?

About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to Analysis Jobs?

Skills that share tags, products or a category with Analysis Jobs: Rust Path Types (openinterpreter/openinterpreter, 69k stars), Python Type Safety (wshobson/agents, 40k stars), Technical Job Search (github/awesome-copilot, 40k stars) and Pyrefly Type Coverage (pytorch/pytorch, 104k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Analysis Jobs?

cartography-cncf (a GitHub organization) maintains it in cartography-cncf/cartography, which has 4,129 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 11, 2026.

Source: cartography-cncf/cartography on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.