Agent skill

Enrich Ontology

by cartography-cncf in cartography-cncf/cartography

Map a Cartography node into the Ontology system using semantic labels (UserAccount, DeviceInstance, Tenant, Database, ObjectStorage, FileStorage) or canonical nodes (User, Device).

Apache-2.0Auto-check passed

Install Enrich Ontology

skills CLI
$ npx skills add cartography-cncf/cartography --skill enrich-ontology -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cartography-cncf/cartography enrich-ontology --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/enrich-ontology .claude/skills/enrich-ontology && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
enrich-ontology
GitHub stars
4.1k
Token cost
~2.4k tokens
SKILL.md length
574 words
Files
2 (incl. references)
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

Map a Cartography node into the Ontology system using semantic labels (UserAccount, DeviceInstance, Tenant, Database, ObjectStorage, FileStorage) or canonical nodes (User, Device).

  • Works in 8 steps: Decide: semantic label or canonical node? → Author the mapping → Register the mapping → …
  • The user asks to add ontology mapping
  • SKILL.md covers Critical rules, Instructions, special_handling quick reference and Canonical node configuration…, plus 1 more section
  • Calls uv

What it does

Enrich Ontology is an agent skill from cartography-cncf/cartography. Map a Cartography node into the Ontology system using semantic labels (UserAccount, DeviceInstance, Tenant, Database, ObjectStorage, FileStorage) or canonical nodes (User, Device). Use when the user asks to add ontology mapping, expose a node as a semantic label, normalise identity / device data across providers, enable cross-module queries, or wire ont properties.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/semantic-labels.md`).

The repository describes itself as: Cartography is a Python tool that pulls infrastructure assets and their relationships into a Neo4j graph database. The licence is Apache-2.0.

When your agent uses it

  • The user asks to add ontology mapping
  • Expose a node as a semantic label
  • Normalise identity / device data across providers
  • Enable cross-module queries

Example prompts

  • “/enrich-ontology”

Requirements

  • Python 3

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Decide: semantic label or canonical node?
  2. Author the mapping
  3. Register the mapping
  4. Wire the semantic label on your node schema
  5. required and eligible_for_source
  6. Cross-entity relationships (e.g. user owns device)
  7. Test
  8. Document the integration

What it can do on your machine

Read from SKILL.md and the folder at commit 0975e95. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Enrich Ontology loads about 2.4k tokens when it runs, and up to ~3.7k if it reads all its reference files. Until then it costs about 97 tokens; SKILL.md has 574 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cartography-cncf/cartography at commit 0975e95, republished under its Apache-2.0 licence (© cartography-cncf). 574 words, ~2,404 tokens.

Download SKILL.mdSave it as .claude/skills/enrich-ontology/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
enrich-ontology
description
Map a Cartography node into the Ontology system using semantic labels (UserAccount, DeviceInstance, Tenant, Database, ObjectStorage, FileStorage) or canonical nodes (User, Device). Use when the user asks to add ontology mapping, expose a node as a semantic label, normalise identity / device data across providers, enable cross-module queries, or wire `_ont_*` properties.

enrich-ontology

Cartography's Ontology system unifies data from multiple sources via two mechanisms:

  1. Semantic labels (recommended) — adds labels (e.g. UserAccount) and prefixed properties (_ont_*) directly to source nodes during ingestion.
  2. Canonical nodes — separate (:User:Ontology) / (:Device:Ontology) nodes that aggregate data from multiple sources.

Most modules only need semantic labels.

Critical rules

  1. Mark primary identifiers required=True in OntologyFieldMapping (e.g. email for User, hostname for Device). Records missing these are excluded from ontology node creation.
  2. For semantic labels, add the exported ontology label constant, for example ExtraNodeLabels([USER_ACCOUNT]). Ontology constants are immutable ExtraNodeLabel values with kind=LabelKind.ONTOLOGY; the ontology system handles the _ont_* properties automatically.
  3. special_handling values are strings: invert_boolean, to_boolean, or_boolean, nor_boolean, equal_boolean, static_value, coalesce. Boolean conditions inside extra={"values": ...} must also be strings ("true", not True).
  4. Ontology mapping docs are generated. Never hand-write schema.md: the > **Ontology Mapping** note is emitted from the node's extra_node_labels. Document the node in the model with a docstring and PropertyRef description= values.
  5. Module name microsoft is the canonical source for Microsoft Graph. entra is still accepted as a backward-compatible alias during migration.

Instructions

Step 1 — Decide: semantic label or canonical node?
NeedUse
Cross-module queries on existing source nodes (e.g. all UserAccount across systems)Semantic label
Aggregate one entity from many sources into a single canonical recordCanonical node

When in doubt, start with semantic label.

Step 2 — Author the mapping

Add the mapping in cartography/models/ontology/mapping/data/. For users:

python
# cartography/models/ontology/mapping/data/useraccounts.py
from cartography.models.ontology.mapping.specs import (
    OntologyFieldMapping, OntologyMapping, OntologyNodeMapping,
)


your_service_mapping = OntologyMapping(
    module_name="your_service",
    nodes=[
        OntologyNodeMapping(
            node_label="YourServiceUser",
            fields=[
                OntologyFieldMapping(ontology_field="email",     node_field="email", required=True),
                OntologyFieldMapping(ontology_field="username",  node_field="username"),
                OntologyFieldMapping(ontology_field="fullname",  node_field="display_name"),
                OntologyFieldMapping(ontology_field="firstname", node_field="first_name"),
                OntologyFieldMapping(ontology_field="lastname",  node_field="last_name"),

                OntologyFieldMapping(
                    ontology_field="inactive",
                    node_field="account_enabled",
                    special_handling="invert_boolean",
                ),
                OntologyFieldMapping(
                    ontology_field="has_mfa",
                    node_field="multifactor",
                    special_handling="to_boolean",
                ),
                OntologyFieldMapping(
                    ontology_field="inactive",
                    node_field="suspended",
                    special_handling="or_boolean",
                    extra={"fields": ["archived"]},
                ),
            ],
        ),
    ],
)

For devices the pattern is the same with OntologyNodeMapping(node_label="YourServiceDevice", ...).

Step 3 — Register the mapping

Add it to the dictionary at the bottom of the file:

python
# Example: bottom of useraccounts.py
USERACCOUNTS_ONTOLOGY_MAPPING: dict[str, OntologyMapping] = {
    # ... existing mappings ...
    "your_service": your_service_mapping,
}

The mappings are auto-imported via cartography/models/ontology/mapping/__init__.py.

Step 4 — Wire the semantic label on your node schema

For semantic labels, the node schema simply gains the extra label — Cartography injects _ont_* and _ont_source automatically at ingestion:

python
from cartography.models.core.nodes import ExtraNodeLabels
from cartography.models.ontology.labels import USER_ACCOUNT


@dataclass(frozen=True)
class YourServiceUserSchema(CartographyNodeSchema):
    label: str = "YourServiceUser"
    extra_node_labels: ExtraNodeLabels = ExtraNodeLabels([USER_ACCOUNT])
    properties: YourServiceUserNodeProperties = YourServiceUserNodeProperties()
    sub_resource_relationship: YourServiceTenantToUserRel = YourServiceTenantToUserRel()

For canonical nodes, define a separate schema with extra_node_labels=ExtraNodeLabels([ONTOLOGY]) and a relationship to the semantic-labeled source nodes. See references/semantic-labels.md for the full template.

Step 5 — required and eligible_for_source

required=True means: source records lacking this field are excluded from ontology node creation. Always mark the primary identifier required:

python
OntologyFieldMapping(ontology_field="email",    node_field="email",       required=True)
OntologyFieldMapping(ontology_field="hostname", node_field="device_name", required=True)

OntologyNodeMapping.eligible_for_source=False means: this mapping links existing ontology nodes but cannot create new ones. Use it when the source lacks the required identifier:

python
# AWS IAM users have no email, so they cannot create new User ontology nodes.
OntologyNodeMapping(
    node_label="AWSUser",
    eligible_for_source=False,
    fields=[
        OntologyFieldMapping(ontology_field="username", node_field="name"),
    ],
),
Show full SKILL.md (210 more words)Show less
Step 6 — Cross-entity relationships (e.g. user owns device)

For services that link users to devices, add a typed analysis statement to cartography/analysis/ontology/analysis.py:

python
AnalysisStatement(
    match="MATCH (u:User)-[:HAS_ACCOUNT]->(:YourServiceUser)-[:OWNS]->(:YourServiceDevice)<-[:OBSERVED_AS]-(d:Device)",
    effects=(
        AddRelationship("u", "OWNS", "d", source_label="User", target_label="Device"),
    ),
)

See the analysis-jobs skill for typed analysis job syntax.

Step 7 — Test

For semantic labels — assert _ont_* properties land on your nodes:

python
def test_ontology_properties(neo4j_session):
    # after running your sync
    row = neo4j_session.run(
        "MATCH (n:YourServiceUser) RETURN n._ont_email, n._ont_source LIMIT 1"
    ).single()
    assert row["n._ont_email"] is not None
    assert row["n._ont_source"] == "your_service"

For canonical nodes — assert the ontology intel module produces them:

python
def test_canonical_user_created(neo4j_session):
    row = neo4j_session.run(
        """
        MATCH (u:User:Ontology)-[:HAS_ACCOUNT]->(ua:YourServiceUser)
        RETURN count(u) AS user_count
        """
    ).single()
    assert row["user_count"] > 0
Step 8 — Document the integration

Do not create or hand-edit schema.md. Sphinx generates it from the data model, including the > **Ontology Mapping** note for any node whose extra_node_labels carry an ontology label constant. Write the documentation in the model itself: a docstring on the node schema and description= on each displayed PropertyRef. Build the docs with uv run ./docs/build.sh and check the generated page.

special_handling quick reference

ValueDescriptionExtra params
invert_booleanInverts the boolean value (true -> false)None
to_booleanConverts to boolean, treating non-null as trueNone
or_booleanLogical OR over multiple boolean fieldsextra={"fields": [...]}
nor_booleanLogical NOR over multiple boolean fieldsextra={"fields": [...]}
equal_booleantrue if value matches any of the specified stringsextra={"values": ["active", "bypass"]}
static_valueSets a static value, ignoring node_fieldextra={"value": "dynamodb"}
coalesceSets the first non-null value from multiple fieldsextra={"fields": [...]}

Canonical node configuration (CLI)

bash
cartography --ontology-users-source "okta,microsoft,gsuite"
cartography --ontology-devices-source "crowdstrike,kandji,duo"

References (load on demand)

  • references/semantic-labels.md — execution flow, available labels/fields, full canonical-node schema example, eligible_for_source deep dive.

© cartography-cncf, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .agents/skills/enrich-ontology of cartography-cncf/cartography.

  • SKILL.md
  • references/semantic-labels.md

Open the folder on GitHubat commit 0975e95

Compare with similar skills

Enrich Ontology next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Enrich Ontology compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Enrich Ontology this skillcartography-cncf/cartography4.1k—~2.4kAutomated safety check: PassApache-2.0
Token Mapnexu-io/open-design100k—~1.4kAutomated safety check: PassApache-2.0
Maps Geographyasgeirtj/system_prompts_leaks69k—~717Automated safety check: PassCC0-1.0
Ontology Term ResolutionK-Dense-AI/scientific-agent-skills48k1 repos~3.6kAutomated safety check: NotesMIT
Feature Maponyx-dot-app/onyx32k—~459Automated safety check: PassCustom licence
Form Labelsthedaviddias/Front-End-Checklist74k—~565Automated safety check: PassMIT

Similar skills

  • Token Map

    nexu-io/open-design

    Map an extracted Figma / source-code token bag onto the active OD design system, producing a deterministic mapping the generate stage can consume.

    100k GitHub stars~1.4k tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Maps Geography

    asgeirtj/system_prompts_leaks

    Accurate maps from real geo data — use for any map, or whenever geography would make a good graphic for a deliverable

    69k GitHub stars~717 tokensUpdated yesterday
    Auto-check passed
  • Ontology Term Resolution

    K-Dense-AI/scientific-agent-skills

    Resolves free-text scientific labels to ontology term IDs and validates existing CURIEs against the EBI Ontology Lookup Service (OLS4).

    48k GitHub starsUsed in 1 repo~3.6k tokens
    Research & ScienceAuto-check: notes
  • Feature Map

    onyx-dot-app/onyx

    Use the Onyx feature map (.agents/feature-map/) to learn what a product surface does, the code behind it, and what a change can break.

    32k GitHub stars~459 tokensUpdated yesterday
    Auto-check passed
  • Form Labels

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing rendered HTML, interactive components, or design-system patterns related to Associate labels with form controls.

    74k GitHub stars~565 tokensUpdated 5 days ago
    Frontend & DesignAuto-check passed
  • Semantic Lists

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing rendered HTML, interactive components, or design-system patterns related to Use semantic list elements.

    74k GitHub stars~504 tokensUpdated 5 days ago
    Frontend & DesignAuto-check passed

More from cartography-cncf/cartography

All 11 skills in this repo
  • Add Node Type

    cartography-cncf/cartography

    Define a new node schema under cartography/models/MODULENAME/, including required properties, sub-resource relationships, extra labels, conditional labels, scoped cleanup, and one-to-many transforms.

    4.1k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Add Relationship

    cartography-cncf/cartography

    Define a CartographyRelSchema (standard relationship), one-to-many edge, or MatchLink connecting existing nodes.

    4.1k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Analysis Jobs

    cartography-cncf/cartography

    Add a post-ingestion typed analysis job to a Cartography module to enrich the graph after sync.

    4.1k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Create Module

    cartography-cncf/cartography

    Author a new Cartography intel module end-to-end (entry point, sync GET/TRANSFORM/LOAD/CLEANUP, declarative data model, integration test, schema docs).

    4.1k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Create Rule

    cartography-cncf/cartography

    Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.

    4.1k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Promote Ontology Relationship

    cartography-cncf/cartography

    Promote provider-specific relationships to a canonical cross-provider ontology edge using the WORKLOADPARENT pattern (a parallel CartographyRelSchema with the canonical rellabel, the old edge kept…

    4.1k GitHub stars~3.6k tokensUpdated today
    Auto-check passed

Questions about Enrich Ontology

What does Enrich Ontology do?

Map a Cartography node into the Ontology system using semantic labels (UserAccount, DeviceInstance, Tenant, Database, ObjectStorage, FileStorage) or canonical nodes (User, Device). Enrich Ontology is an agent skill from cartography-cncf/cartography. Map a Cartography node into the Ontology system using semantic labels (UserAccount, DeviceInstance, Tenant, Database, ObjectStorage, FileStorage) or canonical nodes (User, Device).

When should I use Enrich Ontology?

Enrich Ontology fits situations like: the user asks to add ontology mapping; expose a node as a semantic label; normalise identity / device data across providers; enable cross-module queries.

How do I install Enrich Ontology in Claude Code?

Run `npx skills add cartography-cncf/cartography --skill enrich-ontology -a claude-code`. Or copy the skill folder (.agents/skills/enrich-ontology in cartography-cncf/cartography) into .claude/skills/enrich-ontology in your project. Claude Code loads it when a task matches its description.

How do I install Enrich Ontology in Codex?

Run `npx skills add cartography-cncf/cartography --skill enrich-ontology -a codex`. Or copy the skill folder (.agents/skills/enrich-ontology in cartography-cncf/cartography) into .agents/skills/enrich-ontology in your project. Codex loads it when a task matches its description.

Can I use Enrich Ontology in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cartography-cncf/cartography --skill enrich-ontology -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/enrich-ontology, .gemini/skills/enrich-ontology, .github/skills/enrich-ontology and .opencode/skills/enrich-ontology in your project.

What does Enrich Ontology need to run?

Going by SKILL.md and its folder, Enrich Ontology needs the command-line tools its instructions call (uv). Our summary lists: Python 3.

Does Enrich Ontology access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Enrich Ontology safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Enrich Ontology use?

Enrich Ontology is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Enrich Ontology use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to Enrich Ontology?

Skills that share tags, products or a category with Enrich Ontology: Token Map (nexu-io/open-design, 100k stars), Maps Geography (asgeirtj/system_prompts_leaks, 69k stars), Ontology Term Resolution (K-Dense-AI/scientific-agent-skills, 48k stars) and Feature Map (onyx-dot-app/onyx, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Enrich Ontology?

cartography-cncf (a GitHub organization) maintains it in cartography-cncf/cartography, which has 4,129 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 11, 2026.

Source: cartography-cncf/cartography on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.