Agent skill

Create Module

by cartography-cncf in cartography-cncf/cartography

Author a new Cartography intel module end-to-end (entry point, sync GET/TRANSFORM/LOAD/CLEANUP, declarative data model, integration test, schema docs).

Apache-2.0Auto-check passedTesting & QA

Install Create Module

skills CLI
$ npx skills add cartography-cncf/cartography --skill create-module -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cartography-cncf/cartography create-module --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/create-module .claude/skills/create-module && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
create-module
GitHub stars
4.1k
Token cost
~2.5k tokens
SKILL.md length
775 words
Files
6 (incl. references)
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

Author a new Cartography intel module end-to-end (entry point, sync GET/TRANSFORM/LOAD/CLEANUP, declarative data model, integration test, schema docs).

  • Works in 10 steps: Lay out the module → Wire CLI + Config → Register the module in cartography/sync.py → …
  • The user asks to add a new provider
  • SKILL.md covers Critical rules, Instructions, Final checklist and Common issues, plus 1 more section
  • Calls git, make and pytest

What it does

Create Module is an agent skill from cartography-cncf/cartography. Author a new Cartography intel module end-to-end (entry point, sync GET/TRANSFORM/LOAD/CLEANUP, declarative data model, integration test, schema docs). Use when the user asks to add a new provider, integration, intel module, or service ingestion to Cartography (e.g. "add a new module for service X", "integrate ServiceY", "create a sync for Z API").

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/coding-conventions.md`, `references/config-docs.md` and `references/data-model.md`).

It sits in Testing & QA, covering Integration testing. The repository describes itself as: Cartography is a Python tool that pulls infrastructure assets and their relationships into a Neo4j graph database. The licence is Apache-2.0.

When your agent uses it

  • The user asks to add a new provider
  • Service ingestion to Cartography (e.g

Example prompts

  • “add a new module for service X”
  • “integrate ServiceY”
  • “create a sync for Z API”
  • “/create-module”

Requirements

  • Python 3

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Lay out the module
  2. Wire CLI + Config
  3. Register the module in cartography/sync.py
  4. Implement the sync pattern
  5. Define the data model
  6. Load + cleanup
  7. Integration test
  8. Module documentation
  9. Optional: analysis jobs
  10. Pre-submission checks

What it can do on your machine

Read from SKILL.md and the folder at commit e4eda50. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • make
    • pytest

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Create Module loads about 2.5k tokens when it runs, and up to ~8.3k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 775 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cartography-cncf/cartography at commit e4eda50, republished under its Apache-2.0 licence (© cartography-cncf). 775 words, ~2,471 tokens.

Download SKILL.mdSave it as .claude/skills/create-module/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
create-module
description
Author a new Cartography intel module end-to-end (entry point, sync GET/TRANSFORM/LOAD/CLEANUP, declarative data model, integration test, schema docs). Use when the user asks to add a new provider, integration, intel module, or service ingestion to Cartography (e.g. "add a new module for service X", "integrate ServiceY", "create a sync for Z API").

create-module

Build a brand new Cartography intel module from scratch using the modern declarative data model. The module must follow the standard sync pattern (get -> transform -> load -> cleanup) and be exercised by an integration test.

Critical rules

  1. Use the data model, not handwritten Cypher. Call load() / load_matchlinks() from cartography.client.core.tx, and GraphJob.from_node_schema() for cleanup.
  2. Sub-resource relationships always point to a tenant-like node (AWSAccount, AzureSubscription, GCPProject, GitHubOrganization, your <Service>Tenant). Never to an infrastructure parent.
  3. Required fields use direct dict access, optional fields use .get() with None default. Do not silently swallow exceptions in get().
  4. Only standard schema fields: any custom field added to a CartographyNodeSchema / CartographyRelSchema subclass is ignored. See the add-node-type and add-relationship skills.
  5. Integration tests must call sync(), not individual load() calls. Mock only external boundaries (API clients, credentials).
  6. All commits use git commit -s (DCO).

Instructions

Step 1 — Lay out the module
cartography/intel/your_service/
├── __init__.py          # Entry point: start_your_service_ingestion()
└── users.py             # Domain sync (or devices.py, projects.py, etc.)

cartography/models/your_service/
├── tenant.py            # Tenant/account schema
└── user.py              # Domain schemas

tests/data/your_service/
└── users.py             # Mock API payloads

tests/integration/cartography/intel/your_service/
└── test_users.py        # End-to-end sync test

The entry point (__init__.py) reads from Config, validates required credentials, builds common_job_parameters, and dispatches to per-domain sync() functions. See references/sync-pattern.md for a copy-paste template.

Step 2 — Wire CLI + Config

In cartography/cli.py:

  • Add PANEL_YOUR_SERVICE = "Your Service Options" and register it in MODULE_PANELS.
  • Add Typer options inside _build_app().run() (use Annotated[Optional[str], typer.Option(...)] with rich_help_panel=PANEL_YOUR_SERVICE).
  • Resolve secrets from os.environ and pass them into cartography.config.Config(...).

In cartography/config.py, extend Config.__init__ with the new fields. Then in your module entry point, validate them and short-circuit with logger.info("... not configured - skipping module") when missing.

Step 3 — Register the module in cartography/sync.py

Add one entry to TOP_LEVEL_MODULES using the lazy wrapper. Do not add a top-level import cartography.intel.your_service to sync.py — that defeats lazy SDK loading and reintroduces the slow-startup problem.

python
TOP_LEVEL_MODULES = OrderedDict({
    ...
    "your_service": _LazyStage("cartography.intel.your_service", "start_your_service_ingestion"),
    ...
    # `analysis` must remain last
    "analysis": _LazyStage("cartography.intel.analysis", "run"),
})

Pick a sensible position relative to neighbors (cloud providers grouped together, etc.). The provider's heavy SDK imports stay where they are — they only fire when this stage is selected and run.

Step 4 — Implement the sync pattern

For each domain (users, devices, projects, ...):

python
@timeit
def sync(
    neo4j_session: neo4j.Session,
    api_key: str,
    tenant_id: str,
    update_tag: int,
    common_job_parameters: dict[str, Any],
) -> None:
    raw = get(api_key, tenant_id)               # 1. GET — dumb, raises on failure
    data = transform(raw)                       # 2. TRANSFORM — shape for ingest
    load_users(neo4j_session, data, tenant_id, update_tag)  # 3. LOAD — data model
    cleanup(neo4j_session, common_job_parameters)           # 4. CLEANUP — GraphJob

get() should be minimal: set timeouts, call response.raise_for_status(), and let errors propagate. AWS get-functions wrap with @aws_handle_regions. See references/sync-pattern.md for the long-form template, error-handling rules, and transform examples.

Step 5 — Define the data model

Create dataclasses in cartography/models/your_service/. Required for every node:

python
@dataclass(frozen=True)
class YourServiceUserNodeProperties(CartographyNodeProperties):
    id: PropertyRef = PropertyRef("id")                                    # REQUIRED
    lastupdated: PropertyRef = PropertyRef("lastupdated", set_in_kwargs=True)  # REQUIRED
    # business properties...
    tenant_id: PropertyRef = PropertyRef("TENANT_ID", set_in_kwargs=True)

The schema picks a label, properties, and the mandatory sub_resource_relationship to your tenant-like node:

python
@dataclass(frozen=True)
class YourServiceUserSchema(CartographyNodeSchema):
    label: str = "YourServiceUser"
    properties: YourServiceUserNodeProperties = YourServiceUserNodeProperties()
    sub_resource_relationship: YourServiceTenantToUserRel = YourServiceTenantToUserRel()
    other_relationships: OtherRelationships = OtherRelationships([
        YourServiceUserToHumanRel(),
    ])

For advanced node configurations (extra labels, conditional labels, scoped cleanup, one-to-many) see the add-node-type skill. For relationships, MatchLinks, and multi-module patterns see the add-relationship skill. See references/data-model.md for the full reference.

Step 6 — Load + cleanup
python
def load_users(neo4j_session, data, tenant_id, update_tag):
    load(neo4j_session, YourServiceTenantSchema(), [{"id": tenant_id}], lastupdated=update_tag)
    load(neo4j_session, YourServiceUserSchema(), data, lastupdated=update_tag, TENANT_ID=tenant_id)

def cleanup(neo4j_session, common_job_parameters):
    GraphJob.from_node_schema(YourServiceUserSchema(), common_job_parameters).run(neo4j_session)

If you hand-write a Cypher write query during prototyping, use run_write_query() (managed transaction + retries), never neo4j_session.run().

Step 7 — Integration test

In tests/integration/cartography/intel/your_service/test_users.py, patch only get() and call sync() end-to-end. Assert outcomes (nodes + relationships) using tests.integration.util.check_nodes / check_rels. Do not assert on mock call counts or internal parameters. See references/testing.md for a full template and the test boundary policy.

Show full SKILL.md (314 more words)Show less
Step 8 — Module documentation

Create docs/root/modules/your_service/index.md and docs/root/modules/your_service/config.md, then add config and schema to the module's toctree. Follow references/config-docs.md exactly for the canonical config.md structure and content-placement rules.

Do not create or hand-edit schema.md. Sphinx generates it from the declarative data model. Write human-readable schema documentation in the model itself:

  • Add a docstring to every node and relationship schema.
  • Add description= to every displayed PropertyRef.
  • Use the enrich-ontology skill when adding semantic labels or canonical ontology projections.
Step 9 — Optional: analysis jobs

If the module needs post-ingestion enrichment (internet exposure, permission inheritance, cross-resource linking), call run_typed_analysis_job() / run_scoped_typed_analysis_job() at the end of the entry point. See the analysis-jobs skill.

Step 10 — Pre-submission checks
bash
make lint
# integration test for the module:
pytest tests/integration/cartography/intel/your_service/ -x

Sign every commit: git commit -s -m "...". Update the PR description to match .github/pull_request_template.md.

Final checklist

  • Entry point validates config and skips cleanly when unconfigured
  • CLI panel + Config fields wired, secrets resolved from env vars
  • Module registered in cartography/sync.py:TOP_LEVEL_MODULES via _LazyStage, with no top-level import cartography.intel.<service> added to sync.py
  • Sync follows GET -> TRANSFORM -> LOAD -> CLEANUP
  • All schemas use only standard fields (label, properties, sub_resource_relationship, other_relationships, extra_node_labels, scoped_cleanup)
  • Sub-resource relationship targets a tenant-like node
  • Required fields use data["x"], optional use data.get("x") with None default
  • extra_index=True set on frequently queried fields
  • Integration test exercises sync(), asserts nodes + rels with check_nodes / check_rels
  • index.md and canonical config.md added with a config / schema toctree
  • Schema classes have docstrings and displayed PropertyRef values have descriptions
  • No hand-written schema.md was added
  • make lint clean, git commit -s used

Common issues

See the troubleshooting skill for ModuleNotFoundError, PropertyRef validation failed, missing relationships, cleanup misbehavior, and date-handling pitfalls.

References (load on demand)

  • references/sync-pattern.md — full templates for __init__.py, sync(), get(), transform(), error-handling rules.
  • references/data-model.md — node properties, schema, sub-resource relationships, loading, ECS example.
  • references/testing.md — integration test template, check_nodes / check_rels, mocking policy, integration test boundary.
  • references/coding-conventions.md — error handling, type hints, logging levels and format, deprecation conventions.
  • references/config-docs.md — canonical module config.md template and content-placement rules.

© cartography-cncf, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in .agents/skills/create-module of cartography-cncf/cartography.

  • SKILL.md
  • references/coding-conventions.md
  • references/config-docs.md
  • references/data-model.md
  • references/sync-pattern.md
  • references/testing.md

Open the folder on GitHubat commit e4eda50

Compare with similar skills

Create Module next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Create Module compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Create Module this skillcartography-cncf/cartography4.1k—~2.5kAutomated safety check: PassApache-2.0
Plugin Testingpolyipseity/obsidian-terminal948—~828Automated safety check: PassAGPL-3.0
Td Integration Testmarcus/td250—~1.2kAutomated safety check: PassMIT
Integration E2E Testingshinpr/claude-code-workflows690—~3.5kAutomated safety check: PassMIT
JS-in-HTML Testingliaohch3/claude-tap3.3k—~924Automated safety check: PassMIT
Crosvm Testinggoogle/crosvm1.3k—~847Automated safety check: PassBSD-3-Clause

Similar skills

  • Plugin Testing

    polyipseity/obsidian-terminal

    Skill for testing Obsidian plugin features in this repository.

    948 GitHub stars~828 tokensUpdated 4 days ago
    Testing & QAAuto-check passed
  • Write integration tests for the td-sync admin API using the TestHarness in internal/api/testharnesstest.go.

    250 GitHub stars~1.2k tokensUpdated 7 days ago
    Testing & QAAuto-check passed
  • Integration E2E Testing

    shinpr/claude-code-workflows

    Integration and E2E test design principles, ROI calculation, test skeleton specification, and review criteria.

    690 GitHub stars~3.5k tokensUpdated 6 days ago
    Testing & QAAuto-check passed
  • JS-in-HTML Testing

    liaohch3/claude-tap

    Tests JavaScript embedded in an HTML file in two layers: pytest checks of the logic ported to Python, and Playwright runs in a real browser for the DOM.

    3.3k GitHub stars~924 tokensUpdated 15 days ago
    Testing & QAAuto-check passed
  • Crosvm Testing

    google/crosvm

    Official

    Skill to assist with running tests and managing test VMs in the crosvm repository.

    1.3k GitHub stars~847 tokensUpdated today
    Testing & QAAuto-check passed
  • Add Acceptance Test

    talkincode/toughradius

    Write CI-executable acceptance/integration tests for protocol or end-to-end changes (TR-F022).

    691 GitHub stars~827 tokensUpdated 4 days ago
    Testing & QAAuto-check passed

More from cartography-cncf/cartography

All 11 skills in this repo
  • Add Node Type

    cartography-cncf/cartography

    Define a new node schema under cartography/models/MODULENAME/, including required properties, sub-resource relationships, extra labels, conditional labels, scoped cleanup, and one-to-many transforms.

    4.1k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Add Relationship

    cartography-cncf/cartography

    Define a CartographyRelSchema (standard relationship), one-to-many edge, or MatchLink connecting existing nodes.

    4.1k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Analysis Jobs

    cartography-cncf/cartography

    Add a post-ingestion typed analysis job to a Cartography module to enrich the graph after sync.

    4.1k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Create Rule

    cartography-cncf/cartography

    Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.

    4.1k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Enrich Ontology

    cartography-cncf/cartography

    Map a Cartography node into the Ontology system using semantic labels (UserAccount, DeviceInstance, Tenant, Database, ObjectStorage, FileStorage) or canonical nodes (User, Device).

    4.1k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Promote Ontology Relationship

    cartography-cncf/cartography

    Promote provider-specific relationships to a canonical cross-provider ontology edge using the WORKLOADPARENT pattern (a parallel CartographyRelSchema with the canonical rellabel, the old edge kept…

    4.1k GitHub stars~3.6k tokensUpdated today
    Auto-check passed

Categories

Questions about Create Module

What does Create Module do?

Author a new Cartography intel module end-to-end (entry point, sync GET/TRANSFORM/LOAD/CLEANUP, declarative data model, integration test, schema docs). Create Module is an agent skill from cartography-cncf/cartography. Author a new Cartography intel module end-to-end (entry point, sync GET/TRANSFORM/LOAD/CLEANUP, declarative data model, integration test, schema docs).

When should I use Create Module?

Create Module fits situations like: the user asks to add a new provider; service ingestion to Cartography (e.g.

How do I install Create Module in Claude Code?

Run `npx skills add cartography-cncf/cartography --skill create-module -a claude-code`. Or copy the skill folder (.agents/skills/create-module in cartography-cncf/cartography) into .claude/skills/create-module in your project. Claude Code loads it when a task matches its description.

How do I install Create Module in Codex?

Run `npx skills add cartography-cncf/cartography --skill create-module -a codex`. Or copy the skill folder (.agents/skills/create-module in cartography-cncf/cartography) into .agents/skills/create-module in your project. Codex loads it when a task matches its description.

Can I use Create Module in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cartography-cncf/cartography --skill create-module -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/create-module, .gemini/skills/create-module, .github/skills/create-module and .opencode/skills/create-module in your project.

What does Create Module need to run?

Going by SKILL.md and its folder, Create Module needs the command-line tools its instructions call (git, make and pytest). Our summary lists: Python 3.

Does Create Module access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Create Module safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Create Module use?

Create Module is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Create Module use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.8k tokens, read only when the agent opens those files.

What are the alternatives to Create Module?

Skills that share tags, products or a category with Create Module: Plugin Testing (polyipseity/obsidian-terminal, 948 stars), Td Integration Test (marcus/td, 250 stars), Integration E2E Testing (shinpr/claude-code-workflows, 690 stars) and JS-in-HTML Testing (liaohch3/claude-tap, 3.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Create Module?

cartography-cncf (a GitHub organization) maintains it in cartography-cncf/cartography, which has 4,120 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 7, 2026.

Source: cartography-cncf/cartography on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.