Agent skill

Suggest Concepts

by Fraunhofer-AISEC in Fraunhofer-AISEC/cpg

Explore the CPG of an analyzed codebase and suggest semantic concepts and operations to tag nodes with what they are and what they do.

Apache-2.0Auto-check passed

Install Suggest Concepts

skills CLI
$ npx skills add Fraunhofer-AISEC/cpg --skill suggest-concepts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Fraunhofer-AISEC/cpg suggest-concepts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Fraunhofer-AISEC/cpg.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/suggest-concepts .claude/skills/suggest-concepts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
suggest-concepts
GitHub stars
466
Token cost
~829 tokens
SKILL.md length
451 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

Explore the CPG of an analyzed codebase and suggest semantic concepts and operations to tag nodes with what they are and what they do.

  • Works in 4 steps: Load existing concepts and operations → Explore the code comprehensively → Suggest via the tool → …
  • SKILL.md covers About the CPG, Concepts and Operations and Workflow
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Suggest Concepts is an agent skill from Fraunhofer-AISEC/cpg. Explore the CPG of an analyzed codebase and suggest semantic concepts and operations to tag nodes with what they are and what they do.

Its SKILL.md is about 830 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with C++, Go, Java and Python. The repository describes itself as: A library to extract Code Property Graphs from C/C++, Java, Go, Python, Ruby and every other language through LLVM-IR. The licence is Apache-2.0.

Example prompts

  • “/suggest-concepts”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Load existing concepts and operations
  2. Explore the code comprehensively
  3. Suggest via the tool
  4. Stop

What it can do on your machine

Read from SKILL.md and the folder at commit caf941c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Suggest Concepts loads about 829 tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 451 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~829

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Fraunhofer-AISEC/cpg at commit caf941c, republished under its Apache-2.0 licence (© Fraunhofer-AISEC). 451 words, ~829 tokens.

Download SKILL.mdSave it as .claude/skills/suggest-concepts/SKILL.md (or your agent's skills folder).
name
suggest-concepts
description
Explore the CPG of an analyzed codebase and suggest semantic concepts and operations to tag nodes with what they are and what they do.

Suggest Concepts and Operations for a CPG

Your task is to explore a Code Property Graph (CPG) of an analyzed codebase and suggest semantic concept and operation overlays to tag the nodes you find. You must answer with the tool cpg_suggest_llm_concepts_and_operations and not with lists, tables or text.

About the CPG

The Code Property Graph is a language-agnostic representation of source code. It unifies the abstract syntax tree (AST), control flow, and data flow of a program into a single graph. Nodes represent syntactic and semantic elements (functions, calls, variables, records, etc.), and edges connect them.

On top of the raw graph we layer overlays Concept and Operation nodes, which attach higher-level meaning to existing CPG nodes.

Concepts and Operations

Concepts describe what something is.

  • Attached to nodes that represent or hold a thing (variables, fields, records, sometimes functions).
  • Examples: user_email → Data, api_token → Secret, an AuthService class → Authentication.
  • A concept can have properties and a set of operations associated with it.

Operations describe what something does.

  • Attached to nodes that perform an action, most often calls (function or method calls).
  • Examples: requests.post(...) → HttpRequest, file.write(...) → FileWrite, encrypt(...) → Encryption.
  • Every operation belongs to a concept.

Rules:

  • A concept can stand on its own. An operation always needs a concept.
  • Keep names short and semantic: one word where possible (Encryption, Logging, Secret).

Workflow

1. Load existing concepts and operations

Call cpg_list_llm_concepts_operations once, before anything else.

  • If the result is non-empty, reuse those concept and operation names and their property schemas wherever they semantically fit. Do not invent a duplicate under a different name.
  • If the result is empty suggest new ones.
Show full SKILL.md (183 more words)Show less
2. Explore the code comprehensively

Before suggesting follow a multistep approach by calling other tools to explore the graph, so one listing is rarely enough: Combine several of:

  • cpg_list_functions, cpg_list_records, cpg_list_calls, cpg_list_calls_to, etc. for overview.
  • cpg_get_node to inspect a specific node in detail (if needed).

Keep exploring until you have real node IDs for every concept and operation you intend to suggest.

3. Suggest via the tool

Suggest one concept per turn: emit a single cpg_suggest_llm_concepts_and_operations tool call, then proceed to the next concept on your next turn.

Pass REAL node IDs returned by the previous tools. Never pass placeholder, invented, or guessed IDs. If you don't have a real ID, go back to step 2.

For each call provide:

  • The concept's nodeId (typically a record, field, or variable).
  • Each operation's nodeId pointing to the node where the action is realized.
  • Reasoning so the user can judge the suggestion.
4. Stop

Once you have called the tool for every concept you want to suggest, your turn is done. The user reviews the suggestions and decides what to accept. Do not apply anything yourself.

© Fraunhofer-AISEC, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/suggest-concepts of Fraunhofer-AISEC/cpg.

Open the folder on GitHubat commit caf941c

Compare with similar skills

Suggest Concepts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Suggest Concepts compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Suggest Concepts this skillFraunhofer-AISEC/cpg466—~829Automated safety check: PassApache-2.0
Fory Releaseapache/fory4.6k—~2.9kAutomated safety check: PassApache-2.0
CodeQL Security Scantrailofbits/skills7.5k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Fory Version Bumpapache/fory4.6k—~1.1kAutomated safety check: PassApache-2.0
Fory Performance Optimizationapache/fory4.6k—~2.2kAutomated safety check: PassApache-2.0
Backend Interview SimulatorHazehacker/backend-interview-simulator208—~2.3kAutomated safety check: PassMIT

Similar skills

  • Fory Release

    apache/fory

    Prepare an Apache Fory release candidate from a clean release branch, including the version bump, RC tag, JVM staging, ASF source artifacts, SVN upload, and vote email.

    4.6k GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.5k GitHub stars~4.6k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Bump Apache Fory release or post-release development versions across Java, Kotlin, Scala, Python, Rust, Go, C++, C, Dart, JavaScript, Swift, integration tests, examples, and source docs.

    4.6k GitHub stars~1.1k tokensUpdated yesterday
    MobileAuto-check passed
  • Run profile-driven bottleneck optimization across Apache Fory implementations (Java, C++, Python/Cython, Go, Rust, Swift, C, JavaScript/TypeScript, Dart, Kotlin, Scala).

    4.6k GitHub stars~2.2k tokensUpdated yesterday
    MobileAuto-check passed
  • Backend Interview Simulator

    Hazehacker/backend-interview-simulator

    A skill your agent uses when users want to practice or simulate Java, C++, Go, Golang, mixed-stack, or general backend technical interviews, including resume-based and job-description-based…

    208 GitHub stars~2.3k tokensUpdated 2 mo ago
    Business, Finance & HRAuto-check passed
  • Dbg

    theodo-group/debug-that

    Debug applications using the dbg CLI debugger. An agent skill from theodo-group/debug-that.

    158 GitHub stars~2.5k tokensUpdated 2 days ago
    DevelopmentAuto-check passed

Questions about Suggest Concepts

What does Suggest Concepts do?

Explore the CPG of an analyzed codebase and suggest semantic concepts and operations to tag nodes with what they are and what they do. Suggest Concepts is an agent skill from Fraunhofer-AISEC/cpg. Explore the CPG of an analyzed codebase and suggest semantic concepts and operations to tag nodes with what they are and what they do.

How do I install Suggest Concepts in Claude Code?

Run `npx skills add Fraunhofer-AISEC/cpg --skill suggest-concepts -a claude-code`. Or copy the skill folder (.agents/skills/suggest-concepts in Fraunhofer-AISEC/cpg) into .claude/skills/suggest-concepts in your project. Claude Code loads it when a task matches its description.

How do I install Suggest Concepts in Codex?

Run `npx skills add Fraunhofer-AISEC/cpg --skill suggest-concepts -a codex`. Or copy the skill folder (.agents/skills/suggest-concepts in Fraunhofer-AISEC/cpg) into .agents/skills/suggest-concepts in your project. Codex loads it when a task matches its description.

Can I use Suggest Concepts in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Fraunhofer-AISEC/cpg --skill suggest-concepts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/suggest-concepts, .gemini/skills/suggest-concepts, .github/skills/suggest-concepts and .opencode/skills/suggest-concepts in your project.

What does Suggest Concepts need to run?

SKILL.md names no scripts, command-line tools or credentials: Suggest Concepts is instructions for the agent only.

Does Suggest Concepts access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Suggest Concepts safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Suggest Concepts use?

Suggest Concepts is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Suggest Concepts use?

About 829 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Suggest Concepts?

Skills that share tags, products or a category with Suggest Concepts: Fory Release (apache/fory, 4.6k stars), CodeQL Security Scan (trailofbits/skills, 7.5k stars), Fory Version Bump (apache/fory, 4.6k stars) and Fory Performance Optimization (apache/fory, 4.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Suggest Concepts?

Fraunhofer-AISEC (a GitHub organization) maintains it in Fraunhofer-AISEC/cpg, which has 466 GitHub stars. The repository was last updated on October 9, 2026.

Source: Fraunhofer-AISEC/cpg on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.