Audit and improve the cubic AI-review config (cubic.yaml) for this repo.

Apache-2.0Auto-check passed

Install Cubic Audit

skills CLI
$ npx skills add cartography-cncf/cartography --skill cubic-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cartography-cncf/cartography cubic-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/cubic-audit .claude/skills/cubic-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cubic-audit
GitHub stars
4.1k
Token cost
~2.6k tokens
SKILL.md length
1,201 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit and improve the cubic AI-review config (cubic.yaml) for this repo.

  • Works in 6 steps: Context → List learnings (cubic MCP) -- skip if… → Bucket the learnings → …
  • Asked to audit cubic
  • SKILL.md covers Hard constraints (bake these in), Workflow and Notes
  • Calls git and uv

What it does

Cubic Audit is an agent skill from cartography-cncf/cartography. Audit and improve the cubic AI-review config (cubic.yaml) for this repo. Reviews the custom review rules for relevance, scoping, limits, and factual accuracy, then reconciles them against the repo's cubic learnings, promoting the few high-value recurring ones into durable rules and flagging obsolete, duplicate, or contradictory learnings for cleanup (each verified against the live code). Use when asked to "audit cubic", "rework the cubic config", "review the cubic rules", "check cubic learnings", or on a…

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Model Context Protocol. The repository describes itself as: Cartography is a Python tool that pulls infrastructure assets and their relationships into a Neo4j graph database. The licence is Apache-2.0.

When your agent uses it

  • Asked to audit cubic
  • Rework the cubic config
  • Review the cubic rules
  • Check cubic learnings

Example prompts

  • “audit cubic”
  • “rework the cubic config”
  • “review the cubic rules”
  • “/cubic-audit”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Context
  2. List learnings (cubic MCP) -- skip if unavailable
  3. Bucket the learnings
  4. Audit the rules themselves
  5. Validate cubic.yaml
  6. Report, then apply

What it can do on your machine

Read from SKILL.md and the folder at commit e345364. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.cubic.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cubic Audit loads about 2.6k tokens when it runs. Until then it costs about 144 tokens; SKILL.md has 1,201 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~144
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cartography-cncf/cartography at commit e345364, republished under its Apache-2.0 licence (© cartography-cncf). 1,201 words, ~2,595 tokens.

Download SKILL.mdSave it as .claude/skills/cubic-audit/SKILL.md (or your agent's skills folder).
name
cubic-audit
description
Audit and improve the cubic AI-review config (`cubic.yaml`) for this repo. Reviews the custom review rules for relevance, scoping, limits, and factual accuracy, then reconciles them against the repo's cubic learnings, promoting the few high-value recurring ones into durable rules and flagging obsolete, duplicate, or contradictory learnings for cleanup (each verified against the live code). Use when asked to "audit cubic", "rework the cubic config", "review the cubic rules", "check cubic learnings", or on a recurring cadence to keep the review config sharp.

cubic-audit

Periodic audit of the cubic AI-review configuration (cubic.yaml at the repo root). Two deliverables, in order:

  1. Rule review: are the custom review rules the highest-signal set for this repo, correctly scoped, within cubic's limits, and factually accurate against the code?
  2. Learnings reconciliation: which accumulated cubic learnings should be promoted into durable rules, and which are obsolete / duplicate / contradictory and should be cleaned up in the cubic UI.

Two modes. Deliverable 2 needs the cubic learnings MCP (tools list_learnings / get_learning). That server is connected per-account in the cubic app, not declared in the repo's .mcp.json, so a teammate running this skill may not have it. Probe for it in step 1: if it is reachable, run the full audit (both deliverables). If not, run rules-only mode (deliverable 1 plus the cubic.yaml validation in step 4), and tell the user the learnings reconciliation was skipped because the cubic MCP is not connected, with a one-line pointer on how to enable it (connect the cubic integration in the cubic app, then re-run). Never block the whole skill on the missing MCP.

Cubic docs (re-check if a limit below seems wrong): https://docs.cubic.dev/configure/cubic-yaml and https://docs.cubic.dev/ai-review/custom-agents

Language: all output (chat, cubic.yaml text, commit messages) is US English, regardless of the language used to invoke the skill.

Open source: cartography is a public CNCF project. Never reference clients, internal tickets, or private deployments in cubic.yaml, commits, or learnings recommendations.

Hard constraints (bake these in)

  • Max 5 enabled custom rules per repo. Order matters; beyond the limit only the first N take effect. To add one you must merge or drop one. cubic.yaml is already at the cap (5 custom_rules), so every "promote" recommendation must name what it merges into or replaces.
  • 10,000 characters per rule, and that budget includes the resolved content of any file_paths. Attaching a large doc (AGENTS.md, a schema.md) is counterproductive: it truncates to the least-relevant top and starves the prompt. Prefer self-contained prompts; only link a file if it is small (<2k) and review-focused.
  • cubic.yaml merges across levels: repo > org > UI > built-in defaults.
  • No MCP tool deletes or edits a learning. Learnings cleanup is a manual action in the cubic UI. This skill produces the list; a human actions it.
  • No em-dashes / en-dashes anywhere in cubic.yaml or commits. Run grep -n '—\|–' cubic.yaml before declaring done.
  • Honor the repo's worktree/path and git rules in AGENTS.md (CLAUDE.md may be a symlink to it; read AGENTS.md directly). Commit/push only when explicitly asked; commits use --signoff (DCO is required on this repo); never open a PR without per-PR authorization.

Workflow

0. Context
  • Confirm the repo root (or worktree). Read cubic.yaml.
  • Derive the GitHub slug: git remote get-url origin -> owner/repo (this repo: cartography-cncf/cartography).
1. List learnings (cubic MCP) -- skip if unavailable

The cubic MCP server is namespaced by an opaque id and is connected per-account in the cubic app, not in the repo's .mcp.json. Probe first: run ToolSearch for list_learnings get_learning cubic. If it returns no matching tool, the cubic MCP is not connected in this environment: skip the rest of this step and all of steps 2 and 5's cleanup table, run rules-only mode (steps 3-4), and state in the report that learnings reconciliation was skipped (connect the cubic integration in the cubic app and re-run to enable it). Do not fabricate learnings from memory.

If the tool is found, call list_learnings(owner, repo).

The result is large and is persisted to a file (the tool message returns its path). Do not read it raw. Extract a compact view and read 100% of it:

bash
# f = the persisted list_learnings result file path from the tool message
awk '
/^## / { cat=$0; sub(/^## /,"",cat); next }
/^### / { title=$0; sub(/^### /,"",title); desc=""; getline; while($0=="") getline; while($0!="" && $0 !~ /^- \*\*/){ desc=desc $0 " "; getline } next }
/^- \*\*Confidence\*\*/ { c=$0; sub(/.*: /,"",c) }
/^- \*\*Source\*\*/     { s=$0; sub(/.*: /,"",s) }
/^- \*\*Updated\*\*/    { u=$0; sub(/.*: /,"",u); printf "[%s] %s | %s | %s | %s\n    %s\n", cat, title, c, s, u, desc }
' "$f" > /tmp/cubic_learnings_compact.txt
wc -l /tmp/cubic_learnings_compact.txt

Read the compact file fully (chunk it). Never pipe the awk through head: it silently drops the tail and you will miss whole categories.

2. Bucket the learnings

Most learnings are negative / suppression ("Do not flag X", "Treat Y as intentional", "Before flagging Z, check W"). These are false-positive corrections that already apply automatically. Do NOT turn suppression learnings into rules: a rule says "flag", a suppression says "do not".

  • Promote candidates: positive / prescriptive ("always do X"), general, recurring (appears 2+ times or echoes a known convention), and not already covered by an existing rule. Expect only 1-3 per audit. Since the config is at the 5-rule cap, each promotion must fold into an existing rule's description rather than add a sixth.
  • Cleanup candidates:
    • Contradictory: conflicts with a rule or with repo reality. Highest priority, since these suppress real findings.
    • Obsolete: references a removed/renamed module, deleted helper, or a label/pattern that no longer exists in the code.
    • Duplicate: near-identical pairs (often the same rule reworded, or one with a hyphen vs an arrow).
    • Low-value: vague entries under ~75% confidence that are platitudes. Optional prune.

Verify before recommending deletion. Never trust the learning text alone: grep the code for the referenced symbol / dir / feature. Patterns that pay off:

bash
git grep -n 'def from_node_schema'             # the signature a rule quotes is correct?
git grep -lI 'aws_handle_regions' -- '*.py'    # decorator still referenced?
ls cartography/intel/<module> 2>/dev/null      # module still exists / not renamed?
Show full SKILL.md (405 more words)Show less
3. Audit the rules themselves
  • Are the (<=5) rules the highest-signal for this graph-centric (Neo4j/Cypher) intel tool? Rules tied to the declarative data model (node/rel schemas, MatchLinks, scoped cleanup) and the get -> transform -> load -> cleanup sync contract earn their slots; pure-hygiene rules are the first to cut when you need room.
  • Redundant with tooling? Drop checks already enforced by the pre-commit stack (black, isort, flake8, pyupgrade, mypy). Example: pyupgrade --py36-plus already rewrites legacy typing.Dict/List/Optional to PEP 585 builtins, so a rule should not also police that. Inspect .pre-commit-config.yaml and the [flake8] block in setup.cfg before keeping a hygiene rule.
  • Scoping: every rule should carry include/exclude globs so it only runs where relevant (cuts false positives, saves the 10k budget). Test-only guidance -> tests/**; schema-doc guidance -> docs/root/modules/**; AWS-decorator guidance -> cartography/intel/aws/**. The existing PII rule already excludes tests/** as a model.
  • Factual accuracy: every helper name / signature / path quoted in a prompt must match the code. Verify with grep (a wrong signature in a prompt produces wrong reviews). Spot-check the claims already baked into cubic.yaml (e.g. GraphJob.from_node_schema(), GraphJob.from_matchlink(), @timeit, @aws_handle_regions, the RESOURCE/INWARD sub-resource contract).
  • ignore.files (use sparingly): reviews.ignore.files skips matching files entirely, so it removes all review coverage, not just noise. Reserve it for purely machine-generated artifacts with no hand-authored content. Do not ignore files that another mechanism already governs or that carry meaningful diffs: in this repo uv.lock must stay reviewable because a custom rule flags unwarranted lockfile-only churn (ignoring it disables that signal), and tests/data/** are hand-maintained fixtures that AGENTS.md lists as part of the intel-module surface. Prefer a scoped custom rule over hiding a file. The current cubic.yaml intentionally has no ignore block.
4. Validate cubic.yaml
bash
uv run --with pyyaml --no-project python -c "
import yaml
d=yaml.safe_load(open('cubic.yaml')); r=d['reviews']
print('YAML OK | rules:', len(r['custom_rules']), '(max 5)')
for c in r['custom_rules']:
    n=len(c['description']); print(f\"  {n:>5} chars  {c['name']}{'  <-- OVER 10k!' if n>10000 else ''}\")
"
grep -n '—\|–' cubic.yaml && echo 'FIX em/en-dashes' || echo 'no em/en-dashes'
5. Report, then apply

Present three recap tables and stop for approval before editing:

  • Promote: learning -> target rule (which existing rule it folds into) -> why.
  • Cleanup (grouped: contradictory / obsolete / duplicate / low-value): learning -> type -> code-verified justification.
  • Refactor: rule changes (merge / split / rescope) within the 5 cap.

After approval:

  • Apply the cubic.yaml edits, then re-run the step-4 validation.
  • Hand the learnings cleanup list to the user as manual cubic-UI actions (no MCP delete exists).
  • Commit/push only if asked; PR only with per-PR authorization. Commit message in US English, with --signoff, plus the repo's standard Co-Authored-By trailer.

Notes

  • Read-mostly on cubic: this skill lists learnings, never mutates them, and edits only cubic.yaml.
  • Keep rule prompts self-contained and concrete (good/bad examples + the "why"); that beats terse rules and avoids the file_paths truncation trap.

© cartography-cncf, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/cubic-audit of cartography-cncf/cartography.

Open the folder on GitHubat commit e345364

Compare with similar skills

Cubic Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cubic Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cubic Audit this skillcartography-cncf/cartography4.1k—~2.6kAutomated safety check: PassApache-2.0
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
Figma use_figma Plugin API Ruleswarpdotdev/warp65k4 repos~4.4kAutomated safety check: PassAGPL-3.0
Stitch to Remotion Walkthrough Videosgoogle-labs-code/stitch-skills8.4k6 repos~3.2kAutomated safety check: NotesApache-2.0

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.

    65k GitHub starsUsed in 4 repos~4.4k tokens
    Frontend & DesignAuto-check passed
  • Stitch to Remotion Walkthrough Videos

    google-labs-code/stitch-skills

    Official

    Builds walkthrough videos from Stitch design projects using Remotion, with transitions, zoom effects and text overlays on each screen.

    8.4k GitHub starsUsed in 6 repos~3.2k tokens
    Media & CreativeAuto-check: notes
  • MCP Development

    coollabsio/coolify

    A skill your agent uses for Laravel MCP development. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 1 repo~949 tokens
    Frontend & DesignAuto-check passed

More from cartography-cncf/cartography

All 11 skills in this repo
  • Add Node Type

    cartography-cncf/cartography

    Define a new node schema under cartography/models/MODULENAME/, including required properties, sub-resource relationships, extra labels, conditional labels, scoped cleanup, and one-to-many transforms.

    4.1k GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Add Relationship

    cartography-cncf/cartography

    Define a CartographyRelSchema (standard relationship), one-to-many edge, or MatchLink connecting existing nodes.

    4.1k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Analysis Jobs

    cartography-cncf/cartography

    Add a post-ingestion typed analysis job to a Cartography module to enrich the graph after sync.

    4.1k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Create Module

    cartography-cncf/cartography

    Author a new Cartography intel module end-to-end (entry point, sync GET/TRANSFORM/LOAD/CLEANUP, declarative data model, integration test, schema docs).

    4.1k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Create Rule

    cartography-cncf/cartography

    Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.

    4.1k GitHub stars~3k tokensUpdated yesterday
    Auto-check passed
  • Enrich Ontology

    cartography-cncf/cartography

    Map a Cartography node into the Ontology system using semantic labels (UserAccount, DeviceInstance, Tenant, Database, ObjectStorage, FileStorage) or canonical nodes (User, Device).

    4.1k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed

Questions about Cubic Audit

What does Cubic Audit do?

Audit and improve the cubic AI-review config (cubic.yaml) for this repo. Cubic Audit is an agent skill from cartography-cncf/cartography.yaml) for this repo.

When should I use Cubic Audit?

Cubic Audit fits situations like: asked to audit cubic; rework the cubic config; review the cubic rules; check cubic learnings.

How do I install Cubic Audit in Claude Code?

Run `npx skills add cartography-cncf/cartography --skill cubic-audit -a claude-code`. Or copy the skill folder (.agents/skills/cubic-audit in cartography-cncf/cartography) into .claude/skills/cubic-audit in your project. Claude Code loads it when a task matches its description.

How do I install Cubic Audit in Codex?

Run `npx skills add cartography-cncf/cartography --skill cubic-audit -a codex`. Or copy the skill folder (.agents/skills/cubic-audit in cartography-cncf/cartography) into .agents/skills/cubic-audit in your project. Codex loads it when a task matches its description.

Can I use Cubic Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cartography-cncf/cartography --skill cubic-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cubic-audit, .gemini/skills/cubic-audit, .github/skills/cubic-audit and .opencode/skills/cubic-audit in your project.

What does Cubic Audit need to run?

Going by SKILL.md and its folder, Cubic Audit needs the command-line tools its instructions call (git and uv). Our summary lists: Python 3.

Does Cubic Audit access the network?

SKILL.md names 1 domain. As links in the text: docs.cubic.dev. This is read from the text; nothing was executed.

Is Cubic Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cubic Audit use?

Cubic Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cubic Audit use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cubic Audit?

Skills that share tags, products or a category with Cubic Audit: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cubic Audit?

cartography-cncf (a GitHub organization) maintains it in cartography-cncf/cartography, which has 4,128 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 9, 2026.

Source: cartography-cncf/cartography on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.