Fla Ascend Performance
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.
$ npx skills add cartography-cncf/cartography --skill create-rule -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cartography-cncf/cartography create-rule --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/create-rule .claude/skills/create-rule && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "create-rule" agent skill from https://github.com/cartography-cncf/cartography/tree/master/.agents/skills/create-rule into .claude/skills/create-rule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-rule", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cartography-cncf/cartography/tree/master/.agents/skills/create-ruleType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cartography-cncf/cartography --skill create-rule -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cartography-cncf/cartography create-rule --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/create-rule .agents/skills/create-rule && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "create-rule" agent skill from https://github.com/cartography-cncf/cartography/tree/master/.agents/skills/create-rule into .agents/skills/create-rule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-rule", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cartography-cncf/cartography --skill create-rule -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cartography-cncf/cartography create-rule --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/create-rule .cursor/skills/create-rule && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "create-rule" agent skill from https://github.com/cartography-cncf/cartography/tree/master/.agents/skills/create-rule into .cursor/skills/create-rule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-rule", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cartography-cncf/cartography.git --path .agents/skills/create-rule--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cartography-cncf/cartography --skill create-rule -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cartography-cncf/cartography create-rule --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/create-rule .gemini/skills/create-rule && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "create-rule" agent skill from https://github.com/cartography-cncf/cartography/tree/master/.agents/skills/create-rule into .gemini/skills/create-rule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-rule", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cartography-cncf/cartography create-ruleInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cartography-cncf/cartography --skill create-rule -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/create-rule .github/skills/create-rule && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "create-rule" agent skill from https://github.com/cartography-cncf/cartography/tree/master/.agents/skills/create-rule into .github/skills/create-rule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-rule", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cartography-cncf/cartography --skill create-rule -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cartography-cncf/cartography create-rule --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/create-rule .opencode/skills/create-rule && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "create-rule" agent skill from https://github.com/cartography-cncf/cartography/tree/master/.agents/skills/create-rule into .opencode/skills/create-rule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-rule", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
create-ruleAuthor a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.
Create Rule is an agent skill from cartography-cncf/cartography. Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/. Use when the user asks to add a security check, detection, attack-surface query, compliance control, CIS benchmark rule, or cross-cloud detection.
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/cis-conventions.md`, `references/compliance-frameworks.md` and `references/ontology-in-rules.md`).
It sits in Security, covering Threat modeling. It works with Pydantic. The repository describes itself as: Cartography is a Python tool that pulls infrastructure assets and their relationships into a Neo4j graph database. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e345364. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python and bash).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Create Rule loads about 3k tokens when it runs, and up to ~6.4k if it reads all its reference files. Until then it costs about 74 tokens; SKILL.md has 825 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cartography-cncf/cartography at commit e345364, republished under its Apache-2.0 licence (© cartography-cncf). 825 words, ~3,044 tokens.
.claude/skills/create-rule/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Cartography rules detect attack surfaces, security gaps, and compliance issues across the graph. Rules are composed of one or more Facts (Cypher queries) and a Finding output model (Pydantic).
Rule (e.g., "database-exposed")
├─ Fact (e.g., "aws-rds-public")
├─ Fact (e.g., "azure-sql-public")
└─ Fact (e.g., "gcp-cloudsql-public")cypher_query aliases must match Finding field names exactly. Use RETURN x.id AS id, x.name AS name.cypher_visual_query returns nodes, not properties — used for graph viz.Finding fields are | None with default None. The source field is auto-populated.source and extra are reserved. Never alias them in a cypher_query; use ontology_source for _ont_source.cypher_query must match the declared asset_label. MATCH (k:APIKey) WHERE k:OpenAIApiKey ..., not MATCH (k) WHERE k:OpenAIApiKey ..., so the rows returned cannot diverge from the asset claimed.frameworks=, not tags. Keep tags for categories only (iam, credentials, stride:*).frameworks=.from cartography.rules.spec.model import (
Fact,
Finding,
Framework,
Maturity,
Module,
Rule,
RuleReference,
)A Fact is a Cypher query that detects one specific condition:
_aws_public_databases = Fact(
id="aws-rds-public",
name="Publicly accessible AWS RDS instances",
description="AWS RDS databases exposed to the internet",
cypher_query="""
MATCH (db:AWSRDSInstance)
WHERE db.publicly_accessible = true
RETURN db.id AS id, db.db_instance_identifier AS name, db.region AS region
""",
cypher_visual_query="""
MATCH (db:AWSRDSInstance)
WHERE db.publicly_accessible = true
RETURN db
""",
cypher_count_query="""
MATCH (db:AWSRDSInstance)
RETURN COUNT(db) AS count
""",
identity_fields=("id",),
module=Module.AWS,
maturity=Maturity.STABLE,
)Fact fields:
| Field | Required | Notes |
|---|---|---|
id | Yes | lowercase + hyphens |
name | Yes | human-readable |
description | Yes | what this fact detects |
cypher_query | Yes | structured rows; AS aliases match Finding fields |
cypher_visual_query | Yes | returns nodes for visualization |
cypher_count_query | Yes | total assets evaluated; RETURN COUNT(...) AS count |
module | Yes | Module.AWS, Module.AZURE, Module.GCP, ... |
maturity | Yes | Maturity.EXPERIMENTAL or Maturity.STABLE |
asset_id_field | No | finding field that uniquely identifies an asset (dedupe) |
identity_fields | Yes | tuple of output-model fields forming the finding's stable logical identity across syncs (for downstream lifecycle tracking); required with no default, distinct from asset_id_field |
class DatabaseExposedOutput(Finding):
"""Output model for publicly exposed databases."""
name: str | None = None # human-readable label first: used as the finding title
id: str | None = None
region: str | None = NoneFinding.cypher_query aliases exactly.| None with default None.source field is auto-populated with the module name and is reserved: do not return a source column. Alias the per-row ontology provider ontology_source and declare it on the model.cypher_query (e.g. coalesce(n.friendly_name, n.short_id) AS name, or an AWS Name tag) and declare it first. This is independent of identity_fields/asset_id_field and of RETURN order. See "Display field order (finding title)" in docs/root/usage/rules.md.identity_fields on the Fact (required) to the subset of these fields that forms the finding's stable logical identity, excluding volatile context (*_count, days_*, last_used*, *_date, posture booleans, aggregate lists) so downstream lifecycle tracking does not treat a changed metric as a new finding. See "Finding identity vs. display fields" in docs/root/usage/rules.md.database_exposed = Rule(
id="database-exposed",
name="Publicly Accessible Databases",
description="Detects databases exposed to the internet across cloud providers",
output_model=DatabaseExposedOutput,
tags=("infrastructure", "attack_surface", "database"),
facts=(_aws_public_databases, _azure_public_databases, _gcp_cloudsql_public),
version="1.0.0",
)Rule fields:
| Field | Required | Notes |
|---|---|---|
id | Yes | lowercase + underscores |
name | Yes | human-readable |
description | Yes | what security issue this detects |
output_model | Yes | Pydantic model class |
tags | Yes | tuple of categorisation tags (no compliance) |
facts | Yes | tuple of Fact objects |
version | Yes | semantic version string |
references | No | list of RuleReference for documentation |
frameworks | No | tuple of Framework (compliance metadata) |
Maturity.EXPERIMENTAL — new, may have bugs / perf issues. Use for testing detection capabilities.Maturity.STABLE — production-ready, well-tested, optimized.Versioning follows semver (0.1.0 initial, 0.2.0 add facts, 0.2.1 bug fix, 1.0.0 production-ready).
Tag categories:
infrastructure, identity, data, network, compute.attack_surface, misconfiguration, compliance, vulnerability.aws, azure, gcp, github, okta.stride:spoofing, stride:tampering, stride:repudiation, stride:information_disclosure, stride:denial_of_service, stride:elevation_of_privilege.In cartography/rules/data/rules/__init__.py:
from cartography.rules.data.rules.my_security_rule import my_security_rule
RULES = {
# ... existing rules
my_security_rule.id: my_security_rule,
}cartography-rules list my_security_rule
cartography-rules run my_security_rule
cartography-rules run my_security_rule --output json
cartography-rules run my_security_rule --no-experimentalFor CIS, NIST, SOC2, etc., attach a Framework object or framework helper instead of polluting tags:
from cartography.rules.data.frameworks.cis import cis_aws
my_rule = Rule(
id="aws_access_keys_not_rotated",
name="Access Keys Not Rotated",
# ...
tags=("iam", "credentials", "stride:spoofing"), # category tags only
frameworks=(
cis_aws("1.14"),
),
)Compliance-style tags like cis:1.14, cis:aws-5.0 must NOT live in tags. CLI users filter via --framework CIS, --framework CIS:aws, --framework CIS:aws:5.0.
For framework helpers with known canonical controls, the helper fills Framework.control_title. For custom mappings, set Framework(control_title="...") to the external framework control or requirement title. Keep Rule.name as reusable Cartography security copy. Many Cartography rules may map to the same framework control.
Framework helpers encode the one active revision Cartography supports for each benchmark scope today. If Cartography needs to report against multiple benchmark revisions later, add version-aware helpers or explicit framework objects instead of mixing revisions in one helper.
For deeper framework guidance, including CIS benchmark conventions (rule names, IDs, file naming, headers, references), see references/compliance-frameworks.md and references/cis-conventions.md.
Group facts from different cloud providers under one rule. Each fact's cypher_query should include the provider in the result so the Finding has it:
_aws_unencrypted_storage = Fact(
id="aws-s3-unencrypted",
cypher_query="""
MATCH (b:AWSS3Bucket) WHERE b.default_encryption IS NULL
RETURN b.id AS id, b.name AS name, 'aws' AS provider
""",
# ...
module=Module.AWS,
maturity=Maturity.STABLE,
)
_azure_unencrypted_storage = Fact(
id="azure-storage-unencrypted",
cypher_query="""
MATCH (s:AzureStorageAccount) WHERE s.encryption_enabled = false
RETURN s.id AS id, s.name AS name, 'azure' AS provider
""",
module=Module.AZURE,
maturity=Maturity.STABLE,
)
class UnencryptedStorageOutput(Finding):
id: str | None = None
name: str | None = None
provider: str | None = None
unencrypted_storage = Rule(
id="unencrypted_storage",
name="Unencrypted Cloud Storage",
description="Detects unencrypted storage across cloud providers",
output_model=UnencryptedStorageOutput,
tags=("data", "encryption", "compliance"),
facts=(_aws_unencrypted_storage, _azure_unencrypted_storage),
version="1.0.0",
)Leverage semantic labels (e.g. UserAccount) and _ont_* properties for cross-module detection:
_unmanaged_accounts = Fact(
id="unmanaged-accounts-ontology",
name="User Accounts Not Linked to Identity",
description="Detects user accounts without a corresponding User identity",
cypher_query="""
MATCH (ua:UserAccount)
WHERE NOT (ua)<-[:HAS_ACCOUNT]-(:User)
RETURN ua.id AS id, ua._ont_email AS email, ua._ont_source AS ontology_source
""",
cypher_visual_query="""
MATCH (ua:UserAccount)
WHERE NOT (ua)<-[:HAS_ACCOUNT]-(:User)
RETURN ua
""",
cypher_count_query="""
MATCH (ua:UserAccount)
RETURN COUNT(ua) AS count
""",
asset_label="UserAccount",
asset_id_field="id",
identity_fields=("ontology_source", "id"),
module=Module.CROSS_CLOUD,
maturity=Maturity.STABLE,
)For semantic-label setup, see the enrich-ontology skill.
references/compliance-frameworks.md — Framework field reference, CLI filtering, Rule.has_framework() checks.references/ontology-in-rules.md — using UserAccount / Tenant / Database labels and _ont_* props in rule queries.references/cis-conventions.md — CIS rule naming, IDs, file layout, headers, references, complete CIS example.© cartography-cncf, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in .agents/skills/create-rule of cartography-cncf/cartography.
Open the folder on GitHubat commit e345364
Create Rule next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Create Rule this skillcartography-cncf/cartography | 4.1k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Fla Ascend Performancefla-org/flash-linear-attention | 5.8k | — | ~6.3k | Automated safety check: Pass | MIT | |
| Forensifyalexgreensh/repo-forensics | 188 | — | ~2.5k | Automated safety check: Notes | Custom licence | |
| Commit Security Scancodexstar69/bug-hunter | 519 | — | ~629 | Automated safety check: Pass | MIT | |
| Auditing Code For Vulnerabilitiestrilwu/secskills | 157 | — | ~3.2k | Automated safety check: Pass | MIT | |
| Threat Mitigation Mappingwshobson/agents | 40k | 8 repos | ~742 | Automated safety check: Pass | MIT |
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
codexstar69/bug-hunter
Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
wshobson/agents
Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.
nordstjernen-web/northstar-browser
Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.
cartography-cncf/cartography
Define a new node schema under cartography/models/MODULENAME/, including required properties, sub-resource relationships, extra labels, conditional labels, scoped cleanup, and one-to-many transforms.
cartography-cncf/cartography
Define a CartographyRelSchema (standard relationship), one-to-many edge, or MatchLink connecting existing nodes.
cartography-cncf/cartography
Add a post-ingestion typed analysis job to a Cartography module to enrich the graph after sync.
cartography-cncf/cartography
Author a new Cartography intel module end-to-end (entry point, sync GET/TRANSFORM/LOAD/CLEANUP, declarative data model, integration test, schema docs).
cartography-cncf/cartography
Map a Cartography node into the Ontology system using semantic labels (UserAccount, DeviceInstance, Tenant, Database, ObjectStorage, FileStorage) or canonical nodes (User, Device).
cartography-cncf/cartography
Promote provider-specific relationships to a canonical cross-provider ontology edge using the WORKLOADPARENT pattern (a parallel CartographyRelSchema with the canonical rellabel, the old edge kept…
Works with
Categories
Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/. Create Rule is an agent skill from cartography-cncf/cartography. Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.
Create Rule fits situations like: the user asks to add a security check; attack-surface query; compliance control; CIS benchmark rule.
Run `npx skills add cartography-cncf/cartography --skill create-rule -a claude-code`. Or copy the skill folder (.agents/skills/create-rule in cartography-cncf/cartography) into .claude/skills/create-rule in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cartography-cncf/cartography --skill create-rule -a codex`. Or copy the skill folder (.agents/skills/create-rule in cartography-cncf/cartography) into .agents/skills/create-rule in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cartography-cncf/cartography --skill create-rule -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/create-rule, .gemini/skills/create-rule, .github/skills/create-rule and .opencode/skills/create-rule in your project.
SKILL.md names no scripts, command-line tools or credentials: Create Rule is instructions for the agent only. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Create Rule is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Create Rule: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Forensify (alexgreensh/repo-forensics, 188 stars), Commit Security Scan (codexstar69/bug-hunter, 519 stars) and Auditing Code For Vulnerabilities (trilwu/secskills, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cartography-cncf (a GitHub organization) maintains it in cartography-cncf/cartography, which has 4,128 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 9, 2026.
Source: cartography-cncf/cartography on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.