Agent skill

Ghost Repo Context

by ghostsecurity in ghostsecurity/skills

Scans directory structure, detects projects, maps dependencies, and documents code organization into a repo.md file.

Apache-2.0Auto-check: notesAgent Workflows

Install Ghost Repo Context

skills CLI
$ npx skills add ghostsecurity/skills --skill ghost-repo-context -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ghostsecurity/skills ghost-repo-context --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ghostsecurity/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ghost/skills/repo-context .claude/skills/ghost-repo-context && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ghost-repo-context
GitHub stars
408
Token cost
~786 tokens
SKILL.md length
293 words
Files
4
Skills in repo
5
Repo updated
First seen
Licence
Apache-2.0

At a glance

Scans directory structure, detects projects, maps dependencies, and documents code organization into a repo.md file.

  • Works in 5 steps: Detect Projects — Read /detector.md and… → Summarize Each Project — Read… → Write repo.md — Combine detection and… → …
  • The user needs a codebase overview
  • SKILL.md covers Inputs, Tool Restrictions, Setup and Check Cache First, plus 1 more section
  • Calls git

What it does

Ghost Repo Context is an agent skill from ghostsecurity/skills. Scans directory structure, detects projects, maps dependencies, and documents code organization into a repo.md file. Use when the user needs a codebase overview, project structure map, or repository context before security analysis.

Its SKILL.md is about 790 tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `detector.md`, `summarizer.md` and `template-repo.md`).

It sits in Agent Workflows, covering Codebase knowledge for agents. The repository describes itself as: Ghost Security's collection of AppSec skills for AI coding agents. The licence is Apache-2.0.

When your agent uses it

  • The user needs a codebase overview
  • Project structure map
  • Repository context before security analysis

Example prompts

  • “Use the ghost-repo-context skill to scan directory structure, detects projects, maps dependencies, and documents code organization into a repo.md file”
  • “/ghost-repo-context”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Edit, Glob, Grep, Bash

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Detect Projects — Read /detector.md and follow its instructions against . Save the full detection output (project details needed for step…
  2. Summarize Each Project — Read /summarizer.md. For EACH project detected in step 1, follow the summarizer instructions using that project's…
  3. Write repo.md — Combine detection and summary results into /repo.md using the format in /template-repo.md. For each project include
  4. Validate — Read /repo.md back and verify it contains the expected sections from /template-repo.md (e.g., project entries with Detection…
  5. Output — Return: Repository context is at: /repo.md

What it can do on your machine

Read from SKILL.md and the folder at commit 25fdf06. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Glob
    • Grep
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ghost Repo Context loads about 786 tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 293 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~786

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Edit, Glob, Grep, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ghostsecurity/skills at commit 25fdf06, republished under its Apache-2.0 licence (© ghostsecurity). 293 words, ~786 tokens.

Download SKILL.mdSave it as .claude/skills/ghost-repo-context/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
ghost-repo-context
description
Scans directory structure, detects projects, maps dependencies, and documents code organization into a repo.md file. Use when the user needs a codebase overview, project structure map, or repository context before security analysis.
allowed-tools
Read, Write, Edit, Glob, Grep, Bash
license
apache-2.0
metadata.version
1.1.0

Repository Context Builder

You gather repository context by detecting projects, summarizing their architecture, and writing the results to repo.md. Do all work yourself — do not spawn subagents or delegate.

Inputs

Parse these from $ARGUMENTS (key=value pairs):

  • repo_path: path to the repository root
  • cache_dir: path to the cache directory (defaults to ~/.ghost/repos/<repo_id>/cache)

$ARGUMENTS

If cache_dir is not provided, compute it:

bash
repo_name=$(basename "$(pwd)") && remote_url=$(git remote get-url origin 2>/dev/null || pwd) && short_hash=$(printf '%s' "$remote_url" | git hash-object --stdin | cut -c1-8) && repo_id="${repo_name}-${short_hash}" && cache_dir="$HOME/.ghost/repos/${repo_id}/cache" && echo "cache_dir=$cache_dir"

Tool Restrictions

Do NOT use WebFetch or WebSearch. All work must use only local files in the repository.

Setup

Discover this skill's own directory so you can reference agent files:

bash
skill_dir=$(find . -path '*/skills/repo-context/SKILL.md' 2>/dev/null | head -1 | xargs dirname)
echo "skill_dir=$skill_dir"

Check Cache First

Check if <cache_dir>/repo.md already exists. If it does, skip everything and return:

Repository context is at: <cache_dir>/repo.md

If it does not exist, run mkdir -p <cache_dir> and continue.


Workflow

  1. Detect Projects — Read <skill_dir>/detector.md and follow its instructions against <repo_path>. Save the full detection output (project details needed for step 2). If detection finds no projects, write a minimal repo.md noting "No projects detected" and skip to step 4.

  2. Summarize Each Project — Read <skill_dir>/summarizer.md. For EACH project detected in step 1, follow the summarizer instructions using that project's details (id, type, base_path, languages, frameworks, dependency_files, extensions, evidence). Collect the summary for each project. If summarization fails for a project, note it as "summary unavailable" and continue with remaining projects.

  3. Write repo.md — Combine detection and summary results into <cache_dir>/repo.md using the format in <skill_dir>/template-repo.md. For each project include:

    • Detection: ID, Type, Base Path, Languages, Frameworks, Dependency Files, Extensions, Evidence
    • Summary: Architectural summary, Sensitive Data Types, Business Criticality, Component Map, Evidence
  4. Validate — Read <cache_dir>/repo.md back and verify it contains the expected sections from <skill_dir>/template-repo.md (e.g., project entries with Detection and Summary fields). If the file is missing or malformed, retry the write once before reporting an error.

  5. Output — Return: Repository context is at: <cache_dir>/repo.md

© ghostsecurity, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in plugins/ghost/skills/repo-context of ghostsecurity/skills.

  • SKILL.md
  • detector.md
  • summarizer.md
  • template-repo.md

Open the folder on GitHubat commit 25fdf06

Compare with similar skills

Ghost Repo Context next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ghost Repo Context compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ghost Repo Context this skillghostsecurity/skills408—~786Automated safety check: NotesApache-2.0
ccc Semantic Code Searchcocoindex-io/cocoindex-code2.7k—~938Automated safety check: PassApache-2.0
Context Engineeringabashev/vfs-s31069 repos~2.6kAutomated safety check: NotesApache-2.0
Repomix Codebase Packeryamadashy/repomix29k—~1.3kAutomated safety check: NotesMIT
Codebase Handbook BuilderRuhan-Wang/Harness_Handbook332—~2.2kAutomated safety check: PassApache-2.0
CodemapJordanCoin/codemap704—~1.8kAutomated safety check: PassMIT

Similar skills

  • ccc Semantic Code Search

    cocoindex-io/cocoindex-code

    Semantic code search and index management with the ccc CLI: the agent initializes, indexes and queries the project by concept, filtering by language or path.

    2.7k GitHub stars~938 tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Context Engineering

    abashev/vfs-s3

    Optimizes agent context setup. An agent skill from abashev/vfs-s3.

    106 GitHub starsUsed in 9 repos~2.6k tokens
    Agent WorkflowsAuto-check: notes
  • Repomix Codebase Packer

    yamadashy/repomix

    Packs a local directory or remote GitHub repository into one AI-friendly file with Repomix, then searches it to explore structure, find patterns and count tokens.

    29k GitHub stars~1.3k tokensUpdated 4 days ago
    Agent WorkflowsAuto-check: notes
  • Codebase Handbook Builder

    Ruhan-Wang/Harness_Handbook

    Generates, refreshes, validates and uses a compact handbook that maps where a change touches in a repository, using the active Codex session and no external LLM API.

    332 GitHub stars~2.2k tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed
  • Codemap

    JordanCoin/codemap

    Gives an agent a quick map of a codebase's structure, dependencies, changes and handoffs, and tunes per-project config so the output stays code-first.

    704 GitHub stars~1.8k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Repomix Context Skill

    sopaco/deepwiki-rs

    A skill your agent uses when an agent needs source code from the local repomix index under .terrain/agent/repomix.md (not committed; regenerate via Terrain scan).

    3.1k GitHub stars~671 tokensUpdated 24 days ago
    Agent WorkflowsAuto-check passed

More from ghostsecurity/skills

  • Ghost Exo

    ghostsecurity/skills

    The single interface for building, improving, and debugging exo workflows.

    408 GitHub stars~1.3k tokensUpdated 10 days ago
    Auto-check passed
  • Ghost Report

    ghostsecurity/skills

    Ghost Security — combined security report. An agent skill from ghostsecurity/skills.

    408 GitHub stars~1.4k tokensUpdated 10 days ago
    Auto-check: notes
  • Ghost Scan Deps

    ghostsecurity/skills

    Ghost Security - Software Composition Analysis (SCA) scanner.

    408 GitHub stars~1.3k tokensUpdated 10 days ago
    Auto-check: notes
  • Ghost Scan Secrets

    ghostsecurity/skills

    Ghost Security - Secrets and credentials scanner. An agent skill from ghostsecurity/skills.

    408 GitHub stars~1.2k tokensUpdated 10 days ago
    Auto-check: notes

Categories

Questions about Ghost Repo Context

What does Ghost Repo Context do?

Scans directory structure, detects projects, maps dependencies, and documents code organization into a repo.md file. Ghost Repo Context is an agent skill from ghostsecurity/skills.md file.

When should I use Ghost Repo Context?

Ghost Repo Context fits situations like: the user needs a codebase overview; project structure map; repository context before security analysis.

How do I install Ghost Repo Context in Claude Code?

Run `npx skills add ghostsecurity/skills --skill ghost-repo-context -a claude-code`. Or copy the skill folder (plugins/ghost/skills/repo-context in ghostsecurity/skills) into .claude/skills/ghost-repo-context in your project. Claude Code loads it when a task matches its description.

How do I install Ghost Repo Context in Codex?

Run `npx skills add ghostsecurity/skills --skill ghost-repo-context -a codex`. Or copy the skill folder (plugins/ghost/skills/repo-context in ghostsecurity/skills) into .agents/skills/ghost-repo-context in your project. Codex loads it when a task matches its description.

Can I use Ghost Repo Context in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ghostsecurity/skills --skill ghost-repo-context -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ghost-repo-context, .gemini/skills/ghost-repo-context, .github/skills/ghost-repo-context and .opencode/skills/ghost-repo-context in your project.

What does Ghost Repo Context need to run?

Going by SKILL.md and its folder, Ghost Repo Context needs the command-line tools its instructions call (git). Its frontmatter pre-approves these tools: Read, Write, Edit, Glob, Grep, Bash.

Does Ghost Repo Context access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ghost Repo Context safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ghost Repo Context use?

Ghost Repo Context is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ghost Repo Context use?

About 786 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ghost Repo Context?

Skills that share tags, products or a category with Ghost Repo Context: ccc Semantic Code Search (cocoindex-io/cocoindex-code, 2.7k stars), Context Engineering (abashev/vfs-s3, 106 stars), Repomix Codebase Packer (yamadashy/repomix, 29k stars) and Codebase Handbook Builder (Ruhan-Wang/Harness_Handbook, 332 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ghost Repo Context?

ghostsecurity (a GitHub organization) maintains it in ghostsecurity/skills, which has 408 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on September 28, 2026.

Source: ghostsecurity/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.