Token Map
nexu-io/open-design
Map an extracted Figma / source-code token bag onto the active OD design system, producing a deterministic mapping the generate stage can consume.
Map a Cartography node into the Ontology system using semantic labels (UserAccount, DeviceInstance, Tenant, Database, ObjectStorage, FileStorage) or canonical nodes (User, Device).
$ npx skills add cartography-cncf/cartography --skill enrich-ontology -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cartography-cncf/cartography enrich-ontology --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/enrich-ontology .claude/skills/enrich-ontology && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "enrich-ontology" agent skill from https://github.com/cartography-cncf/cartography/tree/master/.agents/skills/enrich-ontology into .claude/skills/enrich-ontology/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enrich-ontology", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cartography-cncf/cartography/tree/master/.agents/skills/enrich-ontologyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cartography-cncf/cartography --skill enrich-ontology -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cartography-cncf/cartography enrich-ontology --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/enrich-ontology .agents/skills/enrich-ontology && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "enrich-ontology" agent skill from https://github.com/cartography-cncf/cartography/tree/master/.agents/skills/enrich-ontology into .agents/skills/enrich-ontology/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enrich-ontology", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cartography-cncf/cartography --skill enrich-ontology -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cartography-cncf/cartography enrich-ontology --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/enrich-ontology .cursor/skills/enrich-ontology && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "enrich-ontology" agent skill from https://github.com/cartography-cncf/cartography/tree/master/.agents/skills/enrich-ontology into .cursor/skills/enrich-ontology/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enrich-ontology", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cartography-cncf/cartography.git --path .agents/skills/enrich-ontology--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cartography-cncf/cartography --skill enrich-ontology -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cartography-cncf/cartography enrich-ontology --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/enrich-ontology .gemini/skills/enrich-ontology && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "enrich-ontology" agent skill from https://github.com/cartography-cncf/cartography/tree/master/.agents/skills/enrich-ontology into .gemini/skills/enrich-ontology/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enrich-ontology", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cartography-cncf/cartography enrich-ontologyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cartography-cncf/cartography --skill enrich-ontology -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/enrich-ontology .github/skills/enrich-ontology && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "enrich-ontology" agent skill from https://github.com/cartography-cncf/cartography/tree/master/.agents/skills/enrich-ontology into .github/skills/enrich-ontology/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enrich-ontology", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cartography-cncf/cartography --skill enrich-ontology -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cartography-cncf/cartography enrich-ontology --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/enrich-ontology .opencode/skills/enrich-ontology && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "enrich-ontology" agent skill from https://github.com/cartography-cncf/cartography/tree/master/.agents/skills/enrich-ontology into .opencode/skills/enrich-ontology/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enrich-ontology", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
enrich-ontologyMap a Cartography node into the Ontology system using semantic labels (UserAccount, DeviceInstance, Tenant, Database, ObjectStorage, FileStorage) or canonical nodes (User, Device).
Enrich Ontology is an agent skill from cartography-cncf/cartography. Map a Cartography node into the Ontology system using semantic labels (UserAccount, DeviceInstance, Tenant, Database, ObjectStorage, FileStorage) or canonical nodes (User, Device). Use when the user asks to add ontology mapping, expose a node as a semantic label, normalise identity / device data across providers, enable cross-module queries, or wire ont properties.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/semantic-labels.md`).
The repository describes itself as: Cartography is a Python tool that pulls infrastructure assets and their relationships into a Neo4j graph database. The licence is Apache-2.0.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 0975e95. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
uvFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Enrich Ontology loads about 2.4k tokens when it runs, and up to ~3.7k if it reads all its reference files. Until then it costs about 97 tokens; SKILL.md has 574 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cartography-cncf/cartography at commit 0975e95, republished under its Apache-2.0 licence (© cartography-cncf). 574 words, ~2,404 tokens.
.claude/skills/enrich-ontology/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Cartography's Ontology system unifies data from multiple sources via two mechanisms:
UserAccount) and prefixed properties (_ont_*) directly to source nodes during ingestion.(:User:Ontology) / (:Device:Ontology) nodes that aggregate data from multiple sources.Most modules only need semantic labels.
required=True in OntologyFieldMapping (e.g. email for User, hostname for Device). Records missing these are excluded from ontology node creation.ExtraNodeLabels([USER_ACCOUNT]). Ontology constants are immutable ExtraNodeLabel values with kind=LabelKind.ONTOLOGY; the ontology system handles the _ont_* properties automatically.special_handling values are strings: invert_boolean, to_boolean, or_boolean, nor_boolean, equal_boolean, static_value, coalesce. Boolean conditions inside extra={"values": ...} must also be strings ("true", not True).schema.md: the > **Ontology Mapping** note is emitted from the node's extra_node_labels. Document the node in the model with a docstring and PropertyRef description= values.microsoft is the canonical source for Microsoft Graph. entra is still accepted as a backward-compatible alias during migration.| Need | Use |
|---|---|
Cross-module queries on existing source nodes (e.g. all UserAccount across systems) | Semantic label |
| Aggregate one entity from many sources into a single canonical record | Canonical node |
When in doubt, start with semantic label.
Add the mapping in cartography/models/ontology/mapping/data/. For users:
# cartography/models/ontology/mapping/data/useraccounts.py
from cartography.models.ontology.mapping.specs import (
OntologyFieldMapping, OntologyMapping, OntologyNodeMapping,
)
your_service_mapping = OntologyMapping(
module_name="your_service",
nodes=[
OntologyNodeMapping(
node_label="YourServiceUser",
fields=[
OntologyFieldMapping(ontology_field="email", node_field="email", required=True),
OntologyFieldMapping(ontology_field="username", node_field="username"),
OntologyFieldMapping(ontology_field="fullname", node_field="display_name"),
OntologyFieldMapping(ontology_field="firstname", node_field="first_name"),
OntologyFieldMapping(ontology_field="lastname", node_field="last_name"),
OntologyFieldMapping(
ontology_field="inactive",
node_field="account_enabled",
special_handling="invert_boolean",
),
OntologyFieldMapping(
ontology_field="has_mfa",
node_field="multifactor",
special_handling="to_boolean",
),
OntologyFieldMapping(
ontology_field="inactive",
node_field="suspended",
special_handling="or_boolean",
extra={"fields": ["archived"]},
),
],
),
],
)For devices the pattern is the same with OntologyNodeMapping(node_label="YourServiceDevice", ...).
Add it to the dictionary at the bottom of the file:
# Example: bottom of useraccounts.py
USERACCOUNTS_ONTOLOGY_MAPPING: dict[str, OntologyMapping] = {
# ... existing mappings ...
"your_service": your_service_mapping,
}The mappings are auto-imported via cartography/models/ontology/mapping/__init__.py.
For semantic labels, the node schema simply gains the extra label — Cartography injects _ont_* and _ont_source automatically at ingestion:
from cartography.models.core.nodes import ExtraNodeLabels
from cartography.models.ontology.labels import USER_ACCOUNT
@dataclass(frozen=True)
class YourServiceUserSchema(CartographyNodeSchema):
label: str = "YourServiceUser"
extra_node_labels: ExtraNodeLabels = ExtraNodeLabels([USER_ACCOUNT])
properties: YourServiceUserNodeProperties = YourServiceUserNodeProperties()
sub_resource_relationship: YourServiceTenantToUserRel = YourServiceTenantToUserRel()For canonical nodes, define a separate schema with
extra_node_labels=ExtraNodeLabels([ONTOLOGY]) and a relationship to the
semantic-labeled source nodes. See references/semantic-labels.md for the
full template.
required and eligible_for_sourcerequired=True means: source records lacking this field are excluded from ontology node creation. Always mark the primary identifier required:
OntologyFieldMapping(ontology_field="email", node_field="email", required=True)
OntologyFieldMapping(ontology_field="hostname", node_field="device_name", required=True)OntologyNodeMapping.eligible_for_source=False means: this mapping links existing ontology nodes but cannot create new ones. Use it when the source lacks the required identifier:
# AWS IAM users have no email, so they cannot create new User ontology nodes.
OntologyNodeMapping(
node_label="AWSUser",
eligible_for_source=False,
fields=[
OntologyFieldMapping(ontology_field="username", node_field="name"),
],
),For services that link users to devices, add a typed analysis statement to cartography/analysis/ontology/analysis.py:
AnalysisStatement(
match="MATCH (u:User)-[:HAS_ACCOUNT]->(:YourServiceUser)-[:OWNS]->(:YourServiceDevice)<-[:OBSERVED_AS]-(d:Device)",
effects=(
AddRelationship("u", "OWNS", "d", source_label="User", target_label="Device"),
),
)See the analysis-jobs skill for typed analysis job syntax.
For semantic labels — assert _ont_* properties land on your nodes:
def test_ontology_properties(neo4j_session):
# after running your sync
row = neo4j_session.run(
"MATCH (n:YourServiceUser) RETURN n._ont_email, n._ont_source LIMIT 1"
).single()
assert row["n._ont_email"] is not None
assert row["n._ont_source"] == "your_service"For canonical nodes — assert the ontology intel module produces them:
def test_canonical_user_created(neo4j_session):
row = neo4j_session.run(
"""
MATCH (u:User:Ontology)-[:HAS_ACCOUNT]->(ua:YourServiceUser)
RETURN count(u) AS user_count
"""
).single()
assert row["user_count"] > 0Do not create or hand-edit schema.md. Sphinx generates it from the data model, including the > **Ontology Mapping** note for any node whose extra_node_labels carry an ontology label constant. Write the documentation in the model itself: a docstring on the node schema and description= on each displayed PropertyRef. Build the docs with uv run ./docs/build.sh and check the generated page.
special_handling quick reference| Value | Description | Extra params |
|---|---|---|
invert_boolean | Inverts the boolean value (true -> false) | None |
to_boolean | Converts to boolean, treating non-null as true | None |
or_boolean | Logical OR over multiple boolean fields | extra={"fields": [...]} |
nor_boolean | Logical NOR over multiple boolean fields | extra={"fields": [...]} |
equal_boolean | true if value matches any of the specified strings | extra={"values": ["active", "bypass"]} |
static_value | Sets a static value, ignoring node_field | extra={"value": "dynamodb"} |
coalesce | Sets the first non-null value from multiple fields | extra={"fields": [...]} |
cartography --ontology-users-source "okta,microsoft,gsuite"
cartography --ontology-devices-source "crowdstrike,kandji,duo"references/semantic-labels.md — execution flow, available labels/fields, full canonical-node schema example, eligible_for_source deep dive.© cartography-cncf, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in .agents/skills/enrich-ontology of cartography-cncf/cartography.
Open the folder on GitHubat commit 0975e95
Enrich Ontology next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Enrich Ontology this skillcartography-cncf/cartography | 4.1k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Token Mapnexu-io/open-design | 100k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Maps Geographyasgeirtj/system_prompts_leaks | 69k | — | ~717 | Automated safety check: Pass | CC0-1.0 | |
| Ontology Term ResolutionK-Dense-AI/scientific-agent-skills | 48k | 1 repos | ~3.6k | Automated safety check: Notes | MIT | |
| Feature Maponyx-dot-app/onyx | 32k | — | ~459 | Automated safety check: Pass | Custom licence | |
| Form Labelsthedaviddias/Front-End-Checklist | 74k | — | ~565 | Automated safety check: Pass | MIT |
nexu-io/open-design
Map an extracted Figma / source-code token bag onto the active OD design system, producing a deterministic mapping the generate stage can consume.
asgeirtj/system_prompts_leaks
Accurate maps from real geo data — use for any map, or whenever geography would make a good graphic for a deliverable
K-Dense-AI/scientific-agent-skills
Resolves free-text scientific labels to ontology term IDs and validates existing CURIEs against the EBI Ontology Lookup Service (OLS4).
onyx-dot-app/onyx
Use the Onyx feature map (.agents/feature-map/) to learn what a product surface does, the code behind it, and what a change can break.
thedaviddias/Front-End-Checklist
A skill your agent uses when reviewing rendered HTML, interactive components, or design-system patterns related to Associate labels with form controls.
thedaviddias/Front-End-Checklist
A skill your agent uses when reviewing rendered HTML, interactive components, or design-system patterns related to Use semantic list elements.
cartography-cncf/cartography
Define a new node schema under cartography/models/MODULENAME/, including required properties, sub-resource relationships, extra labels, conditional labels, scoped cleanup, and one-to-many transforms.
cartography-cncf/cartography
Define a CartographyRelSchema (standard relationship), one-to-many edge, or MatchLink connecting existing nodes.
cartography-cncf/cartography
Add a post-ingestion typed analysis job to a Cartography module to enrich the graph after sync.
cartography-cncf/cartography
Author a new Cartography intel module end-to-end (entry point, sync GET/TRANSFORM/LOAD/CLEANUP, declarative data model, integration test, schema docs).
cartography-cncf/cartography
Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.
cartography-cncf/cartography
Promote provider-specific relationships to a canonical cross-provider ontology edge using the WORKLOADPARENT pattern (a parallel CartographyRelSchema with the canonical rellabel, the old edge kept…
Map a Cartography node into the Ontology system using semantic labels (UserAccount, DeviceInstance, Tenant, Database, ObjectStorage, FileStorage) or canonical nodes (User, Device). Enrich Ontology is an agent skill from cartography-cncf/cartography. Map a Cartography node into the Ontology system using semantic labels (UserAccount, DeviceInstance, Tenant, Database, ObjectStorage, FileStorage) or canonical nodes (User, Device).
Enrich Ontology fits situations like: the user asks to add ontology mapping; expose a node as a semantic label; normalise identity / device data across providers; enable cross-module queries.
Run `npx skills add cartography-cncf/cartography --skill enrich-ontology -a claude-code`. Or copy the skill folder (.agents/skills/enrich-ontology in cartography-cncf/cartography) into .claude/skills/enrich-ontology in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cartography-cncf/cartography --skill enrich-ontology -a codex`. Or copy the skill folder (.agents/skills/enrich-ontology in cartography-cncf/cartography) into .agents/skills/enrich-ontology in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cartography-cncf/cartography --skill enrich-ontology -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/enrich-ontology, .gemini/skills/enrich-ontology, .github/skills/enrich-ontology and .opencode/skills/enrich-ontology in your project.
Going by SKILL.md and its folder, Enrich Ontology needs the command-line tools its instructions call (uv). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Enrich Ontology is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Enrich Ontology: Token Map (nexu-io/open-design, 100k stars), Maps Geography (asgeirtj/system_prompts_leaks, 69k stars), Ontology Term Resolution (K-Dense-AI/scientific-agent-skills, 48k stars) and Feature Map (onyx-dot-app/onyx, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cartography-cncf (a GitHub organization) maintains it in cartography-cncf/cartography, which has 4,129 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 11, 2026.
Source: cartography-cncf/cartography on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.